Active families, ranked. Mallory tracks every named malware family across vendor reports, researcher analysis, and threat feeds, then surfaces the ones gaining velocity right now.
Ranked by Mallory's mention-velocity model across sources.
ClingSTUN is a Linux back-connect proxy backdoor that converts compromised Internet-facing routers, cameras, digital video recorders, and other connected equipment into persistent, remotely controlled proxy nodes. It enables attackers to relay traffic through infected devices, execute commands, and scan for additional vulnerable systems. Identified by Fortinet’s FortiGuard Labs in October 2026, it supports ARM, MIPS, PowerPC, 32-bit x86, and x86-64 architectures. ClingSTUN is deployed through exploitation of approximately two dozen known vulnerabilities across multiple vendors’ products. Initial-access exploits include CVE-2022-36553 in Hytec Inter routers, CVE-2025-34035 in EnGenius products, CVE-2024-23625 in D-Link UPnP services, and CVE-2023-1389 in TP-Link routers. Architecture-specific downloaders retrieve and execute compatible payloads. The backdoor also contains seven hardcoded vulnerability exploits for self-propagation to additional routers and recording equipment. Its operators have not been publicly identified, and no confirmed victim organizations or infection counts have been disclosed. The malware establishes boot-time persistence by creating hidden executable copies and modifying system initialization scripts. It terminates competing processes, disables watchdog timers, and clears its command-line arguments. When running with root privileges, it conceals its process metadata using information copied from the system’s initial process. ClingSTUN abuses legitimate public Session Traversal Utilities for NAT (STUN) services to discover external address and port mappings and maintain NAT bindings. This activity can resemble ordinary VoIP and WebRTC traffic; the public STUN services are not established as compromised or attacker-controlled. Operator control packets can trigger self-propagation or an outbound TCP connection through which commands are retrieved and executed. The complete mechanism by which operators obtain mappings and deliver control traffic through NAT remains unverified.
RedLine Stealer is a .NET-based information stealer targeting Windows systems. First observed in 2020, it is sold through underground forums under a malware-as-a-service model. It steals browser passwords, cookies, authentication tokens, payment-card information, autofill data, VPN credentials, cryptocurrency wallets, and data from messaging applications such as Discord and Telegram. It also collects host information, including usernames, language, time zone, hardware details, running processes, and installed browsers. Stolen cookies and tokens can enable attackers to hijack authenticated sessions without completing additional multifactor authentication challenges. RedLine is distributed through phishing emails, malicious websites impersonating legitimate applications, and downloads masquerading as gaming software or cracked games. SmokeLoader and DarkTortilla have also delivered RedLine; DarkTortilla can execute it through in-memory process injection without writing the main payload to disk. RedLine constructs strings dynamically to impede analysis and string-based detection, and encrypts configuration values using XOR and Base64 encoding. Some deployments have used Windows DiskCleanup scheduled-task hijacking to bypass User Account Control. RedLine has been used by Lapsus$ to steal passwords and session tokens, and by UNC5587 to harvest credentials from infected employee devices. It has also been identified in compromises involving stolen Claude login sessions. Its use spans consumer and enterprise endpoints rather than a single industry, with stolen authentication material supporting subsequent account takeover and organizational intrusion.
Lumma Stealer, also known as LummaC2 or Lumma, is a Windows information stealer distributed through a malware-as-a-service model. Cybercriminal customers rent the malware to harvest browser-stored credentials, cookies, authentication tokens, and session identifiers. Stolen authentication material can enable account takeover and reuse of authenticated sessions without completing multifactor authentication. Its victims include individual users and employees whose compromised endpoints expose personal and enterprise accounts. Distribution mechanisms include cracked-software and key-generator lures and ClickFix campaigns. ClickFix delivery uses fake CAPTCHA pages that copy malicious commands to the clipboard and persuade victims to execute them. Observed infection chains use obfuscated PowerShell to retrieve additional scripts and archives before launching disguised executables. Lumma uses string obfuscation and process injection to hinder detection. Updated variants inject into legitimate Chrome processes, making malicious communications resemble browser activity. Its command-and-control infrastructure can deliver JavaScript that collects detailed browser and system fingerprints, including hardware characteristics, display properties, fonts, plugins, rendering fingerprints, and network information, then exfiltrates the results. Lumma infections have also deployed GhostSocks as a secondary payload. Trend Micro tracks the associated threat activity as Water Kurita. A coordinated law-enforcement and Microsoft operation disrupted LummaC2 in May 2025, but subsequent activity demonstrated that the malware remained operational.
Akira is a ransomware family and closed-affiliate ransomware-as-a-service operation first observed in March 2023. It conducts double extortion by stealing organizational data before encrypting systems and threatening to publish the stolen information. Its encryptors target Windows, Linux, and VMware ESXi environments, with attacks also affecting Hyper-V infrastructure. Variants include the original C++ Windows encryptor and the Rust-based Megazord and Akira_v2 encryptors. Windows variants use ChaCha20 encryption with RSA-4096 protection of encryption keys and can partially encrypt large files to accelerate execution. Akira affiliates commonly obtain access through compromised VPN, RDP, or remote-management credentials, purchased access, and exploitation of vulnerable remote-access or backup infrastructure. Intrusions involve Active Directory and network reconnaissance, credential extraction from memory, directory databases, browsers, and backup systems, followed by lateral movement through RDP, SMB, WMI, SSH, and remote execution tools. Persistence mechanisms include additional administrator accounts, legitimate remote-management software, and encrypted tunnels. Affiliates disable or uninstall endpoint protection, abuse vulnerable drivers, clear event logs, and delete volume shadow copies to inhibit detection and recovery. Data is commonly archived and exfiltrated using legitimate transfer utilities such as Rclone, WinSCP, and FileZilla. Hypervisor targeting enables disruption of multiple virtual machines through a single infrastructure compromise. Tooling and operational tempo vary between affiliates, and some intrusions involve data theft without observed encryption. Akira affects organizations across manufacturing, professional services, technology, finance, education, and healthcare. The associated operation is tracked under names including Storm-1567, Howling Scorpius, GOLD SAHARA, and Punk Spider. Akira shares implementation details with Conti ransomware and is distinct from the unrelated ransomware bearing the Akira name in 2017.
Vidar is a Windows information-stealing malware family first observed in 2018. Written in C++ and sold as customizable malware-as-a-service through underground forums, it collects browser-saved passwords, cookies, authenticated session data, browsing history, cryptocurrency wallet files, sensitive documents, Telegram data, and system information. Vidar 2.0 also includes functionality to harvest locally stored Azure credentials. Stolen credentials and sessions can enable unauthorized access to personal, corporate, financial, and AI-service accounts, including session replay without a new multifactor authentication challenge. Vidar is distributed through fraudulent software installers, cracked-software and key-generator lures, game-cheat offers, malicious repositories, and downloads promoted through video platforms. ClickFix campaigns on compromised websites also deliver it. Other malware, including SmokeLoader and 2CLoader, has been used to deploy Vidar, and it has been observed alongside STOP/Djvu ransomware. UNC5587 has used Vidar to harvest credentials from infected employee devices; the family is not exclusive to a single threat actor or industry. Observed samples perform anti-debugging and environment checks, inject malicious code into legitimate Windows processes, and obtain command-and-control destinations from Steam and Telegram profiles. This profile-based discovery allows operators to change infrastructure without rebuilding the malware. Vidar stages stolen information locally, exfiltrates it, and can delete the staged data before terminating. One analyzed sample exhibited no persistence mechanism. Vidar has progressively strengthened its string obfuscation, moving from XOR to modified ChaCha-based encryption and then lightweight bytecode virtual machines combined with custom stream ciphers. Recent builds vary opcode mappings, keys, constants, substitution tables, and cipher transformations to hinder static detection and automated reverse engineering.
Ploutus is a financially motivated ATM malware family first discovered in Mexico in 2013. It targets Windows-based ATMs and enables jackpotting by issuing unauthorized commands to cash-dispensing modules, bypassing normal bank authorization and transaction validation without debiting customer accounts. Initially associated with NCR machines, later variants expanded support to multiple ATM vendors. Ploutus abuses ATM middleware, including the eXtensions for Financial Services (XFS) layer; Ploutus.D uses the KAL Kalignite framework for multivendor compatibility. Deployment typically requires physical access to ATM internals. Attackers install the malware by connecting external equipment to an ATM hard drive or replacing the drive with one already containing the malware. Operators then activate the malware and direct cash dispensing. Early versions supported commands through an externally attached keyboard, while Ploutus.B could receive SMS cash-out commands through a mobile phone installed inside the ATM. Variants use activation codes to restrict operator access, and later versions introduced remote-management functionality. Some variants incorporate software protections that hinder debugging, reverse engineering, and forensic analysis, along with deletion functionality intended to conceal the compromise. Ploutus has been used in organized criminal operations against banks and credit unions in Latin America and the United States. U.S. authorities have linked Ploutus-enabled ATM-jackpotting conspiracies to Tren de Aragua.
Mirai is a botnet malware family associated with distributed denial-of-service attacks and the compromise of Linux-based Internet of Things devices, routers, cameras, and internet-facing servers. Infected systems provide traffic-generation capacity and can scan for additional exposed hosts to support further propagation. Mirai-family infections exploit weak remote-access credentials and vulnerable services; individual variants differ in their credential-attack and exploitation capabilities. Compromised servers can also participate in scanning and denial-of-service operations, so the family is not limited to embedded devices. The leaked Mirai source code has become a widely reused foundation for botnets and attack modules. Its recognizable components include DDoS command structures, configuration tables, attack-process management, and command-and-control connection logic. EnemyBot incorporates Mirai modules alongside predominantly Gafgyt-derived code, while Evooo1Bot and Datasurge reuse Mirai components for their own operations. Capabilities added by these distinct families are not necessarily present in original Mirai builds. Mirai.Nomi, a variant derived from Mirai LZRD, adds multiple Linux persistence mechanisms, modified executable packing, and a weekly time-dependent domain generation algorithm. It discovers command-and-control addresses through encrypted DNS TXT records and validates server availability before connecting. Its deployment script removes selected files and terminates processes, including competing bots. These modifications illustrate substantial variation within the Mirai ecosystem, particularly in persistence, evasion, and infrastructure discovery.
The Gentlemen is a ransomware family distributed through a Russian-speaking ransomware-as-a-service operation run by GOLD SHERWOOD since mid-2025. It uses double extortion: affiliates steal business data before encrypting systems and threaten to publish the stolen information unless victims pay. The operation targets organizations opportunistically across numerous countries and sectors, including manufacturing, healthcare, technology services, logistics, insurance, pharmaceuticals, and government-related organizations. Ransomware variants support Windows, Linux, and VMware ESXi, with Linux deployments also affecting network-attached storage environments. The Windows encryptor is written in Go. Affiliates commonly obtain initial access by exploiting exposed Fortinet infrastructure, including CVE-2024-55591, or using compromised Fortinet SSL VPN credentials, particularly where multifactor authentication is absent. Subsequent activity includes network and account enumeration, credential dumping, password spraying, privileged-account manipulation, and lateral movement through RDP, PsExec, and other remote-administration mechanisms. Persistent access can be maintained through tunneling services and remote-management tools. Rclone is frequently used for exfiltration, alongside other file-transfer and object-storage utilities. These activities are affiliate intrusion behaviors rather than necessarily native functions of the ransomware executable. Before encryption, affiliates weaken endpoint protection, clear event logs, and disable backup, replication, database, and virtualization-related services. EDR-killing tools include GentleKiller and other utilities that employ bring-your-own-vulnerable-driver techniques. Ransomware deployment has occurred through local execution, PsExec, domain network shares, and malicious Group Policy Objects. In one documented intrusion, a malicious installer impersonating a legitimate Sysinternals utility delivered EtherRAT before subsequent theft and ransomware deployment. Across 15 analyzed intrusions, the median interval from first observed post-compromise activity to encryption was approximately two days, with the fastest taking less than 24 hours. The operation also indexes and categorizes stolen datasets to identify sensitive material and strengthen extortion leverage.
ChocoShell is an in-memory, PowerShell-based information stealer targeting Windows systems. It is used by Storm-2945, an operational sub-cluster of the Russian espionage actor Midnight Blizzard, also known as APT29, in the CaptiveCrunch campaign targeting corporate travelers using hotel, conference-center, and other shared Wi-Fi networks. Compromised captive-portal infrastructure redirects users to fake browser or operating-system updates and ClickFix prompts that induce malware execution. ChocoShell can also be delivered as a companion payload by the CornFlake remote-access trojan. ChocoShell harvests browser session cookies, saved passwords, stored Wi-Fi credentials, and Microsoft 365 single sign-on tokens. It also collects Azure Active Directory access and refresh tokens and Web Account Manager tokens from the Windows Token Broker cache. These stolen authentication artifacts can enable session replay and access to enterprise cloud services without requiring victims to re-enter credentials. Its browser collection functionality targets Chromium-based and Firefox-family browsers, bypasses Chrome App-Bound Encryption, and uses browser debugging functionality to retrieve plaintext cookies. ChocoShell executes entirely in memory, disables the Antimalware Scan Interface through .NET reflection, and uses timing-based sandbox detection to evade analysis. It implements multiple UAC bypass techniques to obtain elevated privileges. The malware retrieves additional tooling and exfiltrates stolen data over HTTPS, disguising command-and-control requests as ordinary web tracking and JavaScript resource traffic.
CornFlake is a Windows remote access trojan used as the primary persistent implant in CaptiveCrunch, an espionage campaign attributed to Storm-2945, an operational sub-cluster of Midnight Blizzard (APT29). Midnight Blizzard is linked by US and UK authorities to Russia’s Foreign Intelligence Service. CornFlake is principally written in Go; a Rust variant was observed in September 2026. The malware provides remote command execution, keylogging, clipboard monitoring, screenshot capture, microphone and webcam surveillance, browser password and cookie theft, Microsoft 365 session-token theft, file exfiltration, removable-media monitoring, and system and security-posture reconnaissance. It establishes encrypted command-and-control communications using ephemeral ECDH P-256 key exchange and a custom encrypted JSON protocol. A local HTTP API supports modular tasking and integration with companion payloads such as the ChocoShell information stealer. Operators manage implants through the FruitStone command-and-control panel. During installation, CornFlake displays a deceptive update or maintenance progress window and masquerades as a legitimate cloud synchronization service. It maintains redundant persistence through Windows services, registry autorun entries, scheduled tasks, and a watchdog that restores removed persistence mechanisms. CaptiveCrunch delivers CornFlake through fake browser or operating-system updates and ClickFix landing pages presented over compromised hotel, conference-center, and other captive-portal Wi-Fi networks. Attackers manipulate DNS and HTTP traffic to redirect connectivity checks to malicious pages, persuading victims to download or execute the payload. The operation targets corporate travelers across multiple sectors and countries.
Cl0p, also written as Clop, is a ransomware family and the name of an associated Russian-speaking ransomware and data-extortion operation. Its campaigns combine data theft with ransom demands, including double extortion through file encryption and threats to publish stolen information. The operation also conducts data-theft-only extortion without deploying an encryptor, using a Tor-hosted leak site to identify victims and publish stolen data. Cl0p has been linked to TA505 and associated with FIN11, but these actor labels should not be treated as interchangeable. The operation is particularly known for mass exploitation of vulnerabilities in enterprise managed-file-transfer and business applications. Campaigns have targeted Accellion FTA, Fortra GoAnywhere MFT, Progress MOVEit Transfer, Cleo file-transfer products, and Oracle E-Business Suite. Documented exploitation includes CVE-2023-0669 in GoAnywhere MFT and CVE-2023-34362 in MOVEit Transfer; attackers associated with Cl0p have also exploited PaperCut vulnerabilities. Compromising systems that aggregate sensitive information enables large-scale data theft and creates exposure for customers and downstream organizations. Victims span multiple industries, including healthcare, manufacturing, and distribution. Recent campaigns increasingly emphasize stolen-data publication and extortion rather than encryption alone.
LockBit is a file-encrypting ransomware family distributed through a financially motivated ransomware-as-a-service operation. Its developers provide ransomware and supporting infrastructure to affiliates that compromise organizations and conduct extortion. Major iterations include LockBit 2.0 and LockBit 3.0, also known as LockBit Black. The family includes Windows payloads and encryptors targeting VMware ESXi infrastructure, enabling disruption of enterprise systems and hosted virtual machines. LockBit attacks combine encryption with data theft and threats to publish stolen information on an extortion site. Affiliates obtain access through initial-access brokers and exploitation of vulnerable internet-facing applications. LockBit-associated attackers have exploited Microsoft Exchange ProxyShell vulnerabilities and CVE-2023-27350 in PaperCut. Windows variants have used the ICMLuaUtil elevated COM interface to bypass User Account Control. Operators have also employed ancillary tools such as AuKill to disable endpoint security before ransomware deployment; these tools are distinct from the ransomware itself. LockBit operations can extend across compromised networks rather than remaining confined to the initial host. Victims span multiple industries, including healthcare, financial services, transportation, and logistics. An international law-enforcement operation disrupted LockBit infrastructure in 2024, after which the FBI obtained thousands of decryption keys to assist victims.
INC Ransom is a financially motivated ransomware-as-a-service (RaaS) operation active since mid-2023. Its operators provide ransomware payloads and extortion infrastructure to affiliates, which conduct intrusions against organizations worldwide. INC Ransom has targeted professional services, particularly law firms, as well as manufacturing, technology, healthcare, construction, and other sectors. The operation uses double extortion: affiliates steal business data and encrypt victim systems, then threaten publication of the stolen material to increase pressure on victims. Observed INC affiliate activity includes exploitation of exposed remote-access infrastructure, including VPN appliances, use of compromised credentials, and abuse of vulnerable SonicWall SMA 1000 devices. Affiliates have performed Active Directory, network-share, virtualization, and backup-infrastructure reconnaissance; moved laterally using RDP, WinRM, SMB, and remote execution tooling; and targeted credential material including Windows directory-service databases, registry credential stores, browser data, DPAPI material, and SSH keys. Data theft has been conducted using cloud-transfer tooling before encryption. INC deployments have affected Windows systems, VMware ESXi hypervisors, Linux systems, and network-attached storage reachable from compromised Windows hosts. The Windows encryptor supports recursive encryption of local and network-share data, selective or partial encryption modes, process and service termination, shadow-copy removal, and path exclusions. Affiliates have also used scheduled tasks to execute tooling and ransomware, and bring-your-own-vulnerable-driver techniques to obtain kernel-level access and impair endpoint security products. Ransom notes threaten data publication and, in some incidents, additional notification of media, employees, partners, and clients.
Mimikatz is a dual-use Windows credential-access utility widely abused in post-exploitation activity by ransomware operators and cyberespionage groups. It extracts authentication material from system memory, including plaintext passwords, password hashes, Windows PIN codes, and Kerberos tickets. Its credential-dumping functionality targets the Local Security Authority Subsystem Service (LSASS), exposing authentication secrets on compromised hosts. Stolen credentials can support access to additional systems and privileged accounts. Mimikatz is available in x86 and x64 builds and is deployed as a standalone utility, incorporated into malicious toolchains, or adapted into customized variants. SafetyKatz and modified Mimikatz builds have been used in intrusions, while pypykatz is a separate Python implementation. Documented users include Akira and Play ransomware operators, Storm-2570, TaskMasters, Chafer, and Tick. Its use spans enterprise Windows environments across numerous industries and countries rather than a specific victim sector. Mimikatz is generally introduced after attackers have obtained access; its presence alone does not establish the initial infection vector or identify a particular threat actor.
BPFDoor is a stealthy backdoor primarily targeting Linux systems, with Solaris variants also documented. It provides covert, long-term access to previously compromised environments and is associated with the China-linked threat actor Red Menshen, also known as Earth Bluecrow. Deployments have targeted telecommunications providers and organizations in government, logistics, education, finance, and retail, particularly across Asia and the Middle East. Its initial deployment mechanism is not consistently established. BPFDoor attaches Berkeley Packet Filter filters to packet sockets to inspect incoming traffic for specially crafted activation packets. This passive activation mechanism avoids a conventional listening port while dormant and can receive triggers before local host firewall filtering. Depending on the variant and authenticated trigger, it can return a status response, establish a bind shell, or initiate a reverse shell. Some variants temporarily manipulate iptables NAT rules to redirect attacker traffic from legitimate service ports to a hidden shell, removing the rules after connection establishment. Analyzed variants incorporating TinyShell functionality support interactive command execution and file uploads and downloads, enabling data exfiltration. Evasion techniques include masquerading as legitimate daemons or appliance-specific software, suppressing shell history, obfuscating strings, and encrypting communications. Older variants execute from shared-memory storage, delete their on-disk executable, and alter file timestamps; newer variants change these behaviors and may use datagram-style packet sockets and SSL-protected communications. South Korean deployments have impersonated SpamSniper components and Oracle-related telecom processes. BPFDoor supports persistent operator access, but analyzed implementations rely on external startup mechanisms rather than an inherent reboot-persistence facility.
Rekoobe is a Linux backdoor written in C and derived from the open-source Tiny SHell codebase. First discovered in 2015, it supports x86, x64, and SPARC architectures and has documented associations with the China-based threat group APT31, also known as Zirconium. It has been deployed against Linux servers in South Korea and observed on Linux-based network-edge email-security appliances. Its core functionality comprises file upload, file download, and remote shell execution, enabling file theft and delivery of additional payloads. Variants support outbound reverse-shell connections or inbound bind-shell access. Rekoobe uses HMAC-SHA1 and AES-128 to protect command-and-control communications and performs an integrity-verification exchange before accepting commands. It can masquerade as legitimate system processes; appliance-oriented builds impersonate components of the South Korean SpamSniper anti-spam product. A BPF-enabled variant inspects selected IPv4 and IPv6 traffic with both source and destination ports set to 25, authenticates incoming triggers, and launches an encrypted reverse shell. This variant also conceals strings and disables shell-history and editor-information recording. Rekoobe has additionally operated alongside the Syslogk kernel rootkit, which hides the user-mode backdoor and remotely starts or stops it through specially crafted TCP packets. In that deployment, Rekoobe masquerades as an SMTP server and opens a shell after receiving a specific command over TLS. Distribution has included software supply-chain attacks involving a compromised WordPress plugin and a malicious Go module impersonating a legitimate cryptographic library. In the Go campaign, credential harvesting and host preparation occur in separate components before Rekoobe is deployed as a follow-on backdoor.
TinyShell is a lightweight, open-source Unix backdoor that provides remote command execution through interactive shells and supports file uploads and downloads. It has been deployed on Linux and Oracle Solaris systems, as well as network appliances including SonicWall Secure Mobile Access devices and Juniper routers running Junos OS. Implementations support outbound reverse-shell connections and listening bind-shell operation, allowing operators to maintain remote access to compromised infrastructure. TinyShell is used as post-exploitation tooling for persistent access in telecommunications espionage and banking intrusions. Its users include LIMINAL PANDA, Red Menshen, UNC3886, UNC4540, and UNC2891. BPFDoor implementations incorporate TinyShell functionality to provide interactive shell sessions and file transfers after activation. In UNC2891 banking intrusions, TinyShell established outbound command-and-control over mobile connectivity from a physically implanted device, bypassing perimeter firewalls. Backdoor processes were disguised as legitimate software and concealed using Linux bind mounts. UNC3886 deployed six customized TinyShell-based backdoors on end-of-life Juniper MX routers, with active and passive communication mechanisms and scripts that disabled logging. The deployment involved exploitation of CVE-2025-21590 to bypass Junos OS Veriexec protections. In UNC4540 operations against SonicWall appliances, TinyShell supplied remote shell access within a larger malware suite whose supporting scripts harvested credentials and maintained access through reboots and firmware upgrades. Credential harvesting and firmware modification were functions of the surrounding tooling rather than established native TinyShell capabilities.
Stealc is a Windows information-stealing malware family implemented in C, advertised on underground forums in January 2023 and identified in the wild in February 2023. It harvests browser passwords, cookies, authentication tokens, autofill information, browsing history, cryptocurrency-wallet data, and application credentials. Its collection capabilities extend to messaging applications, email clients, gaming platforms, and browser extensions. Stealc V2 additionally targets password managers, cloud credentials, VPN and file-transfer applications, sensitive user files, and desktop screenshots. Stealc profiles infected systems by collecting hardware and operating-system details, installed software, and running processes, and generates a hardware identifier for victim tracking. It communicates with command-and-control infrastructure to register infections, obtain collection configuration, and exfiltrate stolen information. It uses dynamic API resolution, obfuscated strings, Base64 encoding, and RC4 encryption. Anti-analysis measures include resource and emulation checks, language-based execution exclusions, configurable expiration dates, and self-deletion. Observed Chrome Application-Bound Encryption bypass implementations extract plaintext cookies from browser process memory; other observed campaigns use browser-focused process injection to obtain credentials and session tokens. Distribution includes ClickFix lures on compromised websites, loader-mediated delivery through MintsLoader and Amadey, and campaigns exploiting the GitLab vulnerability CVE-2023-7028. Stealc is used in commodity cybercrime against Windows users rather than being confined to a single industry. Stolen browser sessions enable account takeover without repeating password or multifactor authentication. Stealc infections have been associated with theft of Claude sessions subsequently abused to consume victims’ usage allowances and incur unauthorized charges.
BlackMatter is a ransomware family and ransomware-as-a-service operation that emerged in July 2021 as a successor to DarkSide and ceased operations in November 2021. Its early payloads closely resembled the final DarkSide versions. Developers supplied configurable ransomware to affiliates, while the operation recruited initial-access brokers and sought compromised networks belonging to companies with annual revenues exceeding $100 million. Targets included organizations in the United States, United Kingdom, Canada, and Australia. Despite publicly declaring restrictions on critical-infrastructure targeting, BlackMatter attacked organizations in the food and agriculture sector and blood-testing facilities. BlackMatter primarily targets Windows systems, with Linux encryptors also developed to attack VMware ESXi environments. Windows payloads use multithreaded, partial-file encryption to accelerate disruption. Anti-analysis techniques include API hashing, anti-debugging, configuration concealment, and decoding executable routines into memory before removing them. The malware supports COM-based UAC bypass, Active Directory enumeration, and deletion of volume shadow copies through WMI to inhibit recovery. Later versions can print ransom notes through available printers. Intrusions relied on compromised corporate credentials and exploitation of vulnerable internet-facing systems, including remote-access and VPN infrastructure. BlackMatter used a double-extortion model, combining encryption with data theft and threatened publication; its operations employed the ExMatter, also known as Fendr, exfiltration tool. Emsisoft privately exploited a flaw in BlackMatter to recover affected victims' files without ransom payments until the operators corrected it. Following the operation's shutdown, existing victims were transferred to LockBit 2.0 infrastructure.
Warlock is a Windows file-encrypting ransomware family that emerged in June 2025. Also referred to as X2anylock, it includes variants derived from the leaked LockBit 3.0 builder. It encrypts victim files and leaves ransom demands, and terminates backup, database, security, and productivity processes and services to increase disruption and hinder recovery. Warlock is deployed by operators tracked as Storm-2603 by Microsoft and Longlegs by Symantec, a threat cluster assessed as having a China nexus. Its campaigns prominently exploit internet-facing, on-premises Microsoft SharePoint Server deployments, including vulnerabilities associated with the ToolShell exploit chain: CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771. Following compromise, operators deploy web shells and steal ASP.NET machine keys to forge signed payloads for further code execution. The surrounding intrusion activity includes credential dumping, Active Directory reconnaissance, lateral movement, DLL sideloading, and abuse of legitimate remote-access tools. Operators maintain access through tools such as Visual Studio Code tunnels, Cloudflare Tunnel, Velociraptor, and Zoho Assist Unattended Agent. They use separate security-disabling utilities, including bring-your-own-vulnerable-driver tooling, before distributing ransomware through domain replication shares and Active Directory Group Policy. Data theft using Rclone has also occurred before encryption; these supporting tools are distinct from the ransomware payload. Victims span critical infrastructure, government, education, technology, manufacturing, and other sectors across multiple regions. Recent campaigns have affected water utilities, telecommunications providers, regional governments, and universities in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. In one critical-infrastructure intrusion, operators disabled security software on at least 40 hosts and subsequently deployed Warlock on at least 33 systems.
Conti is a file-encrypting ransomware family associated with Wizard Spider and a Russian-speaking cybercriminal ecosystem previously involved in Ryuk and TrickBot operations. It was deployed against organizational networks through an affiliate-based ransomware-and-extortion operation. Conti encrypts victim files and demands payment for decryption. On Windows systems, it attempts to terminate services that interfere with encryption, disable real-time security monitoring, and remove Windows Defender. Its operators also steal data and threaten disclosure to pressure victims into paying, using a public name-and-shame site and tools such as Rclone for exfiltration. Conti attack chains have used Emotet malspam infections to obtain initial access, with compromised organizations becoming potential targets for ransomware deployment. TrickBot, Cobalt Strike, and SystemBC were also associated with its operational ecosystem. Cobalt Strike supported attack preparation and follow-on payload deployment; these supporting tools are distinct from the Conti encryptor itself. The operation disbanded in 2022 following leaks of internal communications and source code. Its personnel and tooling subsequently spread into other ransomware operations, including crews linked to Black Basta and Royal/BlackSuit.
TRITON, also known as TRISIS and HatMan, is an industrial-control-system malware framework that targets Schneider Electric Triconex Tricon safety instrumented systems (SIS). It enables remote control of safety controllers and modification of their in-memory firmware, allowing attackers to read and write memory, execute custom code, and undermine the safety functions responsible for emergency shutdowns. The studied variant targets Tricon MP Model 3008 controllers running firmware versions 10.0 through 10.4 and exploits vulnerabilities tracked as CVE-2018-8872 and CVE-2018-7522. The framework uses a compiled Python component on a Windows engineering workstation to communicate with controllers through the proprietary TriStation protocol and deploy an injector and controller-resident payload. Successful payload deployment requires access to the safety network and the controller key switch to be in PROGRAM mode. TRITON masquerades as the legitimate Triconex Trilog application. Its controller payload provides privileged execution and remote control, enabling safety protections to be disabled or manipulated while the system appears to operate normally. TRITON was deployed against a Saudi Arabian petrochemical facility in 2017 after attackers traversed its IT and OT networks. Malware faults caused safety controllers to trigger two automatic emergency shutdowns, exposing the intrusion before its intended effects were fully achieved. Compromising this final automated safety layer could enable physical damage, environmental harm, and loss of life, although those outcomes were not realized in the documented incident. The operation is associated with the threat actor tracked as XENOTIME and TEMP.Veles. U.S. authorities attributed the attack to Russia’s government-controlled Central Scientific Research Institute of Chemistry and Mechanics (TsNIIKhM). Its targeting centers on energy and petrochemical infrastructure using vulnerable Triconex safety controllers.
Mamona is a ransomware family associated with a financially motivated ransomware-as-a-service operation. It encrypts victim files for ransom and operated a dedicated data-leak site. The project was announced in March 2025 by the operator known as "$$$", who was also associated with BlackLock and Eldorado. Mamona has operational and technical connections to BlackLock and the subsequent Global Group ransomware operation. Global Group emerged as a successor and rebranding of the Mamona and BlackLock ecosystem, reusing code artifacts and established backend infrastructure. Windows samples of Mamona and Global Group share an execution-coordination mutex, providing an additional technical link between the families. An analyzed DevMan ransomware sample also exhibits substantial code overlap with Mamona, although this does not establish that all DevMan capabilities are present in Mamona.