The public MITRE ATT&CK Software dictionary, filtered to malware families. Rows used by one or more of our tracked actors rank first — that's the MENA lens — with the full catalog alphabetical underneath. A software page links out to actor profiles that use it and to its MITRE ATT&CK entry.
| Malware | Aliases | Used by | Description | ATT&CK |
|---|---|---|---|---|
| ASPXSpy malware | ASPXTool | 2 actors | [ASPXSpy](https://attack.mitre.org/software/S0073) is a Web shell. It has been modified by [Threat Group-3390](https://attack.mitre.org/grou… | ↗ |
| Cobalt Strike malware | — | 2 actors | [Cobalt Strike](https://attack.mitre.org/software/S0154) is a commercial, full-featured, remote access tool that bills itself as “adversary… | ↗ |
| DEADWOOD malware | — | 2 actors | [DEADWOOD](https://attack.mitre.org/software/S1134) is wiper malware written in C++ using Boost libraries. [DEADWOOD](https://attack.mitre.o… | ↗ |
| PoisonIvy malware | BreutPoison IvyDarkmoon | 2 actors | [PoisonIvy](https://attack.mitre.org/software/S0012) is a popular remote access tool (RAT) that has been used by many groups.(Citation: Fire… | ↗ |
| Amadey malware | — | 1 actor | [Amadey](https://attack.mitre.org/software/S1025) is a Trojan bot that has been used since at least October 2018.(Citation: Korean FSI TA505… | ↗ |
| Apostle malware | — | 1 actor | [Apostle](https://attack.mitre.org/software/S1133) is malware that has functioned as both a wiper and, in more recent versions, as ransomwar… | ↗ |
| AppleJeus malware | — | 1 actor | [AppleJeus](https://attack.mitre.org/software/S0584) is a family of downloaders initially discovered in 2018 embedded within trojanized cryp… | ↗ |
| AshTag malware | — | 1 actor | [AshTag](https://attack.mitre.org/software/S9031) is a modular .NET backdoor with multiple features that has been used by [WIRTE](https://at… | ↗ |
| AuditCred malware | Roptimizer | 1 actor | [AuditCred](https://attack.mitre.org/software/S0347) is a malicious DLL that has been used by [Lazarus Group](https://attack.mitre.org/group… | ↗ |
| AutoIt backdoor malware | — | 1 actor | [AutoIt backdoor](https://attack.mitre.org/software/S0129) is malware that has been used by the actors responsible for the MONSOON campaign.… | ↗ |
| Azorult malware | — | 1 actor | [Azorult](https://attack.mitre.org/software/S0344) is a commercial Trojan that is used to steal information from compromised hosts. [Azorult… | ↗ |
| BADCALL malware | — | 1 actor | [BADCALL](https://attack.mitre.org/software/S0245) is a Trojan malware variant used by the group [Lazarus Group](https://attack.mitre.org/gr… | ↗ |
| Bandook malware | — | 1 actor | [Bandook](https://attack.mitre.org/software/S0234) is a commercially available RAT, written in Delphi and C++, that has been available since… | ↗ |
| Bankshot malware | Trojan Manuscript | 1 actor | [Bankshot](https://attack.mitre.org/software/S0239) is a remote access tool (RAT) that was first reported by the Department of Homeland Secu… | ↗ |
| BFG Agonizer malware | — | 1 actor | [BFG Agonizer](https://attack.mitre.org/software/S1136) is a wiper related to the open-source project CRYLINE-v.5.0. The malware is associat… | ↗ |
| BLINDINGCAN malware | — | 1 actor | [BLINDINGCAN](https://attack.mitre.org/software/S0520) is a remote access Trojan that has been used by the North Korean government since at… | ↗ |
| BONDUPDATER malware | — | 1 actor | [BONDUPDATER](https://attack.mitre.org/software/S0360) is a PowerShell backdoor used by [OilRig](https://attack.mitre.org/groups/G0049). It… | ↗ |
| Cadelspy malware | — | 1 actor | [Cadelspy](https://attack.mitre.org/software/S0454) is a backdoor that has been used by [APT39](https://attack.mitre.org/groups/G0087).(Cita… | ↗ |
| Caterpillar WebShell malware | — | 1 actor | [Caterpillar WebShell](https://attack.mitre.org/software/S0572) is a self-developed Web Shell tool created by the group [Volatile Cedar](htt… | ↗ |
| China Chopper malware | — | 1 actor | [China Chopper](https://attack.mitre.org/software/S0020) is a [Web Shell](https://attack.mitre.org/techniques/T1505/003) hosted on Web serve… | ↗ |
| Clop malware | — | 1 actor | [Clop](https://attack.mitre.org/software/S0611) is a ransomware family that was first observed in February 2019 and has been used against re… | ↗ |
| CreepyDrive malware | — | 1 actor | [CreepyDrive](https://attack.mitre.org/software/S1023) is a custom implant has been used by [POLONIUM](https://attack.mitre.org/groups/G1005… | ↗ |
| CreepySnail malware | — | 1 actor | [CreepySnail](https://attack.mitre.org/software/S1024) is a custom PowerShell implant that has been used by [POLONIUM](https://attack.mitre.… | ↗ |
| CrossRAT malware | — | 1 actor | [CrossRAT](https://attack.mitre.org/software/S0235) is a cross platform RAT. | ↗ |
| Cryptoistic malware | — | 1 actor | [Cryptoistic](https://attack.mitre.org/software/S0498) is a backdoor, written in Swift, that has been used by [Lazarus Group](https://attack… | ↗ |
| Dacls malware | — | 1 actor | [Dacls](https://attack.mitre.org/software/S0497) is a multi-platform remote access tool used by [Lazarus Group](https://attack.mitre.org/gro… | ↗ |
| DanBot malware | — | 1 actor | [DanBot](https://attack.mitre.org/software/S1014) is a first-stage remote access Trojan written in C# that has been used by [HEXANE](https:/… | ↗ |
| DnsSystem malware | — | 1 actor | [DnsSystem](https://attack.mitre.org/software/S1021) is a .NET based DNS backdoor, which is a customized version of the open source tool DIG… | ↗ |
| Dridex malware | Bugat v5 | 1 actor | [Dridex](https://attack.mitre.org/software/S0384) is a prolific banking Trojan that first appeared in 2014. By December 2019, the US Treasur… | ↗ |
| DropBook malware | — | 1 actor | [DropBook](https://attack.mitre.org/software/S0547) is a Python-based backdoor compiled with PyInstaller.(Citation: Cybereason Molerats Dec… | ↗ |
| Dtrack malware | — | 1 actor | [Dtrack](https://attack.mitre.org/software/S0567) is spyware that was discovered in 2019 and has been used against Indian financial institut… | ↗ |
| DustySky malware | NeD Worm | 1 actor | [DustySky](https://attack.mitre.org/software/S0062) is multi-stage malware written in .NET that has been used by [Molerats](https://attack.m… | ↗ |
| ECCENTRICBANDWAGON malware | — | 1 actor | [ECCENTRICBANDWAGON](https://attack.mitre.org/software/S0593) is a remote access Trojan (RAT) used by North Korean cyber actors that was fir… | ↗ |
| Explosive malware | — | 1 actor | [Explosive](https://attack.mitre.org/software/S0569) is a custom-made remote access tool used by the group [Volatile Cedar](https://attack.m… | ↗ |
| FALLCHILL malware | — | 1 actor | [FALLCHILL](https://attack.mitre.org/software/S0181) is a RAT that has been used by [Lazarus Group](https://attack.mitre.org/groups/G0032) s… | ↗ |
| Ferocious malware | — | 1 actor | [Ferocious](https://attack.mitre.org/software/S0679) is a first stage implant composed of VBS and PowerShell scripts that has been used by [… | ↗ |
| FinFisher malware | FinSpy | 1 actor | [FinFisher](https://attack.mitre.org/software/S0182) is a government-grade commercial surveillance spyware reportedly sold exclusively to go… | ↗ |
| FlawedAmmyy malware | — | 1 actor | [FlawedAmmyy](https://attack.mitre.org/software/S0381) is a remote access tool (RAT) that was first seen in early 2016. The code for [Flawed… | ↗ |
| FlawedGrace malware | — | 1 actor | [FlawedGrace](https://attack.mitre.org/software/S0383) is a fully featured remote access tool (RAT) written in C++ that was first observed i… | ↗ |
| Fooder malware | — | 1 actor | [Fooder](https://attack.mitre.org/software/S9033) is a custom 64-bit C/C++ loader used by [MuddyWater](https://attack.mitre.org/groups/G0069… | ↗ |
| Get2 malware | — | 1 actor | [Get2](https://attack.mitre.org/software/S0460) is a downloader written in C++ that has been used by [TA505](https://attack.mitre.org/groups… | ↗ |
| HARDRAIN malware | — | 1 actor | [HARDRAIN](https://attack.mitre.org/software/S0246) is a Trojan malware variant reportedly used by the North Korean government. (Citation: U… | ↗ |
| Havoc malware | — | 1 actor | [Havoc](https://attack.mitre.org/software/S1229) is an open-source post-exploitation command and control (C2) framework first released on Gi… | ↗ |
| Helminth malware | — | 1 actor | [Helminth](https://attack.mitre.org/software/S0170) is a backdoor that has at least two variants - one written in VBScript and PowerShell th… | ↗ |
| HOPLIGHT malware | — | 1 actor | [HOPLIGHT](https://attack.mitre.org/software/S0376) is a backdoor Trojan that has reportedly been used by the North Korean government.(Citat… | ↗ |
| HotCroissant malware | — | 1 actor | [HotCroissant](https://attack.mitre.org/software/S0431) is a remote access trojan (RAT) attributed by U.S. government entities to malicious… | ↗ |
| IMAPLoader malware | — | 1 actor | [IMAPLoader](https://attack.mitre.org/software/S1152) is a .NET-based loader malware exclusively associated with [CURIUM](https://attack.mit… | ↗ |
| IPsec Helper malware | — | 1 actor | [IPsec Helper](https://attack.mitre.org/software/S1132) is a post-exploitation remote access tool linked to [Agrius](https://attack.mitre.or… | ↗ |
| IronWind malware | — | 1 actor | [IronWind](https://attack.mitre.org/software/S9029) is a custom loader malware that has been in use since at least 2023 by actors including… | ↗ |
| ISMInjector malware | — | 1 actor | [ISMInjector](https://attack.mitre.org/software/S0189) is a Trojan used to install another [OilRig](https://attack.mitre.org/groups/G0049) b… | ↗ |