Active families, ranked. Mallory tracks every named malware family across vendor reports, researcher analysis, and threat feeds, then surfaces the ones gaining velocity right now.
Ranked by Mallory's mention-velocity model across sources.
MicroScan is a Python-based vulnerability-scanning web application developed by China-based Integrity Technology Group and used by Chinese government-linked threat actors associated with Flax Typhoon since at least 2017. It contains more than 1,300 penetration-testing scripts designed to identify vulnerabilities in internet-facing systems. Its scanning targets include OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts. MicroScan supports reconnaissance of victim networks, identifying weaknesses for subsequent exploitation by Integrity Technology Group's clients. Operators have routed scans through the company's Mirai-based botnet of compromised consumer devices, as well as other infrastructure, to obscure their origin. Identified scanning targets include a power company in the United States, airports in Japan and Poland, Taiwanese natural gas and power companies, Taiwanese universities, and a multinational nongovernmental organization. Flax Typhoon actors subsequently compromised multiple organizations whose networks had been scanned with MicroScan. Its established role is vulnerability discovery rather than the separate spear-phishing, malware-delivery, and data-theft functions associated with FishHub.
Mirai is a Linux-based botnet malware family that compromises internet-connected devices and uses them to conduct distributed denial-of-service (DDoS) attacks. First prominent in late summer 2016, it was responsible for major attacks that disrupted online services. Its targets include routers, IP cameras, digital video recorders, network-attached storage systems, and other IoT equipment. Mirai's publicly available source code has spawned numerous variants and independently operated botnets. Mirai propagates by scanning for exposed devices and attempting authentication with common or default credentials, particularly over Telnet. Variants extend this approach with command-injection and remote-code-execution exploits against device firmware and server applications. Documented Mirai campaigns have exploited vulnerabilities in D-Link, Huawei, Netgear, Linksys, and TP-Link devices, as well as Apache Log4j and Sunhillo SureLine. Architecture-specific payloads support multiple Linux processor families. Infected devices communicate with command-and-control infrastructure and execute attack instructions; variants support UDP, TCP, and DNS flooding. Some variants encrypt configuration data or strings and terminate competing malware to retain control of compromised devices. Mirai-derived infrastructure has also supported state-linked operations. U.S. authorities attributed a large Mirai-variant IoT botnet to Integrity Technology Group, a Chinese government contractor associated with Flax Typhoon. This infrastructure supported MicroScan reconnaissance and vulnerability scanning against prospective targets, including energy companies, airports, nongovernmental organizations, and Taiwanese universities. Separately, APT28 repurposed routers initially compromised by the Mirai variant Moobot for espionage infrastructure. These uses reflect distinct operators and derivative campaigns rather than a single threat actor controlling the Mirai family.
FishHub is a spear-phishing and malware-delivery tool developed and operated by China-based Integrity Technology Group and associated with the China-linked threat actor Flax Typhoon. It facilitates targeted intrusions through spear-phishing and downloads additional malware onto victim systems after an initial compromise. Payloads delivered through FishHub provide unauthorized remote access and support file enumeration, searches for specific documents, compression of collected files, and exfiltration to attacker-controlled servers. These capabilities support post-compromise access and sensitive-data theft. Approximately 20 Taiwanese universities were confirmed victims of FishHub-related activity. In October 2026, U.S. authorities seized infrastructure used to deliver FishHub-associated malware as part of an operation targeting Integrity Technology Group’s hacking tools.
EBurst is an open-source, Python-based password-attack tool used to compromise Microsoft Exchange and Microsoft 365 email accounts. It automates password spraying and password guessing against supplied email addresses, including attempts using a small number of common passwords across many accounts. Supported authentication interfaces include Exchange Control Panel, Exchange Web Services, Offline Address Book, Outlook Web Access, RPC, API, MAPI, PowerShell, Autodiscover, and Microsoft-Server-ActiveSync. Chinese government-linked actors associated with Flax Typhoon and activity enabled by Integrity Technology Group have used EBurst for initial access to email accounts and cloud services. These operations have targeted critical infrastructure and other organizations across Southeast Asia, Africa, and North America. EBurst provides password-based account-compromise functionality; it is distinct from the persistence, credential-dumping, and email-exfiltration utilities used alongside it in those operations.
Raptor Train is a large, multi-tiered botnet used as covert infrastructure for China-linked cyberespionage. Active since at least May 2020, it was linked to the Chinese state-sponsored threat actor Flax Typhoon and attributed by U.S. authorities to Integrity Technology Group, which developed, controlled, and managed the network. It compromised devices worldwide, including SOHO routers, modems, firewalls, IP cameras, video recorders, and network-attached storage systems. U.S. authorities identified more than 260,000 actively infected devices in June 2024. Its primary payload, Nosedive, is a Mirai variant deployed through exploitation of known and zero-day vulnerabilities across more than 20 device types. The architecture separates compromised devices, exploitation and payload-delivery infrastructure, and higher-level management systems. Operators used an enterprise-style management application called Sparrow to administer the network. Nosedive lacked persistence on infected devices, with individual bot infections averaging approximately 17 days. Raptor Train supported vulnerability scanning, reconnaissance, exploitation attempts, and traffic relaying that concealed operators' locations and network origins. Observed targets included U.S. and Taiwanese military, government, telecommunications, higher education, defense industrial base, and information technology organizations. Exploitation attempts also targeted Atlassian Confluence and Ivanti Connect Secure systems. Nosedive supports distributed denial-of-service attacks, although researchers did not observe routine deployment of that capability; U.S. authorities reported a DDoS attack against the FBI during the disruption operation. In September 2024, court-authorized FBI operations seized infrastructure and removed malware from infected devices, while research partners blocked traffic to known botnet infrastructure.
ROOFDECK is a Rust-based backdoor observed on ARM64 macOS systems, with additional Windows variants identified. It is associated with the North Korean threat actor TraderTraitor, also tracked as Jade Sleet and UNC4899, and is deployed as a follow-on implant after attackers establish an initial foothold. It has appeared alongside FLATROOF in intrusions affecting cryptocurrency and Web3 organizations and an Indian IT services provider. Associated campaigns target developers and DevOps personnel through fraudulent job interviews and infrastructure-engineering assignments containing weaponized Terraform projects that retrieve and execute malicious providers. ROOFDECK provides arbitrary command execution, interactive and reverse shells, host and process reconnaissance, disk and filesystem discovery, file manipulation, uploads and downloads, encrypted archive creation, data exfiltration, and clipboard access. It supports background tasks, persistence management, configuration changes, self-updating, and self-removal, and facilitates lateral movement. On macOS, it establishes persistence through LaunchAgents and masquerades as legitimate application components or renderer processes. Later variants stripped debugging information and removed earlier implants to hinder analysis and reduce forensic evidence. Its resilient command-and-control discovery combines local configuration, a Pastebin dead drop containing a cryptographically signed and encrypted server address, and decentralized Nostr profile metadata. ROOFDECK verifies the dead-drop signature before accepting the decrypted address and can expand its Nostr relay list through a public directory. After resolving its server, variants communicate over HTTP or WebSocket channels. Observed macOS implants also verify operator-signed commands using an embedded RSA public key before execution.
FLATROOF is a Rust-based backdoor family targeting macOS, Linux, and Windows. Its macOS variant, also known as Gaslight or macOS.Gaslight, has been observed on Apple Silicon systems in operations associated with the North Korean threat actor TraderTraitor, also tracked as Jade Sleet and UNC4899. Observed victims include organizations in the cryptocurrency and Web3 sector and an Indian IT services provider, with developers and DevOps engineers targeted for their access to cloud credentials and source code. FLATROOF supports arbitrary shell-command execution, process termination, file management, payload downloads, data uploads, host reconnaissance, persistence management, configuration changes, and self-removal. It can communicate through the Telegram Bot API, GitHub API polling, and attacker-controlled HTTP webhooks, although individual samples do not necessarily enable every channel. Platform-specific persistence includes Linux services, macOS shell-logout execution, and Windows registry autorun entries. It also discovers security software and can remove macOS quarantine attributes and enable execution of follow-on ROOFDECK payloads. The family incorporates operating-system-specific Python stealers that collect browser credentials, session cookies, browsing history, autofill information, command histories, installed applications, process information, and system profiles. Additional targets include macOS keychain data, Linux keyring secrets, Windows Credential Manager entries, and cryptocurrency-wallet extension data. A Windows component injects code into a suspended Chromium process to recover browser encryption keys. Collected information is staged in compressed archives for exfiltration. Distribution has involved fake recruitment assessments and weaponized Terraform projects that retrieve and execute malicious providers during initialization. A cross-platform deployment chain uses a trojanized Terraform provider and a Bash loader to select payloads by operating system and processor architecture, decrypting executables concealed within decoy font data. FLATROOF serves both as an initial collection implant and as a platform for deploying additional malware, including ROOFDECK.
XMRig is legitimate, open-source cryptocurrency-mining software widely abused as a cryptojacking payload, particularly for mining Monero. Malicious deployments consume compromised systems’ processing resources and submit mining work to pools configured to pay attacker-controlled wallets. XMRig is not inherently a worm, backdoor, or credential stealer; those functions belong to malware and deployment tooling that accompany it. Unauthorized deployments are documented on Windows and Linux servers, cloud workloads, containerized environments, and compromised Ivanti gateways. Attackers commonly install XMRig after exploiting vulnerable internet-facing applications, including Apache Log4j, Confluence, Jenkins, TeamCity, Windows PHP in CGI mode, and Adobe ColdFusion. Exposed or misconfigured container and application-management services also provide deployment opportunities. Payloads may be downloaded by shell or PowerShell scripts, embedded within other malware, or distributed through Docker images. Campaign tooling maintains mining activity through Windows services, scheduled tasks, cron jobs, and process watchdogs. Concealment techniques include masquerading as Microsoft Edge or system services, falsifying process command lines, hiding processes with rootkits, and stopping mining when Task Manager opens. Customized builds with embedded configurations and loaders that decrypt and execute XMRig in memory have also been observed. Some deployments load the vulnerable WinRing0 driver to provide low-level hardware access. XMRig has been deployed in TeamTNT and H2Miner/Kinsing operations and by malware families including Sysrv-hello, BlackSquid, Lucifer, GuptiMiner, and Lcrypt0rx. Its broad reuse reflects opportunistic monetization of compromised computing resources rather than attribution to a single threat actor or industry-specific campaign.
MATCHBOIL is a custom C# downloader for Windows used by the cyberespionage group UAC-0099, also tracked as Earth Sirrush. It collects system identifiers, retrieves and installs additional malicious payloads, and establishes persistence for those payloads. Observed targets include Ukrainian transportation, manufacturing, and energy organizations, as well as government, military, and defense entities. UAC-0099 is assessed to operate in alignment with Russian interests. MATCHBOIL was first publicly documented in August 2025, with analyzed variants spanning April 2024 through April 2026. Delivery typically begins with spearphishing emails linking to archives containing malicious VBScript files, sometimes disguised as documents. Manual execution of the script downloads and launches MATCHBOIL. A later infection chain uses LUNCHPOKE, a malicious Notepad++ plugin, and the BURNYBEAR loader to execute the updated MATCHBOIL.V2 DLL. MATCHBOIL fingerprints infected machines through Windows Management Instrumentation, collecting processor identifiers and BIOS serial numbers; later variants additionally collect usernames, network addresses, and hardware details. It communicates with command-and-control infrastructure over HTTPS, extracts hexadecimal-encoded executable payloads embedded in HTML responses, and writes them to disk. Its usual secondary payload is MATCHWOK, a C# backdoor. Payload persistence uses Windows Registry Run entries or scheduled tasks, while delivery scripts establish persistence for MATCHBOIL or its loader. Later versions contact command-and-control servers every two minutes, enabling retries and retrieval of updated payloads. Early versions use Unicode-based obfuscation and custom string encryption. Later versions employ Eziriz .NET Reactor, debugger detection, and sandbox checks based on system-uptime records. Some variants display deceptive planner or text-search interfaces when launched without expected arguments. MATCHBOIL.V2 changes the malware from an executable to a DLL run by a custom C# loader.
office-cli is a Linux command-line email-collection and exfiltration utility used to obtain unauthorized access to Microsoft 365 Outlook mailboxes. It automates repeated retrieval of messages from different time periods and stores collected email locally in account-specific subdirectories. Operators execute it directly or through Bash scripts, using JSON configuration files containing application client identifiers, tenant identifiers, and client secrets. Targeted accounts are periodically updated to support ongoing collection. The utility uses legitimate mailbox-access mechanisms to reduce detection. Its use is associated with Chinese government-linked actors enabled by Integrity Technology Group, whose techniques overlap with activity tracked as Flax Typhoon, Ethereal Panda, and Red Juliett; these attribution labels are not necessarily interchangeable. The associated email-theft operations have affected government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, within broader campaigns targeting organizations in Africa and North America and U.S. critical infrastructure.
Curlc4txt is a PHP-based information-stealing bot used by threat actors enabled by Integrity Technology Group, a China-based company linked to the Chinese government. It automates mailbox access through Microsoft Exchange Web Services, accessing emails, calendars, and contacts and uploading collected email to attacker-controlled infrastructure. Before exfiltration, it compresses collected messages and can encrypt them using RC4 or AES-128-CBC. It also obfuscates directory and file names and renames a child process to conceal its activity. The bot supports email-theft operations associated with intrusions against organizations worldwide. Observed email-theft victims in these operations include government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia. Its operators use a broader toolset for vulnerability exploitation, password attacks, persistent remote access, and data collection; those capabilities are distinct from the bot's documented mailbox-collection and exfiltration functions.
MATCHWOK is a C# backdoor for Windows used by the cyberespionage threat actor UAC-0099, also tracked as Earth Sirrush. It provides persistent remote access and command execution for intelligence collection. Its deployments have been associated with attacks against Ukrainian government bodies, the Defense Forces, and defense-industrial enterprises, alongside broader MATCHBOIL campaigns targeting transportation, manufacturing, and energy organizations. MATCHWOK executes PowerShell commands using runtime-compiled .NET code and can invoke a renamed PowerShell executable. It receives AES-256-encrypted commands concealed within script elements on remote web pages, saves execution results temporarily, and transmits those results to its command-and-control server over HTTPS. Anti-analysis checks detect tools such as IDA, Wireshark, and Process Monitor and can prevent execution when those tools are present. The backdoor is commonly downloaded and installed by the MATCHBOIL loader, which establishes payload persistence through Windows registry autorun entries or scheduled tasks. Delivery chains begin with phishing or spearphishing emails linking to archives containing malicious scripts. Court-summons-themed campaigns use nested archives and HTA files that execute obfuscated VBScript and PowerShell to deploy MATCHBOIL, which subsequently installs MATCHWOK. MATCHWOK has also been deployed alongside the DRAGSTARE information stealer.
Shai-Hulud is a self-replicating software supply-chain worm targeting the npm and Node.js ecosystem, first discovered in September 2025. It compromises trusted packages and executes malicious lifecycle scripts during installation, exposing developer workstations, servers, and CI/CD environments. Stolen publishing credentials enable it to enumerate packages maintained by victims, inject its payload, and publish infected releases, extending the compromise to downstream users. The worm harvests npm and GitHub tokens, SSH keys, environment variables, repository secrets, and credentials for AWS, Azure, GCP, Kubernetes, and HashiCorp Vault. Later variants also collect browser passwords and cookies, cryptocurrency-wallet data, messaging data, and AI-development-tool configurations. Stolen information is exfiltrated to attacker-controlled infrastructure or public GitHub repositories, with later variants encrypting the collected data. Persistence mechanisms include malicious GitHub Actions workflows, backdoored self-hosted runners, developer-tool execution hooks, and operating-system background services. Shai-Hulud 2.0 and subsequent variants use preinstall execution and obfuscated JavaScript payloads launched through the Bun runtime. ChainDrop-associated variants support remotely supplied code execution and blockchain-based endpoint discovery using Ethereum, allowing infrastructure changes without replacing the infected package. Some variants monitor stolen GitHub tokens and trigger destructive deletion of the infected user's home directory when a monitored token becomes invalid. The family runs on Windows, macOS, and Linux and targets secrets accessible in cloud and build environments. Mini Shai-Hulud variants have been associated with TeamPCP, although that association does not establish attribution for every subsequent campaign.
dcexe is a Windows credential-dumping tool used by Chinese government-linked threat actors enabled by Integrity Technology Group. It performs DCSync through RPC and the Active Directory Directory Replication Service to retrieve account credentials, group membership information, trust relationships, domain identifiers, and replication metadata. Its observed role is post-compromise credential theft and collection of directory information. It has been used in intrusion campaigns targeting organizations worldwide, including government, critical manufacturing, healthcare, information technology, law enforcement, education, and religious organizations.
Vidar is a Windows information-stealing malware family first observed in 2018 and sold as customizable malware-as-a-service through underground markets. Implemented in C++, it harvests browser passwords, cookies, session data, browsing history, cryptocurrency wallet data, sensitive files, and application data, including Telegram information. It also collects system information and exfiltrates stolen data to attacker-controlled servers. Stolen credentials and authenticated sessions facilitate account takeover against personal and corporate services. Vidar is distributed through multistage infection chains, ClickFix social engineering, fake pages on compromised websites, and loaders including SmokeLoader and 2CLoader. Distribution has also involved abuse of ScreenConnect remote-management infrastructure. Vidar has been observed alongside STOP/Djvu ransomware, although this does not establish shared authorship or exclusive operator attribution. Vidar uses Telegram and Steam profiles as dead drops for command-and-control addresses, allowing operators to change destinations by updating profile content. Observed samples inject malicious code into legitimate Windows processes, detect debugging and analysis environments, and delete staged data after exfiltration. Some samples terminate after collection without establishing persistence. Its evolving string protection has included XOR, ChaCha20, and, in 2026, a custom bytecode interpreter combined with a build-specific stream cipher. These techniques hinder static analysis and detection. Browser-process injection has also been observed in Vidar delivery chains.
Midnight Mimosa is a modular Android backdoor and financially motivated malware operation affecting low-cost and counterfeit smartphones built on MediaTek platforms. Its core components are embedded in device firmware before sale and run as persistent, privileged system applications hidden from the launcher. Operators can silently install and remove applications, grant permissions, and download and execute additional code through remotely managed plugins. Ordinary application uninstallation cannot remove the firmware-resident component, and a factory reset may be insufficient. The operation primarily monetizes compromised devices through advertising fraud, silent partner-application installation, and residential-proxy enrollment. Advertising modules fabricate impressions, clicks, and conversion events, while proxy payloads support remotely directed bidirectional traffic relaying. Defensive evasion includes temporarily disabling the Google Play Store during payload installation, disguising system components and installed applications, and forging Google Play installation provenance. Bitdefender observed thousands of affected devices across more than 150 countries over approximately two years and identified 13 Google Play applications carrying related ad-fraud code, providing an additional distribution channel without the firmware component's system privileges. The operators and the point of insertion into the device supply chain have not been established.
SoftEther VPN is legitimate open-source VPN software that threat actors abuse for persistent remote access, encrypted communications, and covert connectivity into compromised networks. Its client, server, and bridge components can connect victim systems to attacker-controlled VPN infrastructure or extend internal networks to remote locations. It is not inherently malware. In malicious deployments, operators rename SoftEther binaries to resemble trusted operating-system or application components and configure services or startup execution to maintain access after reboot. Outbound encrypted connections, including HTTPS-based tunnels, help bypass network restrictions and conceal remote-access traffic. Some deployments use cascading VPN connections to upstream servers. SoftEther provides network access rather than credential-stealing or arbitrary-command-execution functionality; attackers use separate tools and protocols, including RDP, for subsequent operations. Documented abuse includes activity tracked as Flax Typhoon, UAT-7237, GALLIUM/Red Dev 4, Soft Cell, UNC2814, and Larva-26010. Deployments have occurred in telecommunications, government, web-hosting, and critical-infrastructure environments, including Taiwanese organizations and Korean web and database servers. Attackers typically install the software after obtaining an initial foothold, using compromised servers, web shells, or command-line download utilities.
DDoSia is a cross-platform distributed denial-of-service tool developed and operated by the pro-Russian hacktivist group NoName057(16). Its broader ecosystem, known as the DDoSia Project, coordinates crowdsourced attacks through centrally managed infrastructure and volunteer participation. Active since 2022, it primarily targets Ukraine and countries supporting Ukraine, including NATO members. Targets include government and diplomatic services, financial institutions, transportation and logistics providers, defense organizations, telecommunications companies, and media outlets. Campaigns frequently coincide with politically significant events. Early implementations used Python, while subsequent clients are written in Go and support Windows, Linux, and macOS, including multiple processor architectures. Clients authenticate using participant-specific identifiers, retrieve centrally assigned target lists and attack parameters, and generate application-layer and transport-layer attack traffic. Supported techniques include HTTP and HTTPS request floods, HTTP/2 floods, TCP floods including SYN flooding, and slowloris-style resource exhaustion. Later versions retrieve encrypted target data and decrypt it in memory before attack execution. Clients report operational statistics to measure participant contributions. DDoSia is distributed primarily through Telegram, with GitHub also used historically to host tooling and supporting resources. Participants deliberately install and run the client on their own devices rather than joining solely through malware infection. Telegram bots support registration, while public leaderboards and performance-based cryptocurrency rewards incentivize participation. DDoSia followed NoName057(16)'s earlier use of the separate Bobik botnet. Its principal purpose is disruption of service availability; DDoSia activity does not itself establish intrusion or data theft.
Remus is a Windows information stealer marketed through a malware-as-a-service affiliate model since early 2026. Affiliates generate customized payloads with campaign identifiers and operate their own delivery infrastructure. Its collection targets include browser passwords, cookies, session tokens, browser encryption keys, cryptocurrency-wallet data, password-manager data, clipboard contents, screenshots, and selected files. It also collects information from remote-access, VPN, cloud, messaging, and file-transfer applications. Newer versions target locally stored credentials, API tokens, and histories associated with AI assistants and coding tools, including Claude, Cursor, and OpenCode. Stolen session material can enable account access without repeating password or MFA challenges. Remus commonly spreads through ClickFix lures that impersonate CAPTCHA or other verification prompts and persuade victims to execute malicious commands. These lures are delivered through compromised websites, malicious advertising, and email. Other distribution chains use cracked software and trojanized games. Observed delivery components include PLYCHIP, DonutLoader, GoFlateLoader, 2CLoader, and Cruciferra; some chains execute Remus in memory or inject it into legitimate processes. Remus uses browser-process injection to obtain protected browser data. Its evasion techniques include OLLVM-based obfuscation, encrypted system-call references, direct system calls, removal of system-call hooks, and sandbox checks. It profiles compromised systems, including installed security products. Embedded command-and-control configuration and stolen data are protected with ChaCha20, and exfiltration occurs through staged HTTP POST requests. Some subscription tiers support EtherHiding, using Ethereum smart contracts to resolve changing command-and-control infrastructure when embedded destinations are unavailable. Remus exhibits technical similarities to Lumma Stealer, including obfuscation and Chromium credential-extraction techniques.
Amatera Stealer is a Windows information stealer that decrypts stored browser credentials, fingerprints infected hosts, captures screenshots, and collects local data associated with the Cline and Continue AI coding agents. It communicates with command-and-control infrastructure to obtain collection instructions and can download additional payloads. Amatera is distributed through ClearFake and PasteSwitch campaigns using ClickFix social engineering. Compromised websites display fraudulent verification prompts that persuade visitors to execute attacker-supplied commands. Malvertising campaigns also direct users to counterfeit software-download pages. Observed Windows delivery chains use MSHTA and PowerShell or WebDAV-hosted DLLs executed through rundll32. Multi-stage loaders deploy Amatera directly into memory, reducing exposure to file-based detection; associated stages use extensive obfuscation and may disable AMSI or establish scheduled-task persistence. Amatera deployments conceal command-and-control destinations through dead-drop resolver pages and deceptive TLS identity signaling. Observed configurations connect directly to server addresses while presenting Facebook or GitHub identities in TLS SNI or HTTP fields. ClearFake chains delivering Amatera have also deployed ZigCryptoStealer, a Go-based reverse TCP proxy, and NetSupport Manager. One delivery branch is tracked as UAT-10820. Amatera has appeared in opportunistic theft campaigns, including an intrusion observed at a Ukrainian government organization, rather than exclusively targeting that sector.