Trending Malware
Active families, ranked. Mallory tracks every named malware family across vendor reports, researcher analysis, and threat feeds, then surfaces the ones gaining velocity right now.
Ranked by Mallory's mention-velocity model across sources.
Mention map · Last day
Sized by mentionsTop 24 malware · Last day
Clop, also styled Cl0p, is a ransomware family and associated ransomware-as-a-service extortion operation active since 2019. It is widely linked to financially motivated intrusion activity associated with TA505 and FIN11, and multiple reports describe affiliates or overlapping operators conducting intrusions on behalf of the broader Clop ecosystem. The malware has been used in both conventional ransomware attacks involving file encryption and in data-theft-led extortion campaigns in which stolen information is used as the primary leverage. Clop has been associated with large-scale exploitation of internet-facing managed file transfer products, most notably Accellion FTA, GoAnywhere MFT, and MOVEit Transfer. In these campaigns, operators exploited zero-day vulnerabilities to steal data from large numbers of organizations and then pressured victims through leak-site postings and direct extortion. Public reporting also links Clop-linked actors to exploitation of PaperCut NG/MF vulnerabilities. In some campaigns, the operators claimed to focus on data exfiltration from the exposed application rather than broad network encryption, while in other incidents Clop was deployed after several days of hands-on intrusion activity. Operationally, Clop incidents have included manual lateral movement and privilege escalation before ransomware deployment, with attackers seeking administrative control to distribute the payload widely. The malware and its operators have been observed enumerating running processes, identifying security products, and discovering network shares. Clop can modify Windows Registry settings and uses native Windows APIs for discovery and execution-related functions. Reported samples also use simple XOR-based string decryption or deobfuscation. Historical reporting notes use of additional tooling such as FlawedAmmyy and Cobalt Strike during the intrusion phase. Clop is notable for aggressive extortion tradecraft. Beyond maintaining a leak site, operators have pressured victims by contacting customers, partners, employees, and executives, and by prioritizing theft of sensitive data from senior leadership workstations to increase coercive leverage. The group has repeatedly targeted organizations across many sectors and geographies, including government, energy, healthcare, education, manufacturing, finance, and technology. Its campaigns have had especially broad impact when tied to mass exploitation of enterprise file-transfer software. Technical reporting describes Clop as a variant within the CryptoMix lineage and notes that some versions delete Volume Shadow Copies. The operation has also been characterized as increasingly extortion-focused, with some recent incidents emphasizing exfiltration and public shaming over encryption. This combination of opportunistic zero-day exploitation, enterprise targeting, and high-pressure double-extortion tactics has made Clop one of the most prominent ransomware threats of recent years.
AsyncRAT is an open-source .NET remote access trojan for Windows that has been widely used in cybercrime and espionage operations since at least 2019. It provides encrypted command-and-control communications and enables remote monitoring and control of compromised systems. Public reporting consistently associates it with credential and information theft, keylogging, surveillance-oriented collection, payload retrieval, and broader post-compromise remote administration. Variants and related tooling have also been observed using self-signed TLS certificates, certificate pinning, mutex-based host marking, and hidden execution techniques to reduce visibility and resist interception or analysis. Operationally, AsyncRAT is commonly deployed as a commodity payload by multiple threat actors rather than being exclusive to a single cluster. It has been used by financially motivated operators such as TA558 in large-scale phishing campaigns, by aviation-focused cybercriminal activity linked by Cisco Talos to a Nigeria-based actor, and in espionage activity attributed to Confucius. It has also appeared in campaigns and infrastructures alongside other commodity malware families including Quasar RAT, DcRAT, Remcos, AgentTesla, XWorm, LodaRAT, RevengeRAT, and njRAT. Some reporting and campaign tracking use RevengeRAT as an alternate name in connection with AsyncRAT-related activity, though DcRAT is separately identified as a clone derived from AsyncRAT source code. Observed delivery vectors are diverse but heavily phishing-centric. Campaigns have used HTML attachments, OneNote documents, Office files with macros or exploit chains, compressed archives, ISO container files, malicious links, and cloud-hosted or tunneled staging infrastructure. Social engineering themes have included invoices, shipping notices, reservations, travel itineraries, aviation incident reports, and order confirmations. AsyncRAT has also been delivered through trojanized or cracked software ecosystems and by malware loaders such as MintsLoader and PrivateLoader. In several campaigns, intermediate scripts or loaders used PowerShell, VBScript, JavaScript, MSBuild inline tasks, template injection, steganographic payload extraction, or in-memory PE loading before launching the final RAT. Capability reporting shows AsyncRAT supporting persistent access and follow-on malware execution in addition to interactive remote control. Documented behaviors include scheduled-task or autorun-based persistence, antivirus and sandbox checks, security-product discovery, hidden execution of scheduled tasks or child processes, and process hollowing or injection into legitimate Windows binaries. Campaign analyses also describe use of AsyncRAT to steal credentials and other sensitive data, log keystrokes, retrieve additional plugins or payloads for in-memory execution, and maintain long-term access to victim environments. It has been used against organizations across hospitality, aviation, government, defense, finance, education, energy, transportation, technology, and other sectors, with notable targeting in Latin America as well as activity affecting Europe, North America, Asia, and Australia.
SocGholish, also known as FakeUpdates, is a long-running JavaScript-based malware delivery framework and loader used to obtain initial access to Windows environments. Active since at least 2017–2018, it is best known for compromising legitimate websites and presenting visitors with fraudulent browser or software update prompts. Victims who execute the downloaded script or archive contents trigger a staged infection chain that profiles the host, performs anti-analysis checks, and retrieves follow-on payloads. SocGholish has been widely used in drive-by-download and watering-hole operations and has also appeared in malvertising and spam-linked delivery chains. The framework commonly relies on injected or obfuscated JavaScript embedded in compromised websites, often loaded through malicious iFrames or similar redirect mechanisms. It selectively targets likely enterprise victims, especially Windows users arriving from third-party referrers, and uses social engineering themed as browser updates for Chrome, Firefox, Edge, Internet Explorer, or Opera. Delivered archives frequently contain obfuscated JavaScript or HTA loaders that execute through Windows scripting components and invoke cmd.exe or PowerShell to contact command-and-control infrastructure and fetch secondary stages. SocGholish functions primarily as an access and payload delivery platform rather than a single fixed payload. Reported follow-on malware includes NetSupport RAT, Dridex, Hades, WastedLocker, Cobalt Strike, BLISTER, ZLoader, Chthonic, and other tooling used for reconnaissance, credential access, lateral movement, and ransomware deployment. In multiple intrusions, SocGholish operators or downstream affiliates used the initial foothold to enumerate Active Directory environments, collect host and security-product information, inject code into legitimate processes, establish persistence, and stage broader post-exploitation activity that culminated in ransomware such as WastedLocker or LockBit. The malware is strongly associated with the Evil Corp ecosystem and has been linked in public reporting to Indrik Spider and related access-broker activity. It has also been observed in broader criminal service relationships, including traffic distribution systems and partnerships that route victims from compromised or repurposed domains into fake-update infrastructure. SocGholish has been described as a major corporate initial access vector and has repeatedly appeared in financially motivated intrusions affecting enterprises across sectors, including education, professional services, manufacturing, energy, transportation, and other organizations with substantial assets. Operationally, SocGholish emphasizes evasion and selectivity. Variants use heavy obfuscation, rotating infrastructure, domain shadowing, staged profiling, anti-VM or anti-analysis logic, delayed execution, and in some cases in-memory payload execution or DLL-based staging. Some campaigns have abused legitimate remote administration software as the final access tool, while others have delivered offensive frameworks that enable privilege escalation, lateral movement, data theft, and ransomware preparation. Its role as a mature, adaptable loader and initial access framework has made it one of the most prominent fake-update malware operations targeting Windows users and enterprise networks.
DcRAT, also known as DarkCrystal RAT, is a Windows-focused .NET remote access trojan and modular backdoor that has been sold on Russian-language underground forums since at least 2018. It is widely regarded as an AsyncRAT-derived family and shares architectural and cryptographic traits with AsyncRAT, including similar certificate handling and configuration patterns. Open-source availability and low barriers to customization have contributed to broad adoption across commodity crimeware operations and targeted intrusion activity. DcRAT is used to establish persistent remote control over infected systems and supports a broad plugin-based feature set. Documented capabilities include credential theft, keylogging, screenshot capture, system reconnaissance, exfiltration, anti-analysis checks, AMSI bypass in some variants, anti-process or security-tool interference, and downloading additional payloads. Multiple analyses also show DcRAT being deployed through crypters and loaders that use process hollowing or other injection techniques to execute the payload inside legitimate Windows processes. Some variants use TLS with self-signed certificates and certificate pinning, reflecting inheritance from AsyncRAT code. Observed delivery chains show DcRAT distributed through phishing and spearphishing, malicious Office documents exploiting CVE-2017-11882 and CVE-2022-30190, social-engineering lures themed around cryptocurrency giveaways, malicious PDF workflows, Signal-delivered lures, cracked-software ecosystems, and multi-stage loader services such as PrivateLoader. It has also appeared in campaigns using obfuscated VBScript, PowerShell, NSIS installers, LNK files, and Python-based packer chains. The malware has been associated with a range of actors and campaigns, from commodity malware distributors to more targeted operations. Reporting has linked DcRAT use to campaigns targeting Ukrainian civil servants, military personnel, defense enterprises, and media organizations, as well as Indian and Afghan government or diplomatic targets. It has also been noted in activity attributed with varying confidence to Sandworm-linked operations and in broader criminal infrastructure alongside other commodity RATs. DcRAT primarily targets Windows environments and is commonly used as a post-compromise access tool that can support follow-on malware deployment, credential collection, surveillance, and broader hands-on-keyboard activity.
Remcos RAT is a Windows remote access trojan that has been active since at least 2016. Originally marketed by BreakingSecurity as a legitimate remote administration tool, it has been widely abused by criminal operators and has appeared across commodity malware campaigns, phishing operations, and multi-stage loader chains. It is frequently associated with other commodity malware ecosystems and has been used or obtained by actors including APT-C-36, as well as in broader criminal operations where families such as AsyncRAT, Quasar RAT, DCRat, ZLoader, IcedID, and GuLoader also appear. Remcos provides full remote control of an infected system and supports a broad post-compromise feature set. Documented capabilities include keylogging, automated screenshot capture, audio recording through the victim microphone, clipboard theft, registry modification, host reconnaissance such as listing installed applications and running processes, shell command execution, file management, password theft through auxiliary tooling, browser-history collection, webcam-module support, and command-and-control communication with optional TLS. It can also execute additional programs, update itself from remote sources, and in some configurations inject or launch payloads inside other processes. The malware commonly establishes persistence through Windows autorun mechanisms, especially Registry Run entries under the current user and, in some configurations, machine-wide autorun locations. It also supports defense-evasion and privilege-related functionality, including hidden-window execution, watchdog behavior, process injection, and UAC bypass or disablement workflows. Analyses have shown Remcos using generated scripts for restart and uninstall operations, mutex-based single-instance control, encrypted configuration storage, and encrypted logging for some collected data. Observed delivery chains show Remcos distributed through phishing emails, malicious Office documents with macros, compressed attachments, and staged script-based infections. It has also been delivered through encoded PowerShell downloaders, cloud-hosted payload retrieval, steganography-assisted loaders, malicious virtual hard disk images, and loader ecosystems such as GuLoader. Lures have included invoices, tax documents, employment-related messages, and other social-engineering themes. In several campaigns, intermediate loaders used process hollowing into legitimate .NET utilities before launching the final Remcos payload. Remcos is broadly used against Windows users and organizations rather than a single vertical, though reporting has tied campaigns to South American entities and to victims in regions including Japan. Its longevity, modular command set, and compatibility with common criminal delivery infrastructure have made it a persistent fixture in commodity intrusion activity.
Quasar RAT is an open-source .NET remote access trojan descended from xRAT and widely used in both criminal and espionage operations. It has appeared in commodity malware campaigns as well as targeted intrusions, including activity linked to Middle Eastern threat actors such as DustySky/Gaza Cybergang and reporting that associates its use with Molerats-related operations. The malware is also frequently observed alongside other commodity RATs such as AsyncRAT, DCRat, XWorm, and Remcos RAT. Quasar RAT provides full remote administration capabilities for Windows systems. Documented functionality includes system and user reconnaissance, file upload and download, execution of additional payloads, process and task management, startup and persistence management, registry editing, remote desktop and desktop observation, remote mouse and keyboard control, reverse proxying, website visitation, message display, and system shutdown or restart. It also includes credential-access features such as theft of passwords from common web browsers and FTP clients, and it has a built-in keylogger. Network communications are encrypted with AES, and the malware can hide process windows and make web requests less visible to the user as part of its defense-evasion behavior. Persistence mechanisms observed for Quasar RAT include scheduled tasks and startup-folder execution. In some campaigns it has been installed by intermediate malware such as the Downeks downloader, and reporting also notes delivery through malicious RAR archives exploiting WinRAR CVE-2025-8088 to place payloads for persistence. Quasar RAT has additionally been distributed through Microsoft OneNote-based email lures that required user interaction to launch embedded content. Broader reporting links the malware to phishing-delivered malicious RAR files and to command-and-control infrastructure hosted on repurposed expired domains. Quasar RAT is commonly masqueraded as legitimate software or system components and is often packed or obfuscated in operational use. Its long-running availability, broad feature set, and ease of customization have made it a durable commodity RAT across cybercrime and state-aligned intrusion activity.
ZimReaper is a browser-resident JavaScript espionage payload used by the Russia-aligned threat actor TA488, also tracked as Laundry Bear and Void Blizzard, in campaigns against Zimbra Collaboration Suite webmail servers. It was deployed through exploitation of CVE-2025-66376, a stored cross-site scripting flaw in Zimbra Classic UI, in so-called half-click attacks where a victim only needed to open or preview a crafted email for code to execute inside an authenticated webmail session. Once executed, ZimReaper harvests mailbox and account-access data from the victim’s Zimbra session. Reported capabilities include theft of CSRF tokens, browser-autofilled or browser-saved passwords, two-factor authentication scratch or recovery codes, Zimbra version and configuration details, and enumeration of the organization’s Global Address List. It also exports and exfiltrates up to roughly 90 days of mailbox contents. Exfiltration has been observed over both HTTP POST and DNS-based channels. ZimReaper also establishes durable access by creating an app-specific password, commonly labeled to resemble legitimate Zimbra usage, enabling continued IMAP, POP3, or SMTP access without normal two-factor authentication prompts. This persistence can survive ordinary password changes unless the unauthorized application password is explicitly removed. The malware has been associated with espionage targeting of Ukrainian government entities, U.S. government and defense-related organizations including nuclear and defense-industrial targets, and additional government, education, transportation, financial, scientific, and other organizations across Europe, NATO countries, the CIS, Africa, and the United States. ZimReaper is notable as the predecessor to OWAReaper, with later tooling retaining substantial behavioral and code overlap. Its use reflects a focused tradecraft pattern of abusing webmail rendering flaws to gain access, steal credentials and communications, and maintain covert mailbox access for intelligence collection.
Mirai is a Linux-based IoT botnet malware family first observed in 2016 that compromises internet-exposed embedded devices and servers, especially routers, IP cameras, DVRs, and other network-connected appliances, and enrolls them into remotely controlled botnets primarily used for distributed denial-of-service attacks. Following the public release of its source code in 2016, Mirai became one of the most widely reused botnet codebases in the IoT threat landscape, spawning numerous variants and derivative families. Mirai commonly propagates by scanning for exposed Telnet and SSH services and attempting brute-force logins with embedded weak or default credentials. Multiple campaigns and variants have also spread through exploitation of known remote code execution and command injection vulnerabilities in routers, cameras, gateway devices, web applications, and server software. Infection chains frequently use shell-script downloaders to fetch architecture-specific ELF binaries, execute them, remove traces, and sometimes alter firewall rules or delete logs to hinder recovery. Once installed, Mirai typically enforces single-instance execution, obfuscates embedded configuration strings, kills competing malware or processes, and connects to command-and-control infrastructure for tasking. Its core functionality centers on DDoS operations, with observed attack methods including TCP, UDP, ICMP, GRE, HTTP, DNS, and amplification-style floods, while many variants extend the original code with additional scanners, exploit modules, proxying, credential capture, or remote shell capabilities. Mirai-derived malware has been observed targeting both consumer and enterprise-facing devices worldwide and has been associated with some of the largest botnet-driven DDoS activity recorded. Mirai has also served as a foundational codebase for later botnets and variants such as IZ1H9, Murdoc Botnet, Evooo1Bot, Omni-derived campaigns, and other Mirai-inspired malware. These descendants have expanded targeting beyond classic IoT devices to include Linux servers, hosting environments, and edge infrastructure, while retaining Mirai’s characteristic scanning, loader-based propagation, process suppression, and flood engines.
OWAReaper is a browser-resident JavaScript backdoor used in espionage operations attributed to the Russia-aligned threat actor TA488, also tracked as Laundry Bear and Void Blizzard. It is designed specifically for persistent compromise of on-premises Microsoft Exchange Outlook Web Access (OWA) by exploiting CVE-2026-42897, a cross-site scripting flaw that allows attacker-controlled JavaScript to execute when a victim opens a crafted email in OWA. The intrusion method has been characterized as a half-click attack because message viewing alone can trigger execution without requiring a link click or attachment open. The implant executes entirely inside the OWA reading pane and is notable for leaving little or no conventional host-level malware footprint. After execution, it can rewrite the original message on the Exchange server to remove exploit content, reducing forensic visibility. OWAReaper collects mailbox and user context information, including account and Outlook configuration details, and attempts credential theft by creating invisible form elements to trigger browser autofill. It also searches for Outlook add-ins with mailbox write permissions and abuses token-access functionality to obtain OAuth tokens. OWAReaper implements multiple persistence mechanisms across both browser and server-side layers. It can store an encrypted copy of itself in browser storage used by OWA so that opening new OWA tabs causes re-execution. It also enables offline caching and poisons OWA's IndexedDB message cache by inserting hidden content into cached messages, allowing reinfection when cached mail is reopened. More significantly, it abuses Exchange folder-permission operations to grant broad mailbox access through the default organizational user context, creating server-side persistence that can survive password changes and even device reimaging until explicitly remediated on the mail server. For command and control, OWAReaper supports covert channels that include retrieving encrypted instructions from GitHub commit messages and parsing specially formatted inbound emails available within the mailbox cache. It supports toolkit replacement, command-and-control rotation, and arbitrary JavaScript execution. Exfiltration is performed primarily over HTTPS using encrypted request paths, with fallback mechanisms including direct server communication and DNS-based exfiltration. Reported targeting has included government entities in the United States and Europe as well as organizations in telecommunications, finance, hospitality, and aerospace. OWAReaper is widely assessed as an evolution of the earlier ZimReaper implant used by the same actor against Zimbra environments.
Emotet is a long-running modular Windows malware family first identified in 2014. It began as a banking trojan focused on credential theft, then evolved into a large-scale malware delivery platform and botnet used to distribute additional payloads including TrickBot, QakBot, Dridex, IcedID, ransomware, and other follow-on tooling. It has been associated with the cybercrime actor commonly tracked as Mealybug and has played a central role in criminal intrusion chains that culminated in high-impact ransomware incidents. Emotet is primarily delivered through phishing emails, especially malicious attachments such as macro-enabled Microsoft Office documents, and has also used links to downloader documents. Social engineering commonly pressures recipients to enable macros, after which script interpreters such as PowerShell are used to retrieve and execute the payload. Once installed, Emotet relocates itself, establishes persistence in user autorun locations and in some cases services, profiles the infected host, and communicates with a distributed command-and-control infrastructure. It has used encrypted host telemetry that includes system identity and running-process information, enabling server-side decisions about whether to deliver updates or additional modules. A defining characteristic of Emotet is its modular architecture. Observed modules and behaviors include banking credential theft, theft of stored passwords and email credentials, harvesting of Outlook contact and message metadata through MAPI, downloading and execution of secondary malware, and spam propagation using stolen email context. Emotet has also been observed loading modules directly in memory, updating itself, and using anti-analysis logic to limit full functionality in suspected research environments. Emotet has demonstrated strong lateral movement and worm-like behavior inside victim networks. Reported propagation methods include brute forcing credentials, writing to shared drives, and deploying a spreader module to move across accessible systems. It has also used process hollowing and other injection techniques, including abuse of legitimate Windows processes, to execute code and access 64-bit components from a 32-bit context. Additional observed tradecraft includes use of password-recovery tooling for credential theft, obfuscated and stack-string-based configuration storage, and use of compromised web servers as reverse proxies to conceal backend command-and-control servers. Operationally, Emotet became one of the most significant criminal malware ecosystems of its era because it functioned as an initial-access and payload-delivery service for other threat actors. Its infections have repeatedly preceded deployment of banking trojans and major ransomware families, making it a frequent precursor to enterprise-wide compromise, data theft, and extortion. Although international law enforcement disrupted the botnet in 2021, Emotet later resurfaced, reinforcing its status as a resilient and highly adaptable malware platform.
Pegasus is a commercial mobile spyware platform developed by NSO Group and sold to government customers for highly targeted surveillance operations. It is widely associated with mercenary spyware activity directed at journalists, activists, lawyers, diplomats, politicians, and other high-risk individuals. Pegasus has been documented on both iPhone and Android devices and is notable for using sophisticated exploit chains, including zero-click techniques delivered through messaging and calling applications such as iMessage and WhatsApp, allowing compromise without meaningful victim interaction in some campaigns. Once installed, Pegasus provides deep access to the victim device and its contents. Reported capabilities include collection of messages, emails, photos, contacts, call records, and other stored data; monitoring of communications; recording of calls; and covert activation of the microphone and camera. Technical analysis of the Android variant also shows functionality for harvesting data from numerous applications, capturing screenshots, extracting attachments, upgrading the implant, and removing itself from the device under operator command or predefined conditions. Pegasus has been described as capable of achieving near-complete visibility into a compromised phone, enabling extensive surveillance and post-compromise collection. Pegasus has figured prominently in multiple public investigations and legal disputes concerning alleged misuse by state customers. Forensic work by organizations including Citizen Lab and Amnesty International has linked Pegasus activity to campaigns affecting civil society, media, and political figures across numerous countries. Public reporting has also tied Pegasus to exploit chains such as FORCEDENTRY and BLASTPASS against Apple devices. Apple has repeatedly cited Pegasus as a historical example of mercenary spyware in its threat-notification program, although not every notification wave has been attributed to NSO Group. Pegasus is one of the most prominent examples of the commercial spyware industry and remains central to debates over cyber-surveillance, export controls, human rights, and the privatization of offensive cyber capability.
Evooo1Bot is a modular Linux botnet derived from the leaked Mirai codebase that targets internet-facing edge and gateway devices, including routers, firewalls, IP cameras, NAS appliances, and other embedded systems. It has been observed exploiting multiple known vulnerabilities in exposed devices from vendors such as Alcatel, D-Link, Mitsubishi Electric, NETGEAR, Tenda, Telesquare, TP-Link, Hikvision, and Zyxel, and it also includes exploit support for enterprise-facing software such as Atlassian Confluence, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI deployments. Successful compromise results in delivery of architecture-matched binaries and enrollment of the device into a botnet. Although it reuses Mirai’s distributed denial-of-service engine, Evooo1Bot significantly expands the framework with encrypted command-and-control communications, layered string obfuscation, anti-analysis checks, persistence mechanisms, SSH brute-force scanning, credential sniffing, file transfer, interactive shell access, and an integrated exploit module. Anti-analysis behavior includes checks for debuggers, security tooling, sandboxes, virtual machines, containers, and honeypots before proceeding. The malware also removes traces of infection activity and uses multiple persistence methods, including init-system integration, shell profile modification, rc.local changes, and recurring scheduled re-download of the payload. A particularly notable feature is its SOCKS5 relay capability, which can expose a compromised device as a proxy or establish a reverse relay channel. This allows operators to convert infected edge devices into persistent traffic relay infrastructure that can conceal attacker origin, support follow-on intrusion activity, and enable pivoting through victim networks. Evooo1Bot also includes an SSH scanner with brute-force capability and honeypot detection logic, as well as a credential sniffer designed to capture authentication material from network traffic. In addition to proxying and post-compromise control, the malware retains Mirai-style DDoS functionality with multiple flood methods. Evooo1Bot has been assessed as more capable than conventional Mirai-derived botnets because it combines botnet operations, remote administration, credential collection, exploit-driven propagation, and proxy enablement in a single Linux malware family.
Graphite is a spyware and espionage implant name used in two distinct malware contexts. The more widely recognized usage refers to Paragon Solutions’ mercenary mobile spyware platform, which has been linked to highly targeted surveillance of journalists, civil society members, and other selected individuals. Graphite has been associated with zero-click exploitation of Apple devices through Messages and iMessage attack chains, including exploitation mitigated in iOS 18.3.1 and tracked as CVE-2025-43200. Public reporting and forensic investigations have tied Graphite activity to compromises of iPhones and Android devices, with capabilities consistent with full-device surveillance, including access to communications and other sensitive device data. Government customers in multiple countries have been publicly associated with deployments of this platform, and investigations have connected it to targeting in Europe and to WhatsApp notifications sent to affected users. The platform is generally characterized as mercenary spyware sold to government agencies for covert surveillance operations. A separate malware family also known as Graphite has been documented in Windows espionage operations linked with low-to-moderate confidence to APT28. In that usage, Graphite is a DLL implant deployed in a multi-stage intrusion chain delivered through spearphishing documents exploiting CVE-2021-40444. The implant uses Microsoft Graph API and OneDrive as command-and-control infrastructure, gathers host reconnaissance data, polls cloud-hosted tasking, uploads encrypted results, and can execute shellcode in memory. Reported follow-on activity included deployment of Empire stagers and persistence via COM hijacking. This Windows Graphite variant was used against government and defense-related targets in Western Asia and Eastern Europe and reflects a tradecraft pattern of abusing legitimate cloud services to reduce detection. Because the Paragon spyware platform is the dominant contemporary reference associated with the name, Graphite is most commonly understood as a mercenary mobile spyware capability, while defenders should remain aware of the separate APT28-linked Windows implant that shares the same name.
Shai-Hulud is a self-propagating software supply-chain malware family associated with TeamPCP and active since at least mid-2025, primarily targeting developer ecosystems and CI/CD environments. It is best known for compromising open-source package distribution channels and abusing stolen developer credentials to spread through legitimate release workflows. Later variants, including the widely reported ChainDrop or CHAINDROP lineage, expanded the family’s reach across npm packages, GitHub repositories, Docker-related environments, OpenVSX and VS Code extension ecosystems, and internal source-code infrastructure. The malware’s core function is credential theft and downstream propagation. It harvests secrets from developer workstations, build runners, and cloud-connected environments, including npm and GitHub tokens, cloud-provider credentials, Kubernetes and Vault secrets, SSH material, CI/CD tokens, AI-tooling credentials, and other sensitive configuration data. Documented behavior includes searching common credential files, shell and environment data, application configuration files, and in some cases process memory on CI runners. Stolen data is typically compressed, encrypted, and exfiltrated through attacker-controlled infrastructure or attacker-created public GitHub repositories under compromised identities. Shai-Hulud spreads by reusing stolen publishing credentials to modify and republish packages that victims can write to, turning compromised maintainers and CI systems into propagation nodes. In GitHub-centric intrusion paths, it can enumerate accessible repositories and branches and commit malicious configuration files that trigger execution when developers open repositories in tools such as VS Code or Claude Code. This enables worm-like spread even without a direct package installation event. Some variants also abused trusted publishing and signed provenance workflows, causing malicious releases to appear to originate from legitimate repositories and automated pipelines. Observed delivery and execution mechanisms include poisoned package releases with install-time hooks, malicious repository configuration files, and broader open-source supply-chain compromise. The family has been linked to large npm outbreaks affecting hundreds of packages and billions of downstream monthly downloads. Reported campaigns also show targeting of cloud, container, cryptocurrency, and AI-assisted development environments, reflecting an emphasis on high-value developer and infrastructure secrets. Shai-Hulud is commonly described as a credential-stealing worm or infostealer with supply-chain propagation features. Its later variants added stronger obfuscation, dynamic command-and-control discovery, IDE and AI-assistant persistence hooks, and the ability to abuse compromised GitHub identities for exfiltration and further repository seeding. The family represents a notable evolution in open-source malware because it combines credential theft, automated republishing, repository poisoning, and developer-tool execution hooks into a single scalable propagation model.
AmnesiaStealer is a multi-stage Rust-based macOS infostealer distributed through ClickFix social engineering. Victims are lured to counterfeit GitHub-themed download pages and tricked into pasting a malicious command into Terminal, which retrieves and launches the malware. The infection chain uses a shell-script dropper followed by a Rust stealer, with an additional on-demand browser-control module. Once executed, AmnesiaStealer performs host reconnaissance and displays a native-looking macOS installer-style password prompt to capture the user’s login credential. It validates the password locally and reuses it to unlock protected data sources. The malware steals Keychain material, Apple Notes data, Telegram session data, Safari data, documents, and extensive data from multiple Chromium-based browsers, including cookies, saved credentials, browsing history, bookmarks, preferences, and extension-related data. It also searches for cryptocurrency wallet-related browser extension data. To reduce user awareness, it can mute system audio before collecting files. A notable capability is its second-stage browser takeover component, which is triggered on demand and uses the Chrome DevTools Protocol to clone and launch a hidden Chromium browser profile under the victim’s authenticated context. This enables live operator interaction with the browser through keyboard and mouse control, session streaming, and plaintext cookie extraction, effectively supporting browser session hijacking in addition to conventional information theft. AmnesiaStealer also attempts macOS-specific privacy and access bypass techniques, including older APFS snapshot and TCC-related methods associated with CVE-2020-9771, although these are reported to be less effective on newer macOS releases. On newer systems, it has been observed attempting a destructive fallback involving browser Safe Storage manipulation to facilitate later decryption of newly protected browser secrets. The malware can establish persistence via a LaunchDaemon masquerading as an Apple crash-reporting component. The malware is named after an associated backend referred to as Amnesia Panel. Shared lure design and tradecraft have been noted alongside campaigns involving Atomic Stealer and MacSync, while Russian-language panel behavior suggests a Russian-speaking operator or developer environment. AmnesiaStealer primarily targets macOS users and is particularly relevant where theft of browser sessions, credentials, cryptocurrency-related data, and personal documents can enable follow-on fraud or account compromise.
CrashStealer is a macOS information-stealing malware family that impersonates Apple’s crash-reporting utility to harvest sensitive user data. It is implemented primarily in native C++ and has been observed using a staged infection chain in which a signed and Apple-notarized installer masquerades as legitimate software, bypasses Gatekeeper trust checks, retrieves additional components, and launches a payload disguised as the system crash reporter. The campaign has been described as targeted, with delivery gated behind a meeting PIN and lures themed as legitimate software installation. Once executed, CrashStealer presents a native-looking macOS authorization prompt to capture the victim’s login password, validates the password locally, and uses it to unlock and copy login Keychain data. It steals credentials and cookies from Chromium-based browsers and Firefox, targets numerous cryptocurrency wallet browser extensions, collects data from multiple password managers, and searches user directories such as Documents and Downloads for files of interest. Stolen data is encrypted client-side with AES-256-GCM, packaged into archives, and exfiltrated to attacker-controlled infrastructure. CrashStealer also establishes persistence on macOS by copying and re-signing itself and installing a LaunchAgent that masquerades as an Apple component. The malware includes multiple anti-analysis and defense-evasion features, including encrypted strings, control-flow obfuscation, anti-debugging checks, and checks for security or analysis tools. Researchers have noted overlaps in objectives with other macOS stealers such as Atomic Stealer (AMOS) and MacSync, but CrashStealer is distinguished by its native C++ implementation, use of notarized delivery, and client-side encryption of stolen data. Activity was observed progressing from apparent development in May 2026 to active in-the-wild deployment by early July 2026. Apple revoked the abused Developer ID associated with the observed delivery chain after it was reported.
MacSync is a macOS-focused multi-stage information-stealing malware family that combines credential theft, browser and wallet data collection, persistent remote access, screen capture, and wallet-focused phishing. It has been observed in social-engineering campaigns that trick users into pasting a malicious command into Terminal, including ClickFix-style lures and malvertising-driven fake installation guides themed around popular software. Delivery tradecraft has included spoofed GitHub-style download pages, sponsored search results, and fraudulent support or installation content hosted on trusted platforms. After execution, MacSync uses staged loaders, including shell and in-memory AppleScript components, to profile the host, request elevated access, and repeatedly prompt for the victim’s macOS password until valid credentials are obtained. It attempts to persuade victims to grant Terminal Full Disk Access, then harvests browser cookies and saved logins, keychain secrets, SSH and cloud credentials, Telegram session data, Apple Notes data, Safari artifacts, and selected user documents. Reported targeting includes Chromium-based browsers, Gecko-based browsers, numerous cryptocurrency wallet browser extensions, and multiple desktop wallet applications. MacSync goes beyond commodity infostealing by installing a persistent native remote-access component on macOS. That component has been reported to support command execution, interactive shell access, file transfer, and screen capture. Persistence has been established through LaunchAgent mechanisms. In cryptocurrency-focused intrusions, MacSync has also replaced legitimate wallet companion applications with trojanized versions that present fraudulent recovery workflows to steal seed phrases before returning the victim to the expected application experience. Researchers have noted tradecraft overlap with Atomic Stealer (AMOS), including similar social-engineering patterns, password-validation logic, and wallet and browser targeting, but MacSync is distinguished by its combination of stealer functionality, persistent RAT behavior, screen-capture support, and wallet-application trojanization. The malware has been associated with campaigns targeting macOS users seeking AI-related software installation guidance, particularly Claude-themed lures.
Atomic Stealer, commonly known as AMOS, is a macOS information stealer operated as a malware-as-a-service offering and widely used in criminal campaigns targeting Apple users. It is designed to harvest browser credentials, stored passwords, session cookies, cryptocurrency wallet data, keychain material, authentication stores, and other sensitive files from infected systems, then exfiltrate the collected data to attacker-controlled infrastructure. Reporting also indicates that by mid-2025 some AMOS activity incorporated an embedded backdoor capability, expanding the family beyond pure data theft. AMOS has been distributed through multiple social-engineering channels, including malvertising, fake software download pages, counterfeit GitHub-themed sites, compromised or look-alike websites, cracked-software lures, and ClickFix-style workflows that trick victims into pasting attacker-supplied commands into Terminal or Script Editor. Observed campaigns have impersonated well-known software brands and used traffic-distribution and browser-fingerprinting gates to selectively expose malicious instructions only to visitors that appear to be genuine macOS users, reducing visibility to scanners and researchers. On execution, AMOS commonly prompts the victim for the macOS system password to unlock access to protected data sources. Its theft objectives include browser data, keychain-related secrets, cryptocurrency wallets, and files useful for account takeover or financial theft. Session-cookie theft is a notable feature because it can enable hijacking of already authenticated web sessions without needing the underlying password. Operators have also advertised features intended to support cookie abuse. The malware has shown active development. Late-2023 updates introduced payload and string encryption or obfuscation to hinder static detection and conceal command-and-control details. AMOS has remained prominent in the macOS crimeware ecosystem and is frequently discussed alongside other macOS stealers such as MacSync, Poseidon, and newer competitors or derivatives. Shared lure templates and overlapping delivery infrastructure observed across campaigns suggest common tradecraft within the broader macOS infostealer landscape. AMOS primarily targets macOS users, including both personal and business victims, with particular relevance to users of web browsers, cryptocurrency wallets, and Apple authentication stores. It has been observed in broad criminal distribution operations rather than a single narrowly scoped intrusion set, and public reporting has not established a definitive attribution to a named state actor.
BlackEnergy is a Windows malware family associated with Russian state activity and widely linked to Sandworm operations. It evolved from earlier bot and DDoS tooling into a modular intrusion platform used for espionage, credential theft, surveillance, and disruptive operations. BlackEnergy has been used against government and industrial targets, and is especially notable for its role in intrusions affecting the Ukrainian energy sector, including operations tied to the 2015 power outages. In those campaigns, operators used BlackEnergy to steal user credentials and support follow-on destructive actions involving KillDisk. The malware supports a plugin-based architecture that enables multiple post-compromise functions. Documented capabilities include screenshot capture, keylogging, process discovery, collection of local network configuration and routing information, theft of credentials from major web browsers, and harvesting of credentials stored by local applications and Windows credential storage mechanisms. BlackEnergy also uses process injection, including injecting a DLL component into a legitimate Windows service host process, and it has been observed attempting to bypass User Account Control on Windows 7 and later to gain elevated execution. For persistence, BlackEnergy 3 drops a primary DLL component and establishes autostart by creating a shortcut in the Windows Startup folder. It also maintains command-and-control resilience through a backup communication channel using a public web service. BlackEnergy is best characterized as a modular backdoor used in targeted intrusion operations, particularly against critical infrastructure and industrial environments.
Linux/Cdorked is a stealthy HTTP backdoor for Apache web servers that was used to hijack legitimate websites and redirect visitors to malicious content, including exploit kits. It is associated with Operation Windigo, a profit-driven server-side malware ecosystem that also included Linux/Ebury, Linux/Onimiki, and Perl/Calfbot. The malware targeted Linux and Unix hosting environments, with reporting repeatedly noting impact on Apache deployments running cPanel, although that did not by itself demonstrate exploitation of a cPanel vulnerability. Linux/Cdorked modifies the Apache httpd binary and keeps operational state in shared memory, minimizing forensic artifacts on disk and complicating detection. Its configuration can be delivered through obfuscated HTTP requests that do not appear in normal Apache logs. The in-memory payload can be cleared by rebooting, but the altered web-server binary remains a durable sign of compromise. Its primary function was web-traffic redirection: visitors to compromised legitimate sites were selectively sent to attacker-controlled infrastructure serving exploit kits such as Blackhole and later Neutrino. In the Windigo operation, these redirects were used to deliver Windows malware to downstream victims, including Glupteba and Boaxxe variants, with payload selection varying by geography. The initial root-compromise vector for affected servers was not conclusively established. Contemporary assessments considered stolen credentials, phishing against administrators, and brute-force access plausible paths, and broader Windigo reporting concluded the operation expanded primarily through credential theft rather than novel Linux vulnerabilities. Linux/Cdorked was notable for its stealth, selective redirection logic, and role in monetizing compromised servers through drive-by malware delivery and traffic brokerage.
Linux/Onimiki is a Linux DNS server backdoor associated with Operation Windigo, a large profit-driven server compromise ecosystem active since at least 2011. It targets systems already running the BIND DNS server and modifies DNS resolution behavior so that specially crafted domain-name patterns can be resolved to attacker-chosen IP addresses without requiring visible changes to normal server-side DNS configuration. This capability allowed compromised DNS infrastructure to support malicious traffic routing and other monetization activity within the broader Windigo operation. Within Windigo, Linux/Onimiki operated alongside other components including Linux/Ebury, an OpenSSH backdoor and credential stealer; Linux/Cdorked, a web redirection backdoor; and Perl/Calfbot, a spam bot. The broader campaign primarily expanded through stolen credentials rather than exploitation of new Linux vulnerabilities, and monetized access through spam distribution, malicious redirections, and drive-by malware delivery. Linux/Onimiki specifically functioned as a covert DNS manipulation component on Linux DNS servers serving legitimate requests, enabling attacker-controlled name resolution while blending into otherwise normal DNS service activity.
FormBook is a long-running Windows information-stealing malware family sold in underground markets as a ready-to-use crimeware offering. It is best known for harvesting credentials and other sensitive data from web browsers and FTP clients, and for using anti-analysis and code-decryption routines to hinder reverse engineering. FormBook has been widely distributed through malspam and phishing campaigns, including invoice-themed and COVID-19-themed lures, and has also been delivered through exploit chains abusing Microsoft Office Equation Editor vulnerability CVE-2017-11882 as well as through commodity loaders such as GuLoader and SmokeLoader. Campaign reporting has shown targeting across multiple sectors, including educational institutions, and broad opportunistic victimization in multiple regions. Operationally, FormBook is associated with credential theft and data exfiltration from infected Windows systems. Reported behavior includes theft of saved credentials from browsers such as Chrome, Firefox, and Opera, as well as theft from FTP applications. Variants have also used process hollowing or related injection techniques to execute within legitimate Windows processes, and some analyses describe persistence mechanisms and extensive defense-evasion features, including debugger detection, hidden execution, anti-analysis logic, and use of randomly selected or legitimate processes to complicate detection. FormBook later evolved into XLoader, a rebranded successor that introduced significant changes including improved command-and-control encryption and expansion beyond Windows to macOS. In Windows-focused reporting, XLoader is repeatedly described as behaviorally similar to FormBook and in some contexts as its direct continuation. Threat reporting has also linked XLoader activity to clusters such as UAC-0041. Despite the rebranding, FormBook remains the more established family name for the original Windows infostealer lineage and is commonly referenced in discussions of commodity credential-stealing malware delivered via phishing and exploit-based infection chains.
POWERSOURCE is a PowerShell-based backdoor associated with FIN7-linked intrusion activity and also discussed alongside DNSMessenger and TEXTMATE. It is a heavily obfuscated and modified derivative of the public DNS_TXT_Pwnage tool and is designed to operate largely in memory while using DNS TXT records as a covert command-and-control channel. Campaigns involving POWERSOURCE used malicious Office documents and VBS-based staging to install the backdoor, and related activity also included spearphishing lures themed as regulatory or business communications. On compromised Windows systems, POWERSOURCE executes through PowerShell and can store decoded payload material in alternate data streams or in the Windows Registry, depending on the PowerShell version and execution context. It has been observed achieving persistence through Registry Run keys, and related reporting also describes use of scheduled tasks and WMI event subscriptions in closely related DNS-based PowerShell intrusion chains. POWERSOURCE queries Registry locations as part of preparing persistence and environment handling. Its core functionality is to establish a covert backdoor over DNS, allowing attackers to deliver additional PowerShell payloads and maintain remote access while blending with routine name-resolution traffic. POWERSOURCE has been used to deliver the second-stage PowerShell backdoor TEXTMATE, which provides an interactive reverse shell, and in some cases has also delivered Cobalt Strike Beacon. The malware has been linked to targeted operations against U.S.-based organizations in sectors including financial services, retail, transportation, education, information technology services, and electronics. The tooling overlap with DNSMessenger and other FIN7 tradecraft has made attribution complex in some reporting, but POWERSOURCE is consistently characterized as a PowerShell backdoor used in targeted post-compromise operations on Windows hosts.