119 threats
Malware
Cross-platform Java RAT
Malware
Premium .NET keylogger and stealer
Open-source Android RAT
Malware
Lightweight loader and reconnaissance bot
Malware
Japanese-themed loader
Malware
Weaponized remote admin tool
Analysis of emerging Android threats
Malware
Open-source .NET RAT
macOS information stealer
Malware
Go-based information stealer
Malware
Backdoor malware
Malware
AutoIt-scripted malware family
Commercial .NET RAT
Malware
Information stealer targeting browser data and crypto wallets
Malware
Clipboard-hijacking banking malware
Malware
Brazilian banking trojan downloader
TrickBot successor loader
Brazilian banking trojan
Malware
Legacy RAT with modern revival
Malware
Low-cost MaaS RAT
Malware
Information stealer loader
Malware
Commercial adversary simulation framework
Cuba ransomware downloader
Malware
Go-based cross-platform RAT
Deep analysis of Cobalt Strike, the commercial red team framework exploited by APT29, APT41, Conti, and LockBit. Covers Beacon payloads, Malleable C2, Operation Morpheus, and defense strategies.
Unauthorized cryptocurrency mining
Malware
Modular banking trojan
Malware
Emerging downloader malware
Malware
Premium MaaS loader
Analysis of DcRAT (Dark Crystal RAT), the $5-7 .NET MaaS RAT with 34 plugins, dedicated IDE, and usage by threat actors targeting Ukrainian defense. Covers YouTube distribution, plugin ecosystem, and
Custom APT backdoor
Malware
Dual-payload loader
Malware
Prolific banking trojan
Malware
Classic file infector
Emerging Linux threats analysis
Script-based loader chain
Malware
Modular botnet and loader
Malware
Fake application malware
Classic credential stealer and downloader
Malware
File infector trojan
Malware
Delphi-based RAT
Malware
Chinese-origin RAT with decades of use
Malware
Go-based brute force tool
Malware
LATAM banking trojan
VBS-based worm RAT
Malware
Banking trojan turned loader
Malware
Emerging loader malware
Malware
Banking trojan
Malware
Modular financial trojan
Analysis of Latrodectus, the Windows malware loader succeeding IcedID with advanced sandbox evasion, AES-256 encryption, and ClickFix social engineering. Covers TA577/TA578, Operation Endgame survival
Malware
Open-source .NET RAT
Malware
AutoIt-based RAT
Malware
Widely distributed information stealer
E-commerce card skimmer
Malware
Backdoor trojan
MaaS loader
Malware
RedLine fork with shared infrastructure
Malware
Infamous IoT DDoS botnet
Malware
LATAM banking trojan and stealer
Malware
Widely-used .NET RAT
Malware
Cross-platform commercial RAT
Analysis of NjRAT (Bladabindi), the leaked-source .NET RAT active since 2012 with keylogging, MBR wiping, USB worm, and DDoS capabilities. Covers Group5, SideCopy, Dev Tunnels abuse, and defense strat
Malware
Excessive failed DNS resolution abuse
Malware
Information-gathering RAT
Malware
Surveillance-focused RAT
Malware
Commercial RAT disguised as admin tool
Malware
JavaScript-based loader
Malware
Emerging backdoor
Malware
Emerging MaaS RAT
Malware
IRC-based Perl backdoor
Malware
Chinese APT backdoor
Malware
Classic Chinese APT RAT
PowerShell-based malware delivery
Malware
Open-source Python RAT
Budget information stealer
Python-based malware delivery
Malware
Long-running banking botnet
Malware
Proxy backdoor
Malware
Open-source .NET RAT
Malware
MaaS information stealer
Malware
Java-based open-source RAT
Analysis of RedLine Stealer, the MaaS infostealer responsible for 51% of all infostealer infections, its Operation Magnus takedown, and defense strategies.
Malware
Commercial surveillance RAT
Analysis of Bad Rabbit ransomware, a modified variant of Not Petya targeting Ukraine and Russia via drive-by downloads and SMB propagation.
Malware
Free .NET RAT
Advanced C++ information stealer
Malware
PrivateLoader-distributed stealer
Malware
Weaponized Remote Utilities
Malware
DNS hijacking and manipulation
Small downloader
Malware
Legacy IRC-based botnet
Information stealer RAT
JavaScript-based fake update framework
Multi-component malware suite
Adware and crypto-mining botnet
Malware
Stealthy cross-platform malware
Malware
Java-based RAT with fake ransomware
Malware
Lightweight information stealer
Cryptomining botnet
Analysis of SystemBC, the SOCKS5 proxy backdoor with TOR integration used by Ryuk, Conti, DarkSide, and Black Basta ransomware operations. Covers RC4 encryption, DroxiDat variant, and detection strate
Malware
Emerging loader malware
How Lapsus$, ShinyHunters, and Scattered Spider merged into one of the most brazen cybercrime collectives — and what it means for enterprise security.
Analysis of SANDWORM_MODE — the first documented cross-modal supply chain worm designed to subvert AI coding assistants and MCP servers via malicious npm packages.
Malware
Point-of-sale malware
Analysis of Tofsee (Gheg), the modular spam botnet active since 2013 with crypto mining, DDoS, social media spreading, and proxy modules. Covers DGA cracking, PrivateLoader distribution, and defense s
Malware
Modular banking trojan turned loader
Emerging malware family
Analysis of emerging unclassified RATs
Malware
Classic small downloader
Long-running banking trojan
Malware
Chinese-origin RAT targeting Chinese speakers
Malware
Arkei-derived information stealer
Malware
JavaScript worm/RAT hybrid
Malware
USB propagation worm
MaaS information stealer
Modular backdoor framework used by multiple Chinese APT groups for persistent access and supply chain compromises across gaming, technology, and telecom sectors.
Malware
Open-source C# RAT
Malware
Legacy RAT still in use
Malware
Rising MaaS RAT