Files

2.6 KiB

1threatdescriptiondistinct_count_snort_ids
2ArcaneDoorArcaneDoor is a state-sponsored cyberespionage campaign targeting perimeter network devices from multiple vendors, with a particular focus on Cisco Secure Firewall ASA/FTD appliances.2
3AgentTeslaAgentTesla is a widely used .NET-based infostealer that exfiltrates credentials, clipboard data, and keystrokes. It often spreads via phishing emails with malicious attachments.2
4AmadeyAmadey is a lightweight malware primarily used as a loader for deploying additional payloads. It collects system information and often works alongside other malware like SmokeLoader.1
5AsyncRATAsyncRAT is an open-source Remote Access Trojan (RAT) used for remote control, keylogging, and credential theft. It's commonly used by both amateurs and cybercriminals due to its ease of deployment.1
6ChaferChafer is an Iranian nation-state threat group known for cyberespionage against Middle Eastern and Western targets. They primarily target government and critical infrastructure using custom malware.1
7DCRATDCRAT (DarkCrystal RAT) is a modular Remote Access Trojan sold on Russian-speaking forums. It supports plugins for surveillance, data theft, and lateral movement.2
8Lumma StealerLumma Stealer is a commercial credential stealer that exfiltrates browser data, cryptocurrency wallets, and autofill forms. It's often sold as malware-as-a-service (MaaS) to low-skilled actors.3
9NobeliumNobelium is a Russian APT group linked to the SolarWinds supply chain attack. Their operations focus on espionage and long-term access to high-value networks.1
10QuasarQuasar is an open-source RAT that supports remote desktop, file exfiltration, and surveillance. While used legitimately by some, it's also abused in targeted attacks.1
11RemcosRemcos (Remote Control & Surveillance) is a commercial RAT designed for remote access and data exfiltration. It's often distributed via phishing and malspam campaigns.2
12SnakeSnake, also known as Turla or Uroburos, is a sophisticated modular rootkit used for long-term espionage. It's linked to Russian state-sponsored actors and designed for stealth and persistence.1
13Static TundraStatic Tundra is a threat actor that is actively exploiting CVE-2018-0171 in Cisco Smart Install protocol to gain unauthorized access to networks. It's known for its use of Cisco Smart Install protocol to gain unauthorized access to networks.2
14XwormXworm is a customizable .NET-based stealer and RAT that exfiltrates credentials, files, and system data. It's sold on underground forums and used in commodity malware campaigns.2