Trending Malware
Active families, ranked. Mallory tracks every named malware family across vendor reports, researcher analysis, and threat feeds, then surfaces the ones gaining velocity right now.
Ranked by Mallory's mention-velocity model across sources.
Mention map · Last day
Sized by mentionsTop 24 malware · Last day
Medusa is a Windows ransomware family and ransomware-as-a-service operation first publicly observed in 2021 that evolved from a closed model into an affiliate-based extortion ecosystem around 2023. It has compromised hundreds of organizations, with reporting through April 2026 placing victim counts above 500. Activity has heavily affected critical infrastructure, especially healthcare and public health organizations, but victims have also included entities in education, legal, insurance, manufacturing, technology, finance, municipal government, and professional services across the United States, United Kingdom, Australia, and other regions. Medusa operators commonly obtain initial access through third-party access brokers and by rapidly exploiting newly disclosed vulnerabilities in exposed enterprise software and remote management products. The group has been observed weaponizing public vulnerabilities within 24 hours of disclosure and in some cases before public disclosure. Once inside a victim environment, Medusa actors use credential theft, legitimate administrative tools, living-off-the-land techniques, remote monitoring and management software, and Remote Desktop Protocol to expand access, evade detection, and prepare ransomware deployment. Operationally, Medusa follows a double-extortion model that combines data theft with network encryption and leak-site pressure. Operators exfiltrate sensitive files, disable or terminate security tooling, remove recovery mechanisms such as shadow copies, and encrypt systems across the environment. Reported tradecraft includes security software discovery, credential dumping, lateral movement, use of legitimate remote access platforms, and deployment of vulnerable or stolen drivers to interfere with endpoint defenses. Medusa actors have also been reported to tailor ransom demands based on a victim organization’s revenue and to pressure victims with rapid-payment discounts, paid deadline extensions, and threats to publish or auction stolen data. The malware’s Windows encryptor has been described as capable of identifying security products from hard-coded lists for termination or deletion and of hiding execution windows to reduce user visibility. Medusa has also been associated with fast-moving intrusion patterns in which access, data theft, and encryption occur on compressed timelines. Medusa has been linked in reporting to the threat cluster Microsoft tracks as Storm-1175, a financially motivated actor noted for exploiting internet-facing systems at speed. Separate reporting has also described later campaigns in which Storm-1175 replaced Medusa with another ransomware family. Claims of use by other actors exist, but attribution beyond well-documented overlaps should be treated cautiously. The name Medusa has also been used in unrelated malware reporting for Android banking malware and for a rootkit, but in enterprise intrusion and extortion contexts the widely recognized usage refers to the Windows ransomware operation.
StopAndProtect is a multi-component cybercrime malware operation identified in 2026 that combines ransomware with extensive pre-encryption intelligence collection and theft. The operation relies on large numbers of compromised WordPress websites as distributed infrastructure for payload hosting, command-and-control, and storage of exfiltrated victim data, allowing the actors to blend malicious traffic into legitimate web activity and reduce dependence on dedicated servers. Infections begin with a ClickFix-style fake CAPTCHA lure presented on hacked websites. Victims are socially engineered into pasting and executing a malicious PowerShell command, which launches a multi-stage chain involving PowerShell and .NET loader components. The toolkit is modular and includes a ransomware component known as SilentEncryptor, a stealer known as SilentDataCollector, an SMB and USB propagation component, a VBS spreader, a lock-screen module, and a custom chat utility for operator interaction. StopAndProtect does not appear to encrypt every victim immediately. A defining characteristic of the operation is selective monetization after reconnaissance and theft. SilentDataCollector inventories files across local, removable, and network drives, exfiltrates selected documents and file listings, captures screenshots, logs keystrokes, maps network shares, and steals credentials and cryptocurrency wallet data. Reported functionality also includes harvesting communication-related data and automating collection of WhatsApp contact information through screenshot capture. The presence of a chat utility and operator-directed collection workflows indicates hands-on-keyboard post-compromise activity in at least some intrusions. For propagation and broader compromise, the operation includes components that enumerate network shares, spread through SMB and removable media, and use WMI-based remote execution. The lock-screen component can block user input and display a ransom demand, while the ransomware module can be selectively instructed which hosts to encrypt. This supports a hybrid model of covert theft, lateral movement, and optional ransomware deployment consistent with double-extortion tradecraft. The operation has also been linked to malicious WordPress persistence mechanisms on compromised sites, including hidden upload functionality delivered through custom plugins and must-use plugins that enable remote file upload and code execution. Exposed operator tooling showed the actors could mass-manage compromised WordPress domains, toggle fake CAPTCHA overlays, and deploy or remove files across their infrastructure. Observed victim telemetry indicates broad global impact, with especially high concentrations reported in the United States, Russia, and India. The campaign has targeted Windows endpoints through PowerShell-based execution and used compromised web infrastructure at scale to sustain delivery, control, and exfiltration.
TWINLOOT is a previously undocumented modular Python implant framework designed to conceal command-and-control activity within trusted Microsoft cloud services. It uses SharePoint Online through the Microsoft Graph API for dead-drop tasking and data exchange, Microsoft Teams TURN relays with WebRTC DataChannels for interactive operator access, and the victim’s own headless Microsoft Edge browser to make Graph traffic appear consistent with legitimate user activity. The framework is hardened with PyArmor and appears engineered for stealth, cloud blending, and flexible post-compromise operations. Observed capabilities include arbitrary command execution, credential theft, reverse SOCKS5 tunneling for internal network pivoting, reconnaissance, screenshot capture, and multiple persistence options. Its credential-harvesting component presents a convincing fake Windows lock screen tailored to the victim system and captures entered passwords for exfiltration. For lateral movement and operator interaction, TWINLOOT can expose a reverse SOCKS5 channel that proxies traffic from the compromised host into internal services, enabling follow-on access using stolen credentials. TWINLOOT supports several persistence mechanisms, including COM scriptlet hijacking, GhostTask-style scheduled task persistence, self-update and relaunch logic, and an offline-forged NTUSER.MAN mandatory-profile hive technique that does not require administrative privileges. This NTUSER.MAN method has been described as the first observed malicious in-the-wild use of the so-called Corrupting the Hive Mind persistence approach. The framework also contains an EtherHiding-style blockchain-based configuration retrieval component, although that capability was not used in the analyzed build. The intrusion in which TWINLOOT was uncovered began with Microsoft Teams social engineering in which an external actor impersonated IT support and convinced a user to run a PowerShell command that delivered the Python-based payload. No high-confidence attribution to a known threat actor or previously tracked malware family is currently available, although the operation showed deliberate staging and mature cloud-resident infrastructure preparation.
Pegasus is a commercial mercenary spyware platform developed by NSO Group and used in highly targeted surveillance operations against mobile devices. It is best known for compromising iPhones and Android devices and providing operators with extensive access to device contents and sensors, including messages, emails, photos, contacts, call data, microphone, camera, and location information. Reporting and forensic investigations have repeatedly linked Pegasus activity to surveillance of journalists, activists, lawyers, politicians, diplomats, and other high-risk individuals, and to government customers in multiple countries. Pegasus has evolved from earlier one-click delivery methods to sophisticated zero-click exploitation chains that require no user interaction. Publicly documented delivery vectors have included malicious WhatsApp calls and iMessage-based exploit chains such as FORCEDENTRY and later Pegasus-linked iMessage attacks that bypassed platform protections. These operations have relied on advanced exploit chains for initial access and code execution on fully updated devices, reflecting the high cost and technical sophistication associated with mercenary spyware. Once installed, Pegasus functions as a full-device surveillance implant. Documented capabilities include covert collection of communications and stored data, recording calls, activating microphones, accessing cameras, and extracting sensitive information from the device. The malware has also been described as capable of using methods to remove itself from a device, complicating forensic recovery and attribution. Its use has been central to major investigations into commercial spyware abuse, including cases involving unlawful or politically motivated surveillance and broader concerns about the privatization of offensive cyber capabilities.
SilentDataCollector is a Windows data-theft malware component used in the StopAndProtect cybercrime operation. It functions primarily as a stealer focused on covert collection and exfiltration rather than overt disruption, although it operates alongside other toolkit components including ransomware, propagation modules, and victim-interaction tooling. The malware inventories files across fixed, removable, and network drives, generates file listings, and exfiltrates encrypted data to attacker-controlled infrastructure. It can also collect selected victim files on operator command by compressing, encrypting, and transmitting them for theft. Observed capabilities extend beyond simple file collection. SilentDataCollector has been reported to harvest passwords and cryptocurrency wallet data, and newer versions add keylogging, screenshot capture at regular intervals while the victim is active, and network share mapping and unmapping to facilitate access to remote data sources. It also includes targeted surveillance features for WhatsApp, supporting both web and desktop usage patterns by automating searches for specified contacts and capturing screenshots of contact details. These behaviors indicate hands-on-keyboard use in which operators direct collection priorities and selectively steal information from victims. SilentDataCollector is delivered as part of a multi-stage infection chain associated with StopAndProtect. Initial compromise commonly begins with a ClickFix-style fake CAPTCHA lure that tricks victims into executing PowerShell, followed by .NET loader and downloader stages that deploy final payloads. The broader operation relies heavily on compromised WordPress sites for malware hosting, command-and-control, and storage of stolen data. Victim telemetry and recovered archives indicate broad opportunistic targeting across many countries, with notable concentrations in the United States, Russia, and India. The malware is part of a modular criminal toolkit used for credential theft, surveillance, exfiltration, and post-compromise data collection on infected Windows systems.
Backdoor.Turn is a custom Go-based remote access trojan associated with DragonForce ransomware intrusions. It is notable for abusing Microsoft Teams TURN relay infrastructure to conceal command-and-control traffic inside trusted Microsoft service communications, causing network telemetry to resemble ordinary outbound Teams activity. The malware obtains anonymous Teams visitor access through Microsoft’s Skype-backed identity services, uses legitimate TURN relay infrastructure for connection setup, and then establishes attacker communications over QUIC, reflecting one of the earliest documented in-the-wild implementations of Ghost Calls-style covert tunneling through collaboration platforms. Backdoor.Turn has been observed in an intrusion against a major U.S. services firm in which DragonForce operators reportedly maintained access for roughly one to two months before ransomware deployment. The intrusion likely began through exploitation of an exposed SQL or Microsoft SQL Server system, although brokered access has also been considered. During the operation, the attackers used DLL sideloading, account creation, firewall and security-setting changes, and multi-vector bring-your-own-vulnerable-driver techniques to preserve access and suppress defenses. Functionally, Backdoor.Turn provides remote command execution and process creation on compromised systems. Reported capabilities also include internal network scanning, LDAP and Active Directory enumeration, browser credential theft, and support for credential-based lateral movement. In observed cases, the malware was injected into a legitimate process after ransomware deployment, suggesting use for post-encryption persistence, follow-on access, or resale of retained access. The campaign demonstrates unusually sophisticated tradecraft for a ransomware ecosystem actor and illustrates the growing use of trusted cloud and collaboration infrastructure for defense evasion and covert post-compromise operations.
msaRAT is a Rust-based remote access trojan attributed to the Chaos ransomware group and observed in post-compromise activity prior to ransomware deployment. The malware is designed to conceal command-and-control by delegating external network communications to a locally installed Chrome or Microsoft Edge browser rather than opening outbound connections from the implant process itself. It launches the browser in headless mode with remote debugging enabled, controls it through the Chrome DevTools Protocol, injects JavaScript into a browser tab, and establishes command-and-control over a WebRTC DataChannel. Signaling is performed through a Cloudflare Workers endpoint, while relay traffic is forced through Twilio TURN infrastructure by omitting direct peer-to-peer connectivity options, helping obscure attacker infrastructure and blend malicious traffic into legitimate browser activity. Communications are additionally protected with layered encryption, combining browser-provided DTLS with an inner ChaCha-Poly1305 scheme derived through ECDH key exchange. Observed delivery involved a fake Windows update MSI that loaded the Rust payload directly into memory. The malware supports remote command execution and reliable bidirectional data transfer, and its browser-mediated architecture is intended primarily for defense evasion during the pre-encryption phase of Chaos intrusions. Chaos operators have been associated with spam and voice-phishing initial access patterns and double-extortion ransomware operations targeting large organizations.
BTMOB is an Android remote access trojan derived from the SpySolr family and operated as a malware-as-a-service offering. Emerging in 2025, it is designed to lower the barrier to entry for financially motivated operators by combining a RAT payload with builder and campaign-customization capabilities, allowing buyers to generate localized malicious Android applications and phishing lures without significant technical skill. Activity associated with BTMOB has been observed particularly in Latin America, including Brazil and Argentina, but its lure customization and reseller ecosystem make it adaptable to other regions. BTMOB is commonly distributed through phishing and fake application ecosystems. Operators use counterfeit websites and fake app-store pages that impersonate streaming services, cryptocurrency-related services, government entities, banking themes, and other familiar brands to persuade victims to sideload malicious APKs. Observed campaigns have also used IPTV and streaming-themed lures tied to major events. Social-engineering chains may include messaging-app contact, cloned download pages, and customer-support impersonation. Once installed, BTMOB abuses Android Accessibility Services to obtain elevated privileges and silently grant itself additional permissions. It then establishes command-and-control access that enables persistent remote administration of the device. Reported capabilities include remote control, screen capture and recording, keylogging, message access, camera access, device information collection, command execution, credential theft through phishing or HTML injection workflows, and broader data exfiltration. Some reporting also describes overlay-based theft against banking and payment applications and full-device takeover behavior that extends beyond the scope of a typical banking trojan. BTMOB has been described both as a banking-focused fraud platform and as a broader Android RAT ecosystem. Its commercialization includes builder tooling, operator panels, backend infrastructure, and reseller activity, and later reporting indicates the ecosystem has fragmented beyond a single centrally controlled service. Leaked or resold components have reportedly circulated in underground channels, increasing the likelihood of derivative variants and complicating attribution and tracking. Security vendors have also observed BTMOB integrated into other Android fraud operations as a remote-control module, reinforcing its role as a flexible post-compromise capability for mobile financial crime.
StubMaker is a RubyGems supply-chain malware campaign and associated Windows information stealer delivered through typosquatted Ruby packages. The malicious gems abuse the extconf.rb native-extension installation hook to execute during gem installation, fingerprint the host, and on Windows retrieve and launch a multi-stage payload while making the build process appear legitimate by generating fake extension-build artifacts and stub scripts. The Windows infection chain uses a Rust-based loader that decrypts and manually maps an embedded Go stealer entirely in memory. The embedded payload, internally identified as wincfg, is purpose-built for information theft. It targets Chromium-based browsers to extract saved passwords, cookies, session material, browsing history, extension storage, IndexedDB data, and payment-card information. It also includes functionality to recover Chromium Application-Bound Encryption keys from within browser processes through an embedded DLL, enabling theft from browsers protected by newer credential-encryption mechanisms. Beyond browser theft, StubMaker searches for cryptocurrency wallet data across multiple desktop wallets and browser extensions, scans for seed phrases and validates candidate recovery phrases, and collects Telegram Desktop data. It also gathers host profiling information such as username, hostname, operating-system details, hardware characteristics, and public IP information. Collected data is packaged into an encrypted archive in memory, uploaded to a file-sharing service, and the resulting retrieval link is transmitted to attacker-controlled infrastructure. The campaign has been associated with multiple RubyGems publisher accounts and repeated republication of malicious packages, including reuse of previously yanked gem names. Its targeting is centered on Windows developer systems that install malicious Ruby dependencies. No confirmed persistence mechanism has been established from the available reporting.
Havoc is an open-source post-exploitation command-and-control framework created by C5pider and first released in 2022. It is used for red teaming but has also been adopted in real intrusions by multiple threat actors and intrusion sets, including espionage and financially motivated operators. Havoc consists of a teamserver and operator client and deploys proprietary implant payloads known as Demons. The framework supports payload generation in executable, DLL, and shellcode formats and uses HTTP(S) and SMB for command-and-control communications. On compromised Windows systems, Havoc Demon implants provide flexible post-exploitation capability, including command execution, file transfer, screenshot collection, and in-memory tasking through Beacon Object Files. The framework includes multiple evasion features such as AMSI and ETW patching options, indirect syscalls, stack spoofing, configurable sleep and jitter, and sleep-obfuscation techniques including Ekko, Foliage, and WaitForSingleObjectEx. Havoc payloads have also been observed executed through DLL side-loading and custom loaders such as RemoteInjector and Freeze, including injection into suspended processes. Threat actors have delivered or launched Havoc through several intrusion chains, including PowerShell-based execution, malicious archives and shortcut files, MSI-based staging, trojanized software update workflows, exploitation of public-facing applications, and use of legitimate executables for DLL side-loading. Campaign reporting links Havoc to operations targeting government, military, and critical infrastructure entities in regions including the Middle East, Southeast Asia, and Europe. It has been observed alongside other offensive frameworks such as Cobalt Strike, Sliver, and Mythic, and is frequently used as a modular backdoor during hands-on-keyboard activity after initial access is established. Havoc has become notable both for its operational flexibility and for its growing abuse in the wild. Default protocol and memory artifacts have enabled defensive research into network and memory detection, but operator customization and BOF-based tasking can reduce visibility in conventional logging pipelines.
HOLLOWGRAPH is a Windows espionage backdoor linked with high confidence to the Cavern command-and-control framework. It is implemented as a .NET NativeAOT-compiled DLL and has been observed masquerading as a legitimate library to reduce suspicion. The malware is designed for stealthy post-compromise operations and uses compromised Microsoft 365 mailboxes as covert infrastructure rather than relying on conventional attacker-hosted command-and-control servers. Its defining capability is abuse of the Microsoft Graph API to turn a victim’s Microsoft 365 calendar into a bidirectional dead-drop channel. Operators place encrypted tasking in specially crafted calendar events, and the implant retrieves those instructions through Graph API access. For outbound operations, HOLLOWGRAPH encrypts stolen data and exfiltrates it by creating calendar events with attached payloads. Observed tradecraft includes scheduling malicious events far in the future to reduce the likelihood of user discovery. Communications over the Graph channel are protected with hybrid cryptography using RSA-OAEP and AES-256-GCM, with separate key pairs used for inbound and outbound traffic. HOLLOWGRAPH also maintains a secondary DNS-based channel used to refresh Microsoft Entra ID credentials required for continued Graph API access. Reporting indicates this credential-refresh mechanism uses DNS tunneling over IPv6 AAAA records and writes updated authentication values to local configuration storage. This combination of trusted cloud APIs and DNS-based credential maintenance allows the malware to blend into legitimate enterprise traffic and complicates perimeter-based detection. Observed functionality supports at least two core commands for retrieving operator instructions and sending exfiltrated data. The malware has been associated with targeted espionage activity focused primarily on Israeli organizations, with multiple infected systems identified during activity observed in mid-2026. Researchers noted technical overlaps with Iranian-nexus operations, including similarities to Lyceum-related tradecraft, but direct attribution to a specific named threat actor remains unconfirmed. The strongest supported linkage is to the broader Cavern framework and its modular espionage ecosystem.
Clop, also styled Cl0p, is a ransomware and extortion malware family associated with a long-running financially motivated cybercrime ecosystem often linked to TA505 and FIN11 activity. It is notable for combining conventional ransomware capabilities on Windows systems with large-scale data-theft and leak-site extortion operations. Over time, Clop operations have frequently emphasized theft and public shaming over widespread encryption, particularly in campaigns that exploited zero-day vulnerabilities in enterprise software. Clop has been tied to repeated mass-exploitation campaigns against internet-exposed enterprise platforms, including managed file transfer and related business systems such as Accellion FTA, GoAnywhere MFT, MOVEit Transfer, and PTC Windchill and FlexPLM. In these campaigns, operators exploited server-side vulnerabilities to steal data at scale and then pressured victims through leak-site postings and direct extortion communications. Reported tactics have included emailing employees, customers, and partners of victim organizations to increase pressure, as well as targeting sensitive data belonging to executives and senior managers for additional leverage. On compromised Windows hosts, Clop has demonstrated host and network discovery behavior, including enumerating running processes, identifying antivirus and antimalware-related processes, and enumerating network shares. Reported samples also modify Windows Registry settings and use native Windows APIs for execution and memory operations, including dynamic API resolution and memory allocation. String decryption using simple XOR has also been observed. These behaviors support both ransomware execution and broader post-compromise activity. Clop-linked intrusions have also involved specialized server-side implants. A notable example is a custom JavaServer Pages web shell developed specifically for PTC Windchill and FlexPLM environments. That implant was designed with detailed knowledge of Windchill internals and could decrypt stored application secrets, enumerate file repositories, read and delete files, and load additional Java payloads directly into memory. This reflects a pattern of tailored tooling for data exfiltration from high-value enterprise applications. Victims have spanned many sectors, including manufacturing, retail, energy, healthcare, government, education, and other large enterprises that rely on exposed file-transfer or product lifecycle management infrastructure. Clop is widely recognized for double-extortion operations centered on stolen data publication through a leak site, and for opportunistic exploitation of newly disclosed or zero-day vulnerabilities to generate large victim volumes quickly.
AsyncRAT is an open-source .NET remote access trojan first released publicly in 2019 and widely used in both cybercrime and espionage operations. It is designed to remotely monitor and control compromised Windows systems over encrypted communications and has appeared in campaigns conducted by a diverse set of actors, including financially motivated operators such as TA558 and state-linked espionage groups such as Kimsuky and Confucius. It is also frequently observed alongside other commodity RATs including Quasar RAT, DCRat, Remcos, NanoCore, and njRAT. AsyncRAT is primarily used to establish persistent remote access and support post-compromise control of victim hosts. Reported capabilities include remote system monitoring and control, encrypted command-and-control communications, persistence through scheduled tasks or autorun mechanisms, and concealment of execution through hidden windows. Multiple analyses also associate it with information theft and broader post-exploitation activity. Some campaigns used GitHub-hosted encrypted payloads disguised as benign content, while other reporting notes use of self-signed TLS certificates and certificate pinning to protect command-and-control traffic. Observed delivery chains are varied and reflect its commodity nature. AsyncRAT has been delivered through phishing emails carrying HTML attachments, ZIP archives containing malicious LNK files, Microsoft OneNote attachments with embedded objects, Office documents and template-injection chains, compressed archives, and cloud- or repository-hosted follow-on payload retrieval. In several campaigns, initial execution relied on obfuscated PowerShell, script-based loaders, or DLL sideloading before launching the final RAT payload. It has also been observed hosted on GitHub infrastructure and using services such as ngrok or repurposed domains as command-and-control channels. AsyncRAT is heavily associated with Windows-focused intrusion activity. Targeting linked to its use spans government, academia, diplomacy, defense, manufacturing, hospitality, finance, transportation, security research, and virtual asset sectors across multiple regions, with especially notable activity in South Korea and Latin America. Its open-source availability, low barrier to adoption, and adaptability have made it a durable component of modern phishing-led intrusion chains.
Dridex is a modular Windows banking Trojan and malware delivery platform that emerged from the Cridex/Bugat lineage and became one of the most prevalent financial malware families targeting banks, financial institutions, and their customers. It is strongly associated with Evil Corp and has also been linked in industry reporting to large malspam operations attributed to TA505. Dridex primarily targets English-speaking countries, but infections have been observed globally. Dridex is commonly distributed through phishing and spearphishing email campaigns using business-themed lures and malicious attachments, including macro-enabled Office documents and compressed archives. Campaigns have also used Microsoft Office exploitation, including CVE-2017-0199 and CVE-2012-0158, to achieve execution. In some intrusion chains, Dridex has been delivered by other malware such as Emotet, and it has also been observed as a payload delivered through the SocGholish fake-update framework. Functionally, Dridex is best known for stealing online banking credentials through browser injection, API hooking, and keylogging. It can capture screenshots, download modular components, and communicate over encrypted channels, including RC4-protected traffic and peer-to-peer mechanisms. Stolen data is packaged and transmitted for use in fraudulent wire transfers, ACH fraud, business email compromise, fraudulent account opening, and related financial crime. Dridex infections have also been used to provide footholds for broader post-compromise activity. Beyond credential theft, Dridex has served as an access-enablement and malware delivery platform for follow-on operations, including ransomware deployment. It has been tied to BitPaymer and DoppelPaymer intrusion chains, and Dridex-derived or Dridex-associated activity has overlapped with Locky distribution. Evil Corp historically used Dridex infections as a precursor to targeted ransomware operations before shifting portions of its tooling to other frameworks. Technically, Dridex has employed multiple execution and evasion techniques on Windows, including abuse of regsvr32 and DLL side-loading, as well as anti-debugging through OutputDebugStringW. Its modular architecture, financial focus, and role as both a banking Trojan and an initial-access enabler have made it a durable component of cybercriminal operations for credential theft, fraud, and ransomware staging.
MacSync is a macOS-focused information stealer that has also been observed deploying persistent remote-access functionality. It is associated with multi-stage intrusion chains that rely heavily on social engineering rather than software exploitation, especially ClickFix-style lures that trick users into pasting commands into Terminal. Observed delivery themes include fake software-installation guidance, spoofed GitHub-style download pages, and malvertising-driven lures targeting users seeking popular macOS applications. After execution, MacSync uses native macOS tooling and shell commands to retrieve, decode, and launch additional stages, including in-memory AppleScript components. It performs host profiling, enumerates processes and system details, and attempts to obtain elevated access through repeated password prompts and requests related to Transparency, Consent, and Control permissions such as Full Disk Access and Screen Recording. The malware stages stolen data in temporary locations, compresses it into archives, splits archives into chunks when needed, exfiltrates data over HTTP using recurring request patterns, and removes temporary artifacts after upload. MacSync targets a broad set of user secrets and high-value files. Confirmed collection objectives include browser cookies, saved logins, login databases, session data, browser extension storage, Safari data, Apple Notes, Keychain material, account passwords, Telegram sessions, SSH keys, cloud credentials including AWS material, Kubernetes configurations, and sensitive files from common user directories. It also checks for cryptocurrency wallet applications and related artifacts. Beyond classic infostealing, some observed MacSync chains install a persistent Mach-O remote-access component that survives logon through LaunchAgent-style persistence. Reported post-compromise capabilities include command execution, interactive shell access, file upload and download, and screen capture. MacSync has also been linked to wallet-focused phishing behavior in which trusted wallet-related applications or extensions are spoofed or replaced with trojanized versions to steal cryptocurrency recovery phrases. MacSync has been observed in infrastructure clusters and lure ecosystems shared with other macOS stealers such as Atomic Stealer (AMOS), and multiple campaigns indicate reuse of common templates and rapidly rotating delivery infrastructure. Defensively, the most durable traits are its behavioral patterns: Terminal-driven execution, curl-based retrieval, AppleScript-assisted theft, temporary staging and archive creation, credential-store access, and structured HTTP exfiltration from macOS hosts.
Mimikatz is a widely used open-source Windows post-exploitation tool created by Benjamin Delpy for credential access and abuse of Windows authentication mechanisms. It is best known for extracting credentials from memory, including material from LSASS, and for enabling operators to obtain account secrets useful for privilege escalation, lateral movement, and broader domain compromise. Its functionality has made it a staple in both red-team operations and real-world intrusions by ransomware, espionage, and financially motivated actors. Core capabilities include credential dumping from Windows logon sessions and abuse of Active Directory replication features through modules such as DCSync and DCShadow. DCSync can request directory replication data from domain controllers and retrieve password hashes, including highly sensitive domain secrets when the attacker has sufficient privileges. DCShadow can register a rogue domain controller context and push unauthorized directory changes through replication workflows, enabling stealthy manipulation of Active Directory attributes. Mimikatz is also commonly used in pass-the-hash and related post-compromise activity because the credentials it exposes can be reused to authenticate to additional systems without knowing plaintext passwords. The tool is frequently deployed after initial access rather than serving as the initial infection payload itself. Threat actors have executed it directly, loaded modified variants reflectively or in memory, embedded Mimikatz-like components inside other malware, and downloaded it through PowerShell-based tradecraft. It has been observed in ransomware operations, enterprise intrusions, and webshell-enabled compromises, where it is used to dump credentials, escalate privileges, and accelerate lateral movement across Windows networks. Mimikatz targets Windows environments, especially domain-joined enterprise systems where cached credentials, privileged logon sessions, and Active Directory trust relationships provide high-value opportunities. Because it is a dual-use tool rather than a self-propagating malware family, delivery varies by operator and campaign. Its enduring operational relevance stems from its broad credential-access feature set and its support for high-impact post-exploitation actions in Windows and Active Directory environments.
Amatera Stealer is a Windows-focused malware-as-a-service infostealer and the rebranded successor to ACR Stealer, with reporting also linking its lineage to GrMsk Stealer. It is actively developed and has become a prominent commodity stealer in multiple criminal delivery ecosystems. The malware is written in C++ in widely documented variants, although some campaigns have used multi-stage loaders and wrapper components in other languages before the final Amatera payload is launched in memory. Amatera is designed to steal sensitive data from infected systems, especially browser-stored credentials, cookies and session material, cryptocurrency wallets and wallet browser extensions, password managers, messaging and email application data, SSH and FTP client data, and selected local files. Later versions expanded collection breadth substantially across browsers, wallet extensions, desktop wallet applications, Discord and Signal data, and file-grabber patterns aimed at wallet exports, seed phrases, private keys, passwords, and related documents. A notable capability is its theft of protected Chromium data through browser-memory access and injection-based bypasses for Chrome Application-Bound Encryption. Documented variants locate browser encryption structures in memory, recover master keys, and inject browser-targeting payloads using mapped sections and thread-pool hijacking techniques. Amatera also supports downloading and executing additional payloads, making it useful as both a stealer and a post-compromise staging component. The malware emphasizes stealth and evasion. Reported versions use dynamic API resolution, extensive string and control-flow obfuscation, WoW64 syscall techniques, and direct or indirect syscall trampolines to reduce visibility to user-mode monitoring. Some analyses describe use of NTSockets for low-level HTTP communications, ETW suppression in associated loader chains, anti-debugging checks, anti-analysis logic, geofencing behavior, and reflective in-memory loading that can erase PE-header artifacts after launch. Newer builds also upgraded command-and-control protection from simpler symmetric schemes to ECDH-based key exchange with ChaCha20-Poly1305 in some observed samples. Amatera is commonly delivered through multi-stage intrusion chains rather than as a standalone first-stage payload. Observed delivery ecosystems include ClearFake and ClickFix social-engineering campaigns that trick users into pasting and executing commands, fake CAPTCHA and fake verification pages, compromised websites using EtherHiding to retrieve follow-on infrastructure from blockchain data, fake game, mod, crack, and software downloads delivered through RenPy Loader or related chains, malvertising, and cracked-software distribution. It has also been delivered by other loaders including WordlistLoader, GoFlateLoader, CountLoader, and MSHTA-based chains. Victimology is broad and financially motivated, with campaigns affecting general users and organizations across sectors; finance-sector targeting has been specifically observed. The malware is associated with underground MaaS operations and has been marketed by the actor known as SheldIO under the earlier ACR branding. Amatera is widely tracked as an emerging replacement or alternative to other commodity stealers in the post-Lumma disruption landscape.
REMUS is a Windows information-stealing malware family that emerged in early 2026 and is widely assessed as closely related to, or an evolutionary branch of, Lumma Stealer. It is commonly described as a 64-bit Lumma-derived stealer and has rapidly matured into a malware-as-a-service operation with active feature development, operator support, and affiliate-oriented commercialization. REMUS primarily targets Chromium-based browsers and is built to steal saved credentials, cookies, browser vault data, and cryptocurrency-wallet-related data. Reported collection scope also includes password-manager artifacts, gaming-platform data, FTP client credentials, clipboard contents, screenshots, and enterprise email storage files. Multiple reports indicate an increasing emphasis on session theft and persistent authenticated access, including theft of cookies, tokens, and restore-related artifacts that can support account takeover and bypass of MFA-dependent workflows. A notable technical characteristic is its browser-focused key extraction and decryption workflow. REMUS injects into live browser processes and uses techniques associated with Chromium Application-Bound Encryption bypasses to recover protected browser master keys from memory, enabling decryption of browser secrets. If direct browser-process access fails, it can launch a hidden browser instance on a separate desktop to continue key-recovery operations. The malware has also been reported to read encrypted browser key material from local state data so that stolen browser databases can be decrypted offline after exfiltration. REMUS exfiltrates stolen data over HTTP POST and has used traffic-masking measures such as spoofed headers to resemble legitimate telemetry. Its command-and-control design is notable for dynamic infrastructure resolution through blockchain-based dead-drop techniques, specifically querying an Ethereum smart contract at runtime to obtain current backend information. This allows operators to rotate infrastructure without rebuilding the malware and aligns with broader EtherHiding-style tradecraft seen in contemporary stealer and traffic-distribution ecosystems. Distribution has been strongly associated with fake cracked-software and warez ecosystems, including SEO-poisoned sites impersonating pirated tools and games. Turkish-language lures have been repeatedly observed, suggesting focused targeting of Turkish-speaking users in some campaigns. REMUS has also appeared as a payload delivered by broader malware distribution chains and loaders, including ClickFix-related ecosystems and oversized in-memory loaders used to deploy multiple stealer families. The malware is part of a broader industrialized cybercrime environment in which stealer operators emphasize scalability, log management, delivery workflows, restore mechanisms, and long-term monetization of stolen authenticated sessions. Underground reporting indicates REMUS evolved quickly from a conventional credential stealer into a more mature MaaS platform oriented toward persistent account compromise, session continuity, and resale or abuse of stolen access.
Nezha is an open-source server monitoring and task management platform that has been repurposed by threat actors as covert remote access tooling. In intrusion operations, attackers have used the Nezha agent as a post-compromise foothold to retrieve host information, execute commands, transfer files, open interactive terminal sessions, and manage large numbers of compromised systems from a centralized dashboard. Its legitimate administrative functionality, ordinary monitoring-style network traffic, and broad cross-platform support make it attractive for defense evasion and persistent access. Observed abuse has been linked primarily to suspected China-nexus activity. Nezha has been deployed after exploitation of internet-facing applications and web servers, including compromises involving web shells and log-poisoning techniques, and has also appeared in exploitation chains targeting enterprise infrastructure software. In several campaigns, Nezha served as an operational bridge for follow-on payloads such as Gh0st RAT, Cobalt Strike, Sliver, FRP, cryptominers, and other backdoors. Reporting has also described its use as a botnet-style agent and as remote access tooling in managed service provider and multi-victim intrusion scenarios. Victimology associated with reported Nezha abuse includes organizations and systems in Taiwan, Japan, South Korea, Hong Kong, the United States, Germany, Australia, and Canada, spanning sectors such as government, healthcare, manufacturing, legal services, high technology, and managed service environments. Nezha has been observed on Windows and Linux systems, and reporting also notes use on macOS and router-class or embedded platforms such as OpenWRT. In malicious hands, Nezha functions effectively as a remote access trojan by providing persistent, stealthy post-exploitation control over compromised hosts.