T1588.001: T1588.001
Essential information
- MITRE technique ID
T1588.001- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 27/03/2026 01:10
- Author / Source
- The MITRE Corporation
Aliases
Malware
Platforms
PRE
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | resource-development |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (63)
-
AlienVault Confidence 100
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active …
First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:51 · Modified 04/05/2026 16:33 -
Coquettte usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 12:41 · Modified 21/12/2025 12:41
-
MimiStick usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:27 · Modified 21/12/2025 07:27
-
The MITRE Corporation Confidence 100
[Sea Turtle](https://attack.mitre.org/groups/G1041) is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. [Sea …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
The MITRE Corporation Confidence 100
[TA505](https://attack.mitre.org/groups/G0092) is a cyber criminal group that has been active since at least 2014. [TA505](https://attack.mitre.org/groups/G0092) is known for frequently changing malware, driving global trends in criminal malware distribution, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
The MITRE Corporation Confidence 100
[APT-C-36](https://attack.mitre.org/groups/G0099) is a suspected South America espionage group that has been active since at least 2018. The group mainly targets Colombian government institutions as well as important corporations …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
UAC-0057 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 15:45 · Modified 21/12/2025 15:45
-
The MITRE Corporation Confidence 100
[APT37](https://attack.mitre.org/groups/G0067) is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
SideCopy usesThe MITRE Corporation Confidence 100
[SideCopy](https://attack.mitre.org/groups/G1008) is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. [SideCopy](https://attack.mitre.org/groups/G1008)'s name comes from its …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
The MITRE Corporation Confidence 100
[Earth Lusca](https://attack.mitre.org/groups/G1006) is a suspected China-based cyber espionage group that has been active since at least April 2019. [Earth Lusca](https://attack.mitre.org/groups/G1006) has targeted organizations in Australia, China, Hong Kong, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
ransomhouse usesRansomware.Live Confidence 100
No description available
First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 08:55 · Modified 21/12/2025 02:58 -
Mirai usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 12:57 · Modified 21/12/2025 12:57
-
The MITRE Corporation Confidence 100
[MuddyWater](https://attack.mitre.org/groups/G0069) is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).(Citation: CYBERCOM Iranian Intel Cyber January 2022) Since at …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
The MITRE Corporation Confidence 100
[APT1](https://attack.mitre.org/groups/G0006) is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:57 · Modified 21/12/2025 06:57
-
UNC3886 usesThe MITRE Corporation Confidence 100
[UNC3886](https://attack.mitre.org/groups/G1048) is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
Astaroth usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 02:52 · Modified 21/12/2025 02:52
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 13:07 · Modified 21/12/2025 13:07
-
KONNI usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 01:41 · Modified 22/01/2026 21:32
-
Lazarus usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 21:17 · Modified 29/05/2026 12:20
-
The MITRE Corporation Confidence 100
[LAPSUS$](https://attack.mitre.org/groups/G1004) is cyber criminal threat group that has been active since at least mid-2021. [LAPSUS$](https://attack.mitre.org/groups/G1004) specializes in large-scale social engineering and extortion operations, including destructive attacks without the …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
Prometei usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:03 · Modified 21/12/2025 08:03
-
BackdoorDiplomacy usesThe MITRE Corporation Confidence 100
[BackdoorDiplomacy](https://attack.mitre.org/groups/G0135) is a cyber espionage threat group that has been active since at least 2017. [BackdoorDiplomacy](https://attack.mitre.org/groups/G0135) has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
Earth Baxia usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:15 · Modified 21/12/2025 07:15
-
AMOS threat group usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 15:32 · Modified 21/12/2025 15:32
-
Mallox usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:47 · Modified 21/12/2025 04:47
-
The MITRE Corporation Confidence 100
[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 25/05/2026 11:50 -
Slavic Nation Empire usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:56 · Modified 21/12/2025 07:56
-
APT 41 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:29 · Modified 21/12/2025 04:29
-
Metador usesThe MITRE Corporation Confidence 100
[Metador](https://attack.mitre.org/groups/G1013) is a suspected cyber espionage group that was first reported in September 2022. [Metador](https://attack.mitre.org/groups/G1013) has targeted a limited number of telecommunication companies, internet service providers, and universities …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
Starry Addax usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:39 · Modified 21/12/2025 03:39
-
NetMedved usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 19:02 · Modified 21/12/2025 19:02
-
BlindEagle usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:53 · Modified 27/05/2026 15:52
-
Void Blizzard usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 13:54 · Modified 21/12/2025 13:54
-
Silver Fox usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 00:22 · Modified 21/12/2025 00:22
-
Aquatic Panda usesThe MITRE Corporation Confidence 100
[Aquatic Panda](https://attack.mitre.org/groups/G0143) is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, [Aquatic Panda](https://attack.mitre.org/groups/G0143) has primarily …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[Scattered Spider](https://attack.mitre.org/groups/G1015) is a native English-speaking cybercriminal group active since at least 2022. (Citation: CrowdStrike Scattered Spider Profile) (Citation: MSTIC Octo Tempest Operations October 2023) The group initially …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
TA829 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 14:36 · Modified 21/12/2025 14:36
-
GroozaV2 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 18:01 · Modified 29/05/2026 12:20
-
The MITRE Corporation Confidence 100
[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been known to use tailored phishing lures …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 22/05/2026 04:12 -
TA2541 usesThe MITRE Corporation Confidence 100
[TA2541](https://attack.mitre.org/groups/G1018) is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. [TA2541](https://attack.mitre.org/groups/G1018) campaigns are typically high volume and …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
FlyingYeti usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:31 · Modified 21/12/2025 04:31
-
TeamPCP usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/03/2026 22:18 · Modified 20/03/2026 22:18
-
The MITRE Corporation Confidence 100
[APT32](https://attack.mitre.org/groups/G0050) is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
FamousSparrow usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 13:05 · Modified 21/12/2025 13:05
-
LazyScripter usesThe MITRE Corporation Confidence 100
[LazyScripter](https://attack.mitre.org/groups/G0140) is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.(Citation: MalwareBytes LazyScripter Feb 2021)
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
Winnti usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 22:07 · Modified 20/12/2025 22:07
-
Ghostwriter usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 09:32 · Modified 21/12/2025 09:32
-
Lumma usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 13:01 · Modified 21/12/2025 13:01
-
The MITRE Corporation Confidence 100
[Turla](https://attack.mitre.org/groups/G0010) is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
Twelve usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:19 · Modified 21/12/2025 07:19
-
AISURU relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 17:49 · Modified 21/12/2025 17:49
-
APT36, SideCopy relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:08 · Modified 21/12/2025 06:08
-
The MITRE Corporation Confidence 100
[Andariel](https://attack.mitre.org/groups/G0138) is a North Korean state-sponsored threat group that has been active since at least 2009. [Andariel](https://attack.mitre.org/groups/G0138) has primarily focused its operations--which have included destructive attacks--against South Korean …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
Banana Squad relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 14:19 · Modified 21/12/2025 14:19
-
Candiru relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 21:25 · Modified 20/12/2025 21:25
-
Cavalry Werewolf relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 18:09 · Modified 21/12/2025 18:09
-
The MITRE Corporation Confidence 100
[Contagious Interview](https://attack.mitre.org/groups/G1052) is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
DPRK (North Korea) relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:24 · Modified 21/12/2025 08:24
-
LuminousMoth relatedThe MITRE Corporation Confidence 100
[LuminousMoth](https://attack.mitre.org/groups/G1014) is a Chinese-speaking cyber espionage group that has been active since at least October 2020. [LuminousMoth](https://attack.mitre.org/groups/G1014) has targeted high-profile organizations, including government entities, in Myanmar, the Philippines, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
RapperBot relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 16:58 · Modified 21/12/2025 16:58
-
The MITRE Corporation Confidence 100
[Saint Bear](https://attack.mitre.org/groups/G1031) is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
Sharp Dragon relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:57 · Modified 21/12/2025 04:57
Malware (109)
-
Mirai usesFamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
Margulas RAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:55 · Modified 21/12/2025 13:07
-
Mythic usesFamilyPublished 11/08/2025 14:56 · Modified 11/08/2025 14:56
-
Mallox usesFamilyPublished 25/10/2024 20:49 · Modified 25/10/2024 20:49
-
MeltingClaw usesFamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
AMOS Stealer usesFamilyPublished 11/05/2026 11:49 · Modified 11/05/2026 11:49
-
Aisuru usesFamilyPublished 29/01/2026 03:42 · Modified 29/01/2026 03:42
- Winnti
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
-
PylangGhost usesFamilyPublished 18/03/2026 10:49 · Modified 18/03/2026 10:49
-
Totbrick usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
Raccoon Stealer V2 usesFamilyPublished 03/04/2025 17:18 · Modified 03/04/2025 17:18
-
Oyster usesFamilyPublished 08/06/2026 19:36 · Modified 08/06/2026 19:36
-
Sliver usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
SingleCamper usesFamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
Vidar usesFamilyPublished 16/06/2026 09:50 · Modified 16/06/2026 09:50
-
Syncro usesFamilyPublished 23/02/2026 09:34 · Modified 23/02/2026 09:34
-
DcRAT usesFamilyPublished 01/03/2026 05:26 · Modified 01/03/2026 05:26
-
Korplug usesThe MITRE Corporation Confidence 100
[PlugX](https://attack.mitre.org/software/S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.(Citation: Lastline PlugX Analysis)(Citation: FireEye Clandestine Fox Part 2)(Citation: New DragonOK)(Citation: …
First seen 01/01/1970 · Last seen 16/11/5138 Published 31/05/2017 23:32 · Modified 08/06/2026 10:23 - Shamoon
- Oblique RAT
-
ShadowPad - S0596 usesFamilyPublished 30/04/2026 19:11 · Modified 30/04/2026 19:11
-
DocConnect usesFamilyPublished 19/02/2026 11:10 · Modified 19/02/2026 11:10
-
Amadey - S1025 usesFamilyPublished 29/09/2025 08:06 · Modified 29/09/2025 08:06
-
EAGLEDOOR usesFamilyPublished 20/09/2024 11:22 · Modified 20/09/2024 11:22
-
RokRAT usesFamilyPublished 05/02/2025 16:10 · Modified 05/02/2025 16:10
-
ShadyHammock usesFamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
DoppelPaymer usesFamilyPublished 16/05/2025 16:33 · Modified 16/05/2025 16:33
-
Manuscrypt usesFamilyPublished 30/01/2026 08:48 · Modified 30/01/2026 08:48
-
LOTUSLITE usesFamilyPublished 22/04/2026 01:40 · Modified 22/04/2026 01:40
-
PrivateLoader usesFamilyPublished 14/01/2025 15:22 · Modified 14/01/2025 15:22
-
BeaverTail usesFamilyPublished 21/04/2026 12:09 · Modified 21/04/2026 12:09
-
Quasar RAT usesFamilyPublished 15/05/2026 15:23 · Modified 15/05/2026 15:23
-
Grooza usesFamilyPublished 01/10/2025 08:00 · Modified 01/10/2025 08:00
-
RIPCOY usesFamilyPublished 20/09/2024 11:22 · Modified 20/09/2024 11:22
- Trojan.Karagany
-
HemiGate usesFamilyPublished 26/03/2025 20:15 · Modified 26/03/2025 20:15
-
Metasploit usesFamilyPublished 03/02/2026 08:21 · Modified 03/02/2026 08:21
- AlienReverse
-
SmartLoader usesFamilyPublished 13/08/2025 15:43 · Modified 13/08/2025 15:43
-
UniShadowTrade usesFamilyPublished 04/10/2024 10:27 · Modified 04/10/2024 10:27
-
WormGPT usesFamilyPublished 20/12/2024 15:25 · Modified 20/12/2024 15:25
-
VSHELL usesFamilyPublished 05/05/2026 14:07 · Modified 05/05/2026 14:07
- Mario
-
LilithRAT usesFamilyPublished 10/11/2025 11:14 · Modified 10/11/2025 11:14
-
RftRAT usesFamilyPublished 18/03/2026 10:49 · Modified 18/03/2026 10:49
-
Lumma usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:50 · Modified 21/12/2025 16:13
- Mélofée
-
Rugmi usesFamilyPublished 04/04/2025 19:54 · Modified 04/04/2025 19:54
- Candiru
-
Shamoon - S0140 usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
Contagious Trader usesFamilyPublished 18/03/2026 10:49 · Modified 18/03/2026 10:49
-
Penguish usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:17 · Modified 21/12/2025 13:21
-
Ares RAT usesFamilyPublished 23/05/2025 09:59 · Modified 23/05/2025 09:59
-
Atera usesFamilyPublished 17/04/2026 23:18 · Modified 17/04/2026 23:18
-
DustyHammock usesFamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
PlugX - S0013 usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
RapperBot usesFamilyPublished 03/09/2025 05:57 · Modified 03/09/2025 05:57
-
LummaC2 usesFamilyPublished 16/01/2026 20:33 · Modified 16/01/2026 20:33
-
Hive usesFamilyPublished 11/04/2025 09:39 · Modified 11/04/2025 09:39
-
ShadowV2 usesFamilyPublished 27/11/2025 07:37 · Modified 27/11/2025 07:37
-
FoalShell usesFamilyPublished 02/10/2025 09:42 · Modified 02/10/2025 09:42
-
SparrowDoor usesFamilyPublished 26/03/2025 20:15 · Modified 26/03/2025 20:15
-
Remcos RAT usesFamilyPublished 17/06/2026 18:20 · Modified 17/06/2026 18:20
-
StallionRAT usesFamilyPublished 02/10/2025 09:42 · Modified 02/10/2025 09:42
-
Salty2FA usesFamilyPublished 02/12/2025 21:13 · Modified 02/12/2025 21:13
-
Kryptina usesFamilyPublished 24/09/2024 14:42 · Modified 24/09/2024 14:42
-
GoldPickaxe usesFamilyPublished 20/02/2025 20:48 · Modified 20/02/2025 20:48
-
STARKVEIL usesFamilyPublished 28/05/2025 17:57 · Modified 28/05/2025 17:57
-
LockBit Black usesFamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
GRIMPULL usesFamilyPublished 28/05/2025 17:57 · Modified 28/05/2025 17:57
-
MARSSTEALER usesFamilyPublished 14/01/2025 15:22 · Modified 14/01/2025 15:22
- Karkadann
-
Geta RAT usesFamilyPublished 29/07/2024 10:59 · Modified 29/07/2024 10:59
-
RemcosRAT usesFamilyPublished 22/04/2026 07:06 · Modified 22/04/2026 07:06
-
TrickBot - S0266 usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
Rhadamanthys usesFamilyPublished 29/04/2026 02:24 · Modified 29/04/2026 02:24
-
Spark RAT usesFamilyPublished 08/04/2025 19:06 · Modified 08/04/2025 19:06
-
SYS01 usesFamilyPublished 04/11/2024 10:12 · Modified 04/11/2024 10:12
-
NetSupport RAT usesFamilyPublished 22/05/2026 13:08 · Modified 22/05/2026 13:08
-
Guildma usesFamilyPublished 19/05/2026 22:26 · Modified 19/05/2026 22:26
-
EndRAT usesFamilyPublished 18/03/2026 10:49 · Modified 18/03/2026 10:49
-
SWORDLDR usesFamilyPublished 20/09/2024 11:22 · Modified 20/09/2024 11:22
- MrAgent
-
InvisibleFerrett usesFamilyPublished 18/03/2026 10:49 · Modified 18/03/2026 10:49
-
PacketCrypt usesFamilyPublished 20/02/2025 13:44 · Modified 20/02/2025 13:44
-
COOKBOX usesFamilyPublished 31/05/2024 12:19 · Modified 31/05/2024 12:19
-
Poseidon usesFamilyPublished 01/08/2025 12:31 · Modified 01/08/2025 12:31
-
QuasarRAT usesFamilyPublished 25/02/2026 11:35 · Modified 25/02/2026 11:35
-
Lumma Stealer usesFamilyPublished 08/06/2026 19:36 · Modified 08/06/2026 19:36
- HelloBot
-
Caminho usesFamilyPublished 17/12/2025 02:49 · Modified 17/12/2025 02:49
-
BigSquatRAT usesFamilyPublished 18/03/2026 10:49 · Modified 18/03/2026 10:49
-
Auto-Color usesFamilyPublished 21/05/2025 23:03 · Modified 21/05/2025 23:03
-
FROSTRIFT usesFamilyPublished 28/05/2025 17:57 · Modified 28/05/2025 17:57
-
DISGOMOJI usesFamilyPublished 29/07/2024 10:59 · Modified 29/07/2024 10:59
-
FlexStarling usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:39 · Modified 21/12/2025 03:39
-
GolangGhost usesFamilyPublished 18/03/2026 10:49 · Modified 18/03/2026 10:49
-
AllaKore RAT usesFamilyPublished 21/08/2025 16:16 · Modified 21/08/2025 16:16
- AceCryptor
-
Rescoms usesFamilyPublished 25/05/2025 17:47 · Modified 25/05/2025 17:47
-
Redline usesFamilyPublished 08/05/2026 11:31 · Modified 08/05/2026 11:31
-
Ailurophile Stealer usesFamilyPublished 09/09/2024 09:26 · Modified 09/09/2024 09:26
-
AIRASHI usesFamilyPublished 25/09/2025 09:20 · Modified 25/09/2025 09:20
-
Chaos RAT usesFamilyPublished 06/06/2025 11:02 · Modified 06/06/2025 11:02
- Capra RAT
-
SlipScreen usesFamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
PowerShower - S0441 usesFamilyPublished 22/05/2026 13:08 · Modified 22/05/2026 13:08
-
Broomstick usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
Reports (50)
-
AlienVault Confidence 100 20 MITREs 1 IOC 1 ObservablePublished 11/06/2026 23:09 · Modified 15/06/2026 19:16 · threat-report
-
AlienVault Confidence 100 20 MITREs 7 IOCs 7 Observables 1 APTPublished 11/06/2026 23:09 · Modified 15/06/2026 19:16 · threat-report
-
17 MITREs 2 Malwares 13 Observables 1 APTPublished 13/04/2026 14:40 · Modified 13/04/2026 14:48
-
8 MITREs 1 Observable 1 APTPublished 25/03/2026 10:38 · Modified 27/03/2026 00:08
-
20 MITREs 7 Malwares 5 Observables 1 APTPublished 18/03/2026 10:49 · Modified 18/03/2026 11:21
-
9 MITREsPublished 17/12/2025 21:22 · Modified 21/12/2025 19:35
-
19 MITREs 2 Malwares 24 Observables 1 APTPublished 17/12/2025 02:49 · Modified 21/12/2025 19:33
-
9 MITREs 1 Malware 37 Observables 1 APTPublished 10/12/2025 17:22 · Modified 21/12/2025 18:58
-
4 CVEs 9 MITREs 2 Malwares 6 ObservablesPublished 09/12/2025 12:50 · Modified 21/12/2025 18:50
-
10 MITREs 2 Malwares 1 APTPublished 02/12/2025 21:13 · Modified 21/12/2025 18:19
-
18 MITREs 2 Malwares 38 Observables 1 APTPublished 26/11/2025 09:39 · Modified 21/12/2025 18:02
-
1 CVE 13 MITREs 1 Malware 40 ObservablesPublished 23/10/2025 13:40 · Modified 23/10/2025 14:11
-
9 CVEs 18 MITREs 2 Malwares 11 Observables 1 APTPublished 25/09/2025 09:20 · Modified 25/09/2025 14:48
-
An emerging DDoS for hire botnet related12 MITREs 1 MalwarePublished 25/09/2025 09:20 · Modified 25/09/2025 14:58
-
14 MITREs 1 Malware 17 ObservablesPublished 16/09/2025 14:29 · Modified 16/09/2025 14:42
-
Like PuTTY in Admin's Hands related16 MITREs 2 MalwaresPublished 27/08/2025 16:22 · Modified 27/08/2025 19:43
-
14 MITREs 1 Malware 1 APTPublished 20/08/2025 17:38 · Modified 20/08/2025 21:20
-
14 MITREs 4 Malwares 11 ObservablesPublished 13/08/2025 15:43 · Modified 13/08/2025 15:48
-
Fake Tesla Websites Scams related4 MITREsPublished 10/08/2025 20:55 · Modified 11/08/2025 14:11
-
14 MITREs 5 ObservablesPublished 04/08/2025 16:13 · Modified 04/08/2025 21:00
-
19 MITREs 9 Malwares 103 Observables 1 APTPublished 01/07/2025 08:07 · Modified 01/07/2025 08:36
-
8 MITREs 2 Observables 1 APTPublished 19/06/2025 22:30 · Modified 23/06/2025 23:01
-
5 MITREs 1 Malware 17 Observables 1 APTPublished 06/06/2025 12:45 · Modified 08/06/2025 17:09
-
13 MITREs 1 Malware 23 ObservablesPublished 06/06/2025 11:02 · Modified 08/06/2025 17:04
-
8 MITREs 71 ObservablesPublished 20/05/2025 21:16 · Modified 21/05/2025 22:05
-
1 CVE 14 MITREs 1 Malware 1 Observable 1 APTPublished 16/05/2025 16:33 · Modified 21/05/2025 20:49
-
10 MITREs 6 Malwares 2 ObservablesPublished 14/05/2025 13:56 · Modified 21/05/2025 19:59
-
9 MITREs 87 ObservablesPublished 06/05/2025 15:50 · Modified 06/05/2025 20:16
-
4 MITREsPublished 26/04/2025 09:40 · Modified 28/04/2025 08:51
-
13 MITREs 2 MalwaresPublished 11/04/2025 09:39 · Modified 11/04/2025 16:14
-
Where to Find Aspiring Hackers related11 MITREs 7 Malwares 1 APTPublished 04/04/2025 19:54 · Modified 07/04/2025 08:04
-
13 MITREs 6 Malwares 6 Observables 1 APTPublished 03/04/2025 17:18 · Modified 03/04/2025 18:31
-
21 MITREs 3 Malwares 12 Observables 1 APTPublished 26/03/2025 20:15 · Modified 26/03/2025 20:51
-
18 MITREs 2 MalwaresPublished 20/02/2025 13:44 · Modified 21/02/2025 15:29
-
1 CVE 10 MITREs 2 Malwares 16 ObservablesPublished 20/02/2025 02:49 · Modified 20/02/2025 08:58
-
9 MITREs 1 Malware 1 APTPublished 05/02/2025 16:10 · Modified 05/02/2025 21:48
-
10 MITREs 3 Malwares 4 ObservablesPublished 03/02/2025 03:58 · Modified 03/02/2025 11:42
-
1 CVE 7 MITREs 1 Malware 25 Observables 1 APTPublished 24/01/2025 13:30 · Modified 24/01/2025 14:24
-
14 MITREs 10 MalwaresPublished 14/01/2025 15:22 · Modified 15/01/2025 19:48
-
17 MITREs 1 Malware 1 APTPublished 09/01/2025 08:56 · Modified 09/01/2025 09:38
-
9 MITREs 6 ObservablesPublished 07/01/2025 14:23 · Modified 07/01/2025 16:36
-
7 MITREs 2 Malwares 5 ObservablesPublished 20/12/2024 15:25 · Modified 20/12/2024 16:41
-
16 MITREs 1 MalwarePublished 18/12/2024 18:13 · Modified 18/12/2024 19:37
-
6 MITREsPublished 22/11/2024 04:49 · Modified 22/11/2024 09:24
-
8 MITREs 2 ObservablesPublished 22/11/2024 04:49 · Modified 22/11/2024 09:24
-
3 CVEs 14 MITREs 2 Malwares 25 ObservablesPublished 19/11/2024 21:59 · Modified 20/11/2024 09:22
-
16 MITREs 1 Malware 26 ObservablesPublished 04/11/2024 10:12 · Modified 04/11/2024 11:32
-
15 MITREs 2 Malwares 1 Observable 1 APTPublished 25/10/2024 13:53 · Modified 25/10/2024 15:52
-
1 CVE 12 MITREs 1 Malware 2 Observables 1 APTPublished 23/10/2024 11:07 · Modified 23/10/2024 13:19
-
9 MITREs 3 Malwares 171 Observables 1 APTPublished 18/10/2024 15:56 · Modified 18/10/2024 16:26
Vulnerabilities (CVE) (33)
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via …
- Attack vector
- Network
- Published
- 20/05/2024
- Modified
- 29/05/2026
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of …
- Attack vector
- NETWORK
- Published
- 08/07/2024
- Modified
- 21/12/2025
The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie …
- Published
- 20/12/2025
- Modified
- 21/12/2025
A vulnerability was found in LB-LINK AC1900 Router 1.0.2 and classified as critical. Affected by this issue is the function websGetVar of …
- Attack vector
- NETWORK
- Published
- 24/02/2025
- Modified
- 21/12/2025
Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command injection via shell metacharacters in …
- Attack vector
- NETWORK
- Published
- 11/07/2025
- Modified
- 21/12/2025
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, …
- Attack vector
- Network
- Published
- 19/05/2025
- Modified
- 21/12/2025
RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim …
- Attack vector
- Network
- Published
- 09/06/2025
- Modified
- 21/12/2025
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
- Attack vector
- Network
- Published
- 04/10/2023
- Modified
- 29/05/2026
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, …
- Attack vector
- NETWORK
- Published
- 28/01/2020
- Modified
- 21/12/2025
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file …
- Attack vector
- Local
- Published
- 24/08/2023
- Modified
- 27/05/2026
- Published
- 20/12/2025
- Modified
- 21/12/2025
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to …
- Attack vector
- Network
- Published
- 10/06/2025
- Modified
- 21/12/2025
A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing …
- Attack vector
- NETWORK
- Published
- 13/04/2024
- Modified
- 21/12/2025
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON …
- Attack vector
- NETWORK
- Published
- 06/01/2023
- Modified
- 21/12/2025
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An …
- Published
- 14/06/2022
- Modified
- 27/05/2026
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be …
- Attack vector
- Network
- Published
- 16/06/2025
- Modified
- 21/12/2025
VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 …
- Published
- 03/11/2021
- Modified
- 21/12/2025
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted …
- Published
- 03/11/2021
- Modified
- 21/12/2025
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out …
- Attack vector
- Local
- Published
- 20/12/2025
- Modified
- 30/12/2025
Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled …
- Attack vector
- Network
- Published
- 10/02/2023
- Modified
- 21/12/2025
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to …
- Attack vector
- Network
- Published
- 18/11/2024
- Modified
- 21/12/2025
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This …
- Attack vector
- Network
- Published
- 07/02/2025
- Modified
- 21/12/2025
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.
- Published
- 03/11/2021
- Modified
- 21/12/2025
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network …
- Published
- 03/11/2021
- Modified
- 21/12/2025
The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the …
- Attack vector
- NETWORK
- Published
- 25/11/2025
- Modified
- 21/12/2025
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute …
- Attack vector
- Network
- Published
- 31/05/2023
- Modified
- 21/12/2025
OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath …
- Attack vector
- Network
- Published
- 15/07/2024
- Modified
- 21/12/2025
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys …
- Attack vector
- Local
- Published
- 04/03/2024
- Modified
- 21/12/2025
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path …
- Published
- 20/12/2017
- Modified
- 13/05/2026
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries …
- Attack vector
- Network
- Published
- 29/04/2025
- Modified
- 21/12/2025
Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. …
- Published
- 03/11/2021
- Modified
- 21/12/2025
Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions …
- Attack vector
- NETWORK
- Published
- 23/08/2022
- Modified
- 21/12/2025
Attack patterns (MITRE) (1)
-
T1588 subtechnique-ofObtain Capabilities
Campaign (4)
- Operation Spalax uses
- C0015 uses
- FunnyDream uses
- J-magic Campaign uses
Course Of Action (1)
- Pre-compromise mitigates