Trending Malware
Active families, ranked. Mallory tracks every named malware family across vendor reports, researcher analysis, and threat feeds, then surfaces the ones gaining velocity right now.
Ranked by Mallory's mention-velocity model across sources.
Mention map · Last day
Sized by mentionsTop 24 malware · Last day
Medusa is a ransomware family and ransomware-as-a-service operation first identified in 2021 that evolved from a closed operation into an affiliate-based model by at least early 2023. It has impacted more than 500 victims across multiple critical infrastructure and enterprise sectors, with frequent targeting of healthcare and public health organizations as well as education, legal, insurance, technology, manufacturing, government, defense, and financial services entities. The operation is distinct from MedusaLocker. Medusa uses double extortion: operators and affiliates steal data, encrypt systems, and threaten public release of exfiltrated information if ransom demands are not met. The group commonly gives victims a short negotiation window and uses leak-site pressure to coerce payment. Initial access is obtained through phishing, purchased access from initial access brokers, and rapid exploitation of newly disclosed unpatched internet-facing vulnerabilities. Medusa has been observed weaponizing public vulnerabilities within 24 hours of disclosure and, in some cases, using exploit access before public disclosure. Post-compromise activity emphasizes speed, stealth, and use of legitimate or commonly available tooling. Medusa actors use PowerShell and other living-off-the-land techniques, harvest credentials with tools such as Mimikatz, leverage remote monitoring and management software and remote access services including RDP for lateral movement, and use common utilities for staging and exfiltration. Reported tradecraft includes disabling security tools, deleting shadow copies, terminating services, archiving data for theft, and transferring the encryptor across the environment before broad encryption. The Windows encryptor has been associated with a payload that appends a Medusa-specific extension to encrypted files. Medusa’s operational model relies heavily on affiliates and access brokers, with payments scaled to the value of access. Its intrusion pattern is characterized by opportunistic targeting of exposed, unpatched systems rather than exclusive focus on a single vertical, although healthcare has been a particularly frequent victim sector. The combination of rapid exploitation, credential theft, lateral movement, data exfiltration, defense evasion, and network-wide encryption has made Medusa a significant and persistent ransomware threat.
Clop, also written Cl0p, is a ransomware and data-extortion operation known for large-scale exploitation of enterprise software vulnerabilities to steal data from victim organizations. The operation has repeatedly targeted internet-exposed business platforms, including managed file transfer products and product lifecycle management systems, and has used stolen data to pressure victims through leak-site publication and direct extortion. In 2026, activity attributed to Clop included exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM. In those intrusions, operators deployed a bespoke JavaServer Pages web shell tailored specifically to Windchill environments. The implant used native Windchill classes and application context to access the database, decrypt credentials stored in the application keystore, enumerate file-vault repositories, retrieve and delete files, and execute additional Java code in memory. Its design reflected detailed knowledge of Windchill internals, including APIs, schema, keystore handling, and vault structure, and enabled theft of engineering data, product designs, administrative secrets, and directory-management credentials. Running through the application’s own identity and traffic patterns also reduced forensic visibility and supported stealthy post-compromise activity. Clop has also been associated with earlier mass-exploitation campaigns against Accellion FTA, GoAnywhere MFT, and MOVEit Transfer. Across these campaigns, the group has emphasized rapid data theft and extortion at scale, often claiming large numbers of victims and publishing victim names on a leak site when negotiations fail. Reporting also links Clop to deployment of custom web shells in some software-exploitation operations, reinforcing its pattern of developing platform-specific tooling for high-value enterprise targets. The operation is widely characterized as extortion-focused and has at times prioritized data exfiltration over encryption. It has used victim-shaming infrastructure and pressure tactics such as contacting employees, customers, or partners of affected organizations. Targeting has included sectors that rely heavily on enterprise file transfer and PLM platforms, such as manufacturing, aerospace, defense, automotive, retail, energy, and medtech. Clop is commonly discussed alongside affiliate designations such as FIN11 and TA505, although precise organizational relationships are not always consistently resolved in public reporting.
GoginRAT is a previously undocumented Go-based remote access trojan associated with the SilkParasite cyber-espionage campaign, a China-nexus intrusion set targeting government organizations in Central Asia. It is part of a broader modular malware ecosystem used for long-term access and selective capability deployment against public-sector victims. Architecturally, GoginRAT closely resembles NomadRAT despite being implemented in a different programming language, suggesting a shared design pattern across the operator’s toolset. The implant uses a separate transmitter component for command-and-control communications and exposes functionality through independent plugins rather than embedding all capabilities in a monolithic payload. Confirmed plugin-supported functions include file system operations and shell command execution, consistent with hands-on post-compromise control. GoginRAT has been observed in intrusions that begin with tailored spearphishing against government entities, including malicious Office-document lures and, in some cases, password-protected archive delivery. Within the wider SilkParasite campaign, malware deployment commonly relies on DLL sideloading using legitimately signed applications, and the overall toolset is designed to maintain a small footprint and reduce detection. Researchers also noted development artifacts in GoginRAT, including leftover Go test functions and a placeholder encryption key, assessed as signs of AI-assisted development rather than fully automated malware generation.
NomadRAT is a previously undocumented remote access trojan associated with the SilkParasite cyber-espionage campaign, a China-nexus intrusion set targeting government organizations in Central Asia. It has been observed in operations against public-sector entities in countries including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. The malware is written in C++ and is designed as a modular implant with a main orchestrator component, a dedicated transmitter library for command-and-control communications, and plugins that are retrieved from the server on demand using numeric identifiers. This architecture supports a low-footprint, selectively deployed post-compromise capability set aligned with long-term espionage objectives. NomadRAT has been linked to spear-phishing-led intrusion chains using tailored Office-document lures, sometimes delivered in password-protected archives, with execution facilitated through macro-triggered DLL sideloading via legitimately signed applications. The broader SilkParasite toolset is characterized by modular engineering, defense evasion through trusted binaries and small operational footprint, and tradecraft overlaps with other Chinese-linked malware ecosystems.
DriveSilkRAT is a previously undocumented remote access trojan associated with the SilkParasite cyber-espionage campaign, a China-nexus intrusion set targeting government organizations in Central Asia. The malware is part of a broader modular toolset used against public-sector entities in countries including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. It has been observed in operations that rely on tailored spearphishing lures, including malicious Office documents sometimes delivered in password-protected archives, with execution chains involving macro-triggered DLL sideloading through legitimately signed applications. DriveSilkRAT is implemented in .NET and C++ and uses Google Drive as its command-and-control channel, polling a designated folder for tasking and uploading execution results back to the same location. It supports an in-memory .NET plugin architecture that enables operators to selectively extend functionality while maintaining a relatively small footprint. Reported plugin capabilities include process listing, system and network enumeration, file management, and command execution, making the malware suitable for long-term interactive access and espionage-oriented post-compromise activity. Its use of trusted cloud infrastructure and modular execution model aligns with defense-evasion tradecraft seen across the SilkParasite ecosystem.
NodeEdgeRAT is a JavaScript-based remote access trojan associated with the SilkParasite cyber-espionage campaign, a China-nexus intrusion set assessed to have targeted government organizations in Central Asia. It is one of several distinct RAT families used by the operators as part of a modular, low-footprint toolset intended to establish and maintain access in selected victim environments. NodeEdgeRAT packages its core functionality into a single script rather than relying on a broader plugin framework. Documented capabilities include remote command execution, file management, and file transfer, enabling operators to interact with compromised hosts, manipulate files, and move data to and from victim systems. The malware family has also been noted for development artifacts consistent with AI-assisted coding workflows, including a placeholder encryption-key configuration value. Within the broader SilkParasite intrusion chain, initial compromise activity has been linked to spear-phishing using tailored government-themed lures, including password-protected archives containing malicious Office documents. Those documents have been reported to trigger macro-based execution and DLL sideloading to deploy first-stage payloads, after which SilkParasite operators use multiple RAT families for persistence and post-compromise operations. The campaign has primarily targeted government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan, with related lure material also observed for a Georgian government entity. SilkParasite has been linked by researchers to prior China-aligned activity including FamousSparrow, and its broader tooling ecosystem includes other implants such as DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, SpiceRAT, and BloodAlchemy.
CookiETagRAT is a previously undocumented remote access trojan associated with the SilkParasite cyber-espionage campaign, a China-nexus intrusion set targeting government organizations in Central Asia. It has been observed in operations against public-sector entities in countries including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan as part of a broader modular malware ecosystem used for long-term access and selective post-compromise tasking. The malware is implemented in C++ and is notable for using HTTP Cookie and ETag response headers as its command-and-control channel to receive and execute operator commands. This design aligns with SilkParasite’s broader emphasis on low-footprint, evasive tooling intended to blend into normal traffic patterns and avoid looking like conventional malware. Across the campaign, operators relied on plugin-oriented and modular implants, legitimately signed applications abused for DLL sideloading, and tailored spearphishing lures delivered through malicious Office documents, sometimes packaged in password-protected archives. CookiETagRAT forms part of a professionally engineered espionage toolset that also includes other RAT families such as DriveSilkRAT, NomadRAT, GoginRAT, NodeEdgeRAT, SpiceRAT, and BLOODALCHEMY. The campaign has been linked directly to prior FamousSparrow activity and indirectly to the broader ShadowPad-linked Chinese threat ecosystem. Its operational use indicates a focus on covert command execution and sustained access in government environments rather than disruptive effects.
Mirai is a Linux-based IoT botnet malware family best known for compromising internet-exposed embedded devices such as routers, IP cameras, DVRs, NAS appliances, and other edge systems, then enrolling them into centrally controlled botnets for large-scale distributed denial-of-service operations. It became one of the defining malware families in the IoT threat landscape and has remained highly influential because its source code was publicly leaked, enabling extensive reuse, modification, and proliferation of variants and derivative botnets. Mirai commonly propagates by scanning for exposed services and abusing weak or default credentials, especially over Telnet and SSH, and by exploiting known vulnerabilities in internet-facing devices and servers. Once a device is compromised, Mirai typically downloads an architecture-appropriate binary, executes it on the target, and connects to command-and-control infrastructure to await instructions. Mirai-derived campaigns have targeted a wide range of Linux-based and embedded platforms and have also been observed infecting some server environments in addition to traditional IoT devices. The malware family’s core capability is botnet-enabled DDoS activity, with variants supporting multiple flood techniques across TCP, UDP, GRE, DNS, and HTTP. Many descendants preserve this attack engine while extending the framework with additional modules such as encrypted command-and-control, exploit dispatchers, SSH brute-forcing, credential sniffing, proxying, reverse relays, interactive shell access, file transfer, persistence mechanisms, anti-analysis checks, and process-killing logic. Some Mirai-related families have also incorporated monetization features beyond DDoS, including proxy abuse, extortion support, and in certain derivative strains, cryptomining. Mirai has inspired or directly contributed code to numerous later botnets and malware families, including variants and forks such as IZ1H9, Murdoc Botnet, LiquorBot, EnemyBot, and Evooo1Bot. These descendants have been used in campaigns exploiting newly disclosed vulnerabilities in routers, cameras, web applications, and edge infrastructure, demonstrating the continued operational relevance of the Mirai codebase years after its original emergence. Mirai remains a foundational malware family in Linux and IoT botnet operations and a persistent driver of opportunistic exploitation, large-scale scanning, and DDoS activity worldwide.
MacSync Stealer is a macOS-focused information stealer used in social-engineering-driven campaigns that trick users into executing attacker-supplied Terminal commands. Observed delivery commonly relies on ClickFix-style lures, including fake support or software-installation pages, malvertising, and GitHub- or chat-themed landing pages that instruct victims to paste a curl command into Terminal. The malware uses native macOS and Unix tooling, including shell scripts, curl, base64 or compression utilities, and AppleScript executed through osascript, to retrieve, unpack, and run its payload while blending into normal system activity. Once active, MacSync Stealer collects a broad range of high-value data from infected Macs. Reported targets include macOS Keychain material, browser credentials, cookies, session data, browsing history, Apple Notes, SSH keys, cloud credentials such as AWS material, Kubernetes configuration files, Telegram sessions, and files from common user directories. It also checks for cryptocurrency wallet browser extensions, desktop wallet applications, and hardware-wallet companion software, and has been observed modifying wallet applications to phish for wallet recovery phrases. Data is staged locally, compressed into archives, split into chunks, and exfiltrated through recurring HTTP PUT upload patterns. The malware also removes temporary staging artifacts after exfiltration. MacSync has also been associated with post-compromise remote access functionality. Reported variants install a persistent macOS component via LaunchAgent mechanisms, enabling interactive shell access, command execution, and file transfer for the operator. Campaigns involving MacSync have requested sensitive macOS permissions such as Full Disk Access and Screen Recording to expand collection and surveillance. The malware’s infrastructure is known to rotate rapidly, but recurring behavioral traits across payload retrieval, AppleScript-assisted execution, staging, chunked exfiltration, and cleanup have enabled defenders to cluster related activity. No named threat actor attribution is established at high confidence, though the malware shares delivery templates and tradecraft with other macOS stealers such as Atomic Stealer and CrashStealer.
Atomic macOS Stealer, commonly abbreviated AMOS, is a macOS-focused information stealer offered through a malware-as-a-service model and widely used in criminal campaigns targeting credentials, cryptocurrency assets, and authenticated browser sessions. It is commonly delivered through social-engineering lures such as counterfeit software installers, malvertising, fake document-sharing pages, and ClickFix-style workflows that trick users into executing commands or installing trojanized disk images. Observed lures have impersonated trusted brands and services including collaboration, file-sharing, and software distribution platforms. AMOS is designed to harvest browser credentials, cookies and session material, cryptocurrency wallet data, macOS keychain contents, and messaging-app data such as Telegram files. Reported variants and campaigns have also targeted Apple Notes and other sensitive user files. The malware commonly prompts victims for their macOS password to unlock protected data sources and improve collection depth. Exfiltration of staged data to attacker-controlled infrastructure is a core function. Persistence has been observed through scheduled background components on macOS, including LaunchDaemon-style mechanisms. Reporting from 2025 also indicates the family gained an embedded backdoor capability, expanding it beyond pure theft into longer-term post-compromise access. In campaign use, AMOS has appeared alongside other payloads and shared lure infrastructure with macOS stealers such as MacSync and, in comparative analysis, has been discussed alongside families including CrashStealer and AmnesiaStealer. AMOS has been distributed in broad criminal operations including malvertising and ClickFix campaigns, and has been observed in targeted social-engineering activity against conference attendees and cryptocurrency-adjacent users. It is a prominent macOS infostealer family and a recurring component of financially motivated intrusion activity focused on credential theft, session hijacking, and cryptocurrency wallet compromise.
FakeMBAM is a Windows backdoor disguised as a Malwarebytes installer and associated with a large-scale supply-chain style distribution campaign that abused the automatic update mechanisms of Download Studio and the adblocker applications NetShield Kit, My AdBlock, and Net AdBlock. Activity was observed at significant scale, with infections concentrated in Russia, Ukraine, and Kazakhstan, and the campaign appears intended to reach the full user bases of the affected applications. Code and infrastructure overlaps between the distributors and the malware suggest either a common operator or a closely connected compromise. The malware is installed through a counterfeit Malwarebytes package that silently creates a fake Malwarebytes directory populated with legitimate signed components alongside malicious DLLs. Execution relies on DLL sideloading: a trojanized Qt component causes the legitimate Malwarebytes executable to load a malicious library that implements the backdoor. Persistence is established by creating a Windows service masquerading as a Malwarebytes service, and the malware also modifies host settings to facilitate execution. Once active, FakeMBAM polls attacker-controlled infrastructure for encrypted configuration updates using custom HTTP headers and cryptographic validation. It stores encrypted configuration locally and supports retrieval and deployment of additional payloads. Observed secondary payloads included persistent XMRig-based cryptocurrency miners. The malware can execute payloads directly or via scheduled tasks, periodically reinstall removed payloads, and in some cases attempt to run payloads under a stolen active user token. Its behavior demonstrates defense evasion, persistence, post-compromise payload delivery, and monetization through cryptomining.
ShadowPad is a sophisticated modular Windows backdoor and malware platform widely associated with Chinese espionage operations. It emerged around 2015 as an evolution of PlugX and became publicly notable after its use in major software supply-chain compromises, including the NetSarang, CCleaner, and ASUS ShadowHammer incidents. ShadowPad is best characterized as a privately sold or selectively shared malware framework rather than an openly distributed toolkit, with functionality extended through plugins that enable operators to tailor capabilities to specific intrusions. The malware is designed for long-term covert access on compromised systems. Its architecture uses an obfuscated loader and shellcode-based components to decrypt and load a root plugin, which in turn loads additional embedded or remotely supplied plugins into memory. Reported functionality includes arbitrary command execution, deployment of next-stage payloads, host reconnaissance, process discovery, collection of victim username and domain information, collection of system date and time, configuration and virtual file system storage in the Windows Registry, and DLL injection into legitimate processes such as svchost.exe. ShadowPad is also noted for anti-detection and persistence features, and operators commonly pair it with DLL sideloading through legitimate signed applications. ShadowPad has been used across multiple espionage clusters and by several China-linked threat groups, which makes attribution based solely on its presence unreliable. Groups and activity clusters publicly linked to ShadowPad use include APT41-related operations, Tick, Tonto Team, SparklingGoblin, FamousSparrow-linked activity, and other China-nexus intrusion sets. It has appeared in campaigns targeting government, telecommunications, critical infrastructure, software supply chains, and other strategic sectors across Asia and beyond, including operations against entities in Pakistan, India, and Central Asia. Its broad adoption, modularity, and continued evolution have made it one of the most consequential shared backdoors in the Chinese cyber-espionage ecosystem.
BloodAlchemy is a Windows x86 backdoor and remote access trojan associated with China-aligned espionage activity. It has been assessed as an updated evolution of DeedRAT and part of the broader ShadowPad lineage, and has been observed in operations linked to the REF5961 intrusion set as well as later campaigns targeting government and strategic-sector organizations in Asia. Multiple reports note that it is favored by several China-aligned threat actors and has appeared in intrusions against government entities in Southern, Southeastern, and Central Asia. The malware is typically deployed through DLL sideloading using a legitimate signed application and a malicious loader, after which shellcode decrypts and reconstructs the BloodAlchemy payload in memory from a custom encrypted and compressed format. It is designed for stealthy post-compromise access and supports multiple execution modes, including in-process execution, separate-thread execution, service-based execution, and creation of a process followed by code injection. Documented anti-analysis and evasion features include anti-debugging, anti-sandbox checks, encrypted strings and configuration data, and use of trusted or benign host processes. BloodAlchemy supports persistence through several mechanisms, including services, scheduled tasks, registry autoruns, and COM-based task scheduling interfaces. Its configuration can contain multiple command-and-control entries along with mutexes, process names for injection, and behavioral flags. Communication capabilities include HTTP, sockets, and named pipes, with support for encrypted, compressed, and encoded data transport. Reported backdoor functions include host information collection, component replacement and self-update, proxy configuration handling, self-uninstallation, and storage or removal of additional payloads. Observed command support and development artifacts indicate an actively maintained espionage implant rather than commodity malware. Operational reporting has tied BloodAlchemy to spearphishing-led intrusion chains in which malicious Office documents and archive-based lures trigger DLL sideloading and deployment of modular implants. It has been used in campaigns targeting government ministries, foreign affairs organizations, and other high-value public-sector entities, and has also been cited in activity against Central Asian energy and policy-related targets. Its lineage, tradecraft, and victimology are consistent with long-term intelligence collection operations.
WannaCry is a Windows ransomware family that caused a major global outbreak in 2017 by combining file-encryption extortion with worm-like network propagation. It is widely known under aliases including WanaCrypt0r, WanaCrypt, WanaCry, and WCRY. The malware is strongly associated with exploitation of the SMB vulnerability addressed by MS17-010, particularly through EternalBlue, and with use of the DoublePulsar backdoor to deliver its payload in memory and spread laterally across vulnerable systems. Operationally, WannaCry separates propagation and ransomware functions across multiple components. Its worming stage scans for vulnerable hosts, checks SMB behavior consistent with MS17-010 exposure, exploits susceptible systems, and can install or leverage DoublePulsar to inject a launcher into a privileged process. Subsequent stages deploy service-based components that establish execution and launch the ransomware interface and encryption workflow. Analyses of the 2.0 generation showed a modular design in which the SMB-spreading dropper, service component, and decryptor GUI were distinct binaries, making the propagation mechanism adaptable for delivery of other payloads. Core behaviors include rapid lateral movement over SMB, in-memory payload delivery through DoublePulsar, service creation for persistence, local network discovery to identify nearby targets, and defense-evasion measures such as hiding files. WannaCry has also been observed using a kill-switch domain check in prominent variants; later modified samples disabled the practical effect of that logic while retaining worm behavior. Some altered variants lacked functional encryption yet continued to propagate, underscoring that the family’s worm capability can persist independently of its extortion component. The malware targets Windows systems, especially unpatched or exposed hosts within enterprise and organizational networks. Its impact was amplified by self-propagation rather than reliance on user interaction during the main outbreak, although earlier reporting indicates the family had also appeared through other delivery paths before the global incident. WannaCry remains a defining example of ransomware fused with worm-like exploitation and post-exploitation backdoor use.
Evooo1Bot is a modular Linux botnet derived from the leaked Mirai source code that targets internet-facing edge infrastructure, including routers, firewalls, IP cameras, NAS appliances, and other embedded or gateway devices. Active since at least July 2026, it extends Mirai’s original distributed denial-of-service functionality with a broader post-compromise feature set oriented toward proxy abuse, credential collection, remote administration, and continued propagation. Initial compromise is achieved through exploitation of multiple known vulnerabilities in exposed devices and through SSH brute-force activity. After access is obtained, the malware deploys architecture-specific Linux binaries and attempts to reduce forensic visibility by clearing shell history. It performs anti-analysis and anti-honeypot checks before fully activating, including checks for debuggers, reverse-engineering tools, sandbox artifacts, virtualization or container environments, and known SSH honeypot indicators. A defining capability of Evooo1Bot is its SOCKS5 relay module, which converts compromised devices into persistent proxy nodes. It supports both direct-listening and reverse-relay modes, allowing operators to route traffic through victim infrastructure for concealment, geographic evasion, internal-network pivoting, and criminal proxy operations. The malware also supports encrypted command-and-control communications disguised to blend with normal encrypted web traffic. Beyond proxying, Evooo1Bot includes an interactive shell, file upload and download functions, self-update, and multiple persistence mechanisms using common Linux startup and scheduling facilities. It also contains a credential-sniffing component that monitors network activity to capture HTTP Basic Authentication material and cookies, as well as an SSH scanner that uses a built-in credential dictionary and additional checks to avoid honeypots. Newer variants include an embedded exploit dispatcher targeting additional products and enterprise-facing applications, although some exploit implementations appear to be faulty. Evooo1Bot retains Mirai-style botnet behavior through an inherited DDoS engine supporting multiple flood techniques, but its modular design and reverse proxy capability make it more versatile than conventional Mirai descendants. The malware is best characterized as a Linux botnet platform for distributed denial-of-service attacks, credential interception, proxy infrastructure creation, and follow-on intrusion support against exposed edge environments.
StopAndProtect is a multi-component cybercrime malware operation centered on a ransomware family of the same name and supported by a broader toolkit for covert data theft, surveillance, lateral movement, and victim interaction. The operation relies heavily on large numbers of compromised WordPress websites, which are repurposed as distributed infrastructure for malware delivery, command-and-control, and storage of exfiltrated victim data. Infection commonly begins with a ClickFix-style fake CAPTCHA lure that tricks users into executing a PowerShell command, after which staged PowerShell and .NET downloader/loader components deploy the main payloads. Observed payloads include SilentEncryptor, the ransomware component; SilentDataCollector, a stealer focused on file inventorying and selective exfiltration; NetworkShareScanner, which propagates via SMB shares and removable media; a VBS-based spreader that also supports WMI-driven lateral movement; a lock-screen module; and a custom chat utility used for operator-victim communication. Newer stealer variants have been observed with keylogging, screenshot capture, network-share mapping, and WhatsApp-focused collection features. The operation does not always culminate in encryption; in many cases it appears to prioritize reconnaissance and theft of file listings and selected files before, or instead of, ransomware deployment. The campaign targets Windows systems and has affected victims globally, with notable concentrations observed in the United States, Russia, and India. Operational security failures exposed internal logs, screenshots, stolen-data archives, and tooling used to manage the compromised WordPress infrastructure, indicating a broad, actively managed criminal ecosystem rather than isolated ransomware incidents. The abuse of outdated and vulnerable WordPress installations, along with malicious plugins and must-use plugins for persistence and arbitrary file upload, is a defining feature of the operation’s infrastructure strategy.
Mimikatz is a widely used open-source Windows post-exploitation tool created by Benjamin Delpy that is primarily known for credential theft and abuse of Windows authentication mechanisms. It can extract credentials from memory, including material associated with the Local Security Authority Subsystem Service, and is commonly used to dump passwords, hashes, and Kerberos-related secrets from compromised systems. Its functionality has made it a staple utility in both red-team operations and real-world intrusions by ransomware operators, cybercriminal groups, and state-linked threat actors. Beyond basic credential dumping, Mimikatz includes capabilities for abusing Active Directory replication and trust relationships. Its lsadump::dcsync functionality can request directory replication data from domain controllers to obtain password hashes, including highly sensitive account material, while lsadump::dcshadow can register a rogue domain controller context and push unauthorized directory changes. These features enable privilege escalation, persistence, and broad post-compromise control in Windows enterprise environments when attackers already possess sufficient privileges. Mimikatz is frequently observed after initial compromise as part of hands-on-keyboard intrusion activity rather than as a self-propagating payload. Threat actors commonly pair it with PowerShell, remote administration tools, lateral movement frameworks, and exfiltration utilities. It has been used in ransomware intrusions such as Medusa and Maze-related activity, in campaigns involving tools like Emotet, QakBot, and TrickBot, and in long-term intrusions where operators used it to harvest credentials before moving laterally or escalating privileges. Variants, modified builds, reflective loaders, and Mimikatz-like components are also commonly embedded or repurposed inside other malware families. Mimikatz targets Windows systems and is especially impactful in Active Directory environments because stolen credentials and replication abuse can enable domain-wide compromise. Its core role is credential access, but in practice it also supports privilege escalation, lateral movement, persistence, and broader post-exploitation objectives by giving attackers access to privileged accounts and authentication artifacts.
TAMECAT is a modular PowerShell-based backdoor used in espionage operations attributed to the Iranian threat actor APT42, also tracked under aliases including Mint Sandstorm and CharmingCypress. It has been used against high-value targets such as senior government and defense officials, policy experts, individuals associated with the nuclear energy sector, and in some reporting, family members of primary targets. The malware is designed for long-term intelligence collection while minimizing forensic artifacts through largely in-memory execution and extensive use of obfuscation and legitimate Windows components. TAMECAT is commonly delivered through highly targeted spearphishing and relationship-based social engineering. Reported lures include conference invitations, interviews, meeting documents, and other professional pretexts, sometimes reinforced through prolonged contact over personal email, corporate accounts, or WhatsApp. Observed delivery chains include malicious shortcut files disguised as documents and abuse of Windows search-ms and WebDAV to retrieve and execute follow-on stages. The malware uses a staged, modular architecture. Early-stage components have used VBScript and PowerShell to perform environment checks, including discovery of installed antivirus products via WMI or VBScript logic, and to retrieve additional payloads. TAMECAT employs command obfuscation, Base64-encoded communications, and AES-encrypted data exchange. Reporting also describes custom handling of initialization vectors in HTTP headers and support for multiple command-and-control paths, including HTTPS as well as fallback or alternate channels over Telegram and Discord. Some variants also support FTP-based exfiltration. TAMECAT supports remote command execution, host reconnaissance, file discovery, screenshot capture, browser data theft, Outlook mailbox data collection, and staged exfiltration. Reconnaissance functions have included collection of operating system details, hostname, domain context, privilege level, network configuration, installed software, process information, uptime, and patch status. File collection modules have targeted documents, archives, media, images, and password-database files while excluding some noisy or low-value paths. A notable capability is theft of browser credentials and cookies from Chromium-based browsers. Reported techniques include abusing Microsoft Edge remote debugging to extract decrypted browser data and suspending Chrome to access locked profile databases for credential and cookie collection. TAMECAT has also been reported to collect Outlook mailbox cache data, capture repeated screenshots, package stolen information into archives, split large data into chunks, and exfiltrate the results over encrypted channels. Persistence has been observed through per-user autorun mechanisms and logon-script style execution, alongside storage of victim identifiers and staged data in user-accessible locations. Defense-evasion tradecraft includes fileless execution, runtime string reconstruction, fragmented payload encoding, use of trusted binaries and LOLBins, and adaptive execution paths based on the defensive environment. Overall, TAMECAT is a mature surveillance backdoor optimized for stealthy, resilient, long-duration access in support of Iranian cyber-espionage objectives.
OWAReaper is a browser-resident JavaScript backdoor used by the Russia-aligned espionage group tracked as TA488, Void Blizzard, and Laundry Bear. It is designed for persistent compromise of on-premises Microsoft Exchange Outlook Web Access (OWA) through exploitation of CVE-2026-42897, a cross-site scripting flaw that allows attacker-controlled JavaScript to execute when a victim opens a specially crafted email in OWA. The intrusion method has been described as a half-click attack because opening the message alone can trigger execution without requiring a link click or attachment open. The implant executes entirely inside the OWA reading pane and is notable for leaving little or no conventional host-level malware footprint. Its functionality includes collection of mailbox and account context such as the victim’s email address, username, and Outlook configuration, as well as theft of credentials by abusing browser autofill through invisible DOM elements. It can also identify Outlook add-ins with mailbox write permissions and abuse token-access functionality to obtain OAuth tokens. Reported collection objectives include credentials, contacts, emails, and other mailbox data. OWAReaper incorporates multiple persistence mechanisms spanning browser and server-side state. It can store an encrypted copy of itself in browser storage so that it re-executes when new OWA tabs are opened. It also enables OWA offline caching and poisons cached messages in IndexedDB with hidden content that can retrigger execution when cached mail is reopened. More significantly, it abuses Exchange folder-permission operations to grant broad mailbox access through the Default user, creating server-side persistence that can survive password changes and even endpoint reimaging until the mailbox permissions are explicitly remediated. For operational security and stealth, OWAReaper can rewrite the original email on the server to remove exploit content after execution. It supports covert command-and-control through public GitHub commit messages and through specially formatted inbound emails available to the compromised OWA session. Exfiltration is primarily performed over HTTPS using encrypted request paths, with fallback mechanisms including direct server communication and DNS-based exfiltration. The malware is assessed as an evolution of the earlier ZimReaper implant used against Zimbra and reflects a mature webmail-focused espionage capability aimed at long-term mailbox access and data theft. Observed targeting has included government organizations in the United States and Europe as well as telecommunications, financial, hospitality, and aerospace entities. Exchange Online has not been reported as affected; the activity is associated with vulnerable on-premises Exchange Server OWA deployments.
VShell is a Go-based remote access trojan and backdoor used in intrusions worldwide, with especially frequent use by Chinese-speaking threat actors and China-aligned intrusion clusters. It is associated with long-term espionage, persistence, post-compromise network expansion, and access-brokering activity rather than being limited to short-lived smash-and-grab operations. Reported users or linked clusters include UNC5174, Houken, UNK_MassTraction, and other Chinese-speaking operators, though VShell usage is broader than any single actor. VShell provides full remote administration capabilities, including interactive command execution, file browsing, file upload and download, screenshot capture, port forwarding, and proxying. It can convert compromised systems into SOCKS5, HTTP, or TCP/UDP relay nodes to support pivoting, concealment, and exfiltration. Public reporting also notes plugin support and one-click persistence features, with operators using it alongside offensive utilities such as scanning and credential-access tools. The malware supports multiple communications methods and listener types, including TCP, UDP, WebSockets, DNS, DNS-over-HTTPS, DNS-over-TLS, and object-storage-based channels. Traffic is encrypted, and later versions added stealth-oriented features such as reduced logging, anti-sandbox measures, decoy web content on listeners, and broader payload options including stagers, stageless beacons, and shellcode. VShell has been observed running fully in memory in some intrusions, including deployments launched by shell scripts or custom downloaders. VShell is cross-platform, with client support documented for Windows, Linux, and macOS. It has been deployed after exploitation of public-facing systems and appliances, including webmail and edge infrastructure, and has appeared in compromises involving Roundcube, Ivanti-adjacent actor ecosystems, exposed servers, Kubernetes and cloud-hosted Linux environments, MS-SQL server intrusions, and mass website exploitation operations. In several campaigns, operators used VShell after exploiting known vulnerabilities to maintain access, move laterally, scan internal networks, and deepen control over victim environments. Victimology linked to VShell-enabled operations includes government, healthcare, military, research, academia, telecommunications, finance, transport, manufacturing, and other sectors across multiple regions. Its recurring role as a post-exploitation implant, combined with flexible transport options and proxying features, has made it a common tool in sustained intrusion sets seeking durable footholds and covert remote control.
Mythic is an open-source, cross-platform post-exploitation command-and-control framework developed with an agent-agnostic, modular architecture that separates the management platform from payloads. It is widely used in adversary emulation and red teaming, but has also been repeatedly observed in real intrusions conducted by espionage and financially motivated actors. Public reporting has linked its use to groups including SideCopy, APT36/Transparent Tribe, GOFFEE, and other operators deploying Mythic-compatible implants during follow-on intrusion activity. The framework supports multiple command-and-control transports, including HTTP, TCP, DNS, and SMB, and provides operators with flexible payload generation for Windows, Linux, and macOS. Known Mythic agents include Apollo for Windows, Poseidon for macOS, and Apfell for macOS, while private or customized Mythic-compatible agents have also been observed. Mythic is designed for post-compromise operations rather than initial exploitation, enabling operators to execute commands, conduct reconnaissance, transfer files, manage implants, and support data exfiltration. File transfer functionality includes configurable chunk sizes for uploads and downloads. In intrusion activity, Mythic has been used after phishing- or loader-based compromise to maintain persistent access and manage victim environments. It has appeared in campaigns where weaponized documents, malicious macros, and script-based execution chains delivered in-memory payloads, as well as in financially motivated operations where loaders such as BLISTER deployed a Mythic implant. Reporting also describes Mythic agents operating in Linux container environments, including fileless execution from anonymous memory, illustrating its adaptability beyond traditional endpoints. Because Mythic is open source, actively maintained, and easy to customize, it has become a notable alternative to frameworks such as Cobalt Strike and Sliver. Its widespread reuse by both legitimate security teams and malicious actors complicates attribution, but its role as a mature post-exploitation and command-and-control platform is well established.
IceCube is a JavaScript-based credential-stealing malware used in espionage intrusions against vulnerable Roundcube webmail deployments. It has been associated with the suspected China-aligned cluster UNK_MassTraction, which targeted universities in the United States and Canada, particularly physics, engineering, astrophysics, particle physics, and other research environments with potential national-security relevance. The malware is delivered through phishing emails that exploit the Roundcube cross-site scripting vulnerability CVE-2024-42009 when a victim opens a message in a vulnerable webmail session, enabling attacker-controlled JavaScript to execute in the browser without requiring attachment execution. Once loaded, IceCube escapes the constrained Roundcube frame context through DOM traversal to access the broader browser DOM and the authenticated Roundcube session. It is designed to steal usernames, passwords, cookies, session tokens, authentication material including two-factor-related data, and browser or environment information such as language, screen characteristics, and form values. The malware also uses stolen session context and anti-CSRF material to support follow-on exploitation of Roundcube server-side vulnerabilities, including attempts to leverage CVE-2025-49113 for deeper compromise. In observed campaigns, successful follow-on activity enabled deployment of server-side access tooling such as SquareShell or fallback loading of VShell, allowing attackers to pivot from webmail compromise into broader network intrusion. IceCube’s role in these operations is both credential theft and post-exploitation enablement. Its tradecraft includes deferred triggering and session abuse to maximize the chance of successful exploitation while reducing visibility. The malware reflects a broader pattern of treating internet-facing mail infrastructure as an entry point into institutional networks rather than solely as a source of mailbox data. Although the name IceCube also appears in unrelated historical Android plugin nomenclature, the malware most widely recognized under this name in current reporting is the Roundcube-focused JavaScript stealer used by UNK_MassTraction.
DOGLEASH is a lightweight Linux backdoor written in C and associated with the China-nexus threat actor UAT-7810. It has been used in the LapDogs Operational Relay Box ecosystem alongside LONGLEASH, JARLEASH, and LEASHTEST to support the compromise and operational use of edge infrastructure, particularly routers and other embedded Linux devices. UAT-7810 has been assessed as an infrastructure-focused actor that builds and maintains relay networks for downstream espionage activity, including support to other China-aligned operators such as UAT-5918. DOGLEASH is deployed post-compromise via shell scripts on infected Linux systems. Those scripts have been observed modifying local firewall rules to permit inbound TCP traffic to the port on which the implant listens. The malware operates as a passive backdoor, quietly binding to a hardcoded TCP port and waiting for authenticated inbound requests. Reported functionality includes execution of arbitrary shellcode or in-memory code, shell command execution, file reading, file renaming, closing its listener, and collection of operating system information. Its design is consistent with post-exploitation access on compromised Linux-based networking devices rather than broad commodity malware deployment. The malware has been observed in campaigns targeting unpatched Ruckus wireless routers and ASUS AiCloud routers as part of efforts to expand ORB infrastructure. Variants have been hosted for multiple architectures including MIPS, ARM, and x64, reflecting use across routers, embedded devices, and standard Linux systems. Within the broader UAT-7810 toolchain, DOGLEASH appears to provide quiet, low-footprint access and code-execution capability on compromised nodes that can then be incorporated into relay infrastructure or used for follow-on operations.