Skip to content
THE HUNTER’S LEDGER
Families
Malware and tool families
46 families named by a published report, detection rule, IOC feed or actor profile. Each page collects every spelling the corpus uses for the family and points back to where it appears. Families are listed by what the evidence calls them; a report that declines to name a family is not given one here.
kit · 2 reports · 11 rules · 2 actors
GHOST cryptojacker kit
A Linux cryptojacking kit with an LD_PRELOAD rootkit, competitor-killing and self-spreading stages, run by more than one operator.
UTA-2026-016UTA-2026-017
toolkit · 2 reports · 9 rules · 1 actor
ARPA
A Turkish-language observability-harvesting and correlation platform built on an AI agent framework.
UTA-2026-013
rat · 4 reports · 8 rules · 1 actor
XWorm
A commodity .NET RAT sold as malware-as-a-service, among the most frequently recovered families in open directories.
UTA-2026-003
ransomware · 1 report · 7 rules · 1 actor
Chaos
The Chaos ransomware builder lineage, here as a TorBrowserTor-named variant with its own crypter.
UTA-2026-005
toolkit · 1 report · 7 rules · 1 actor
GOCLOUD
UTA-2026-020
rat · 1 report · 7 rules
Remcos
stealer · 1 report · 6 rules · 1 actor
Rhadamanthys
UTA-2026-010
c2 framework · 2 reports · 6 rules · 1 actor
OpenStrike
An open-source Cobalt Strike reimplementation, staged alongside cracked Cobalt Strike builds.
UTA-2026-004
c2 framework · 2 reports · 6 rules · 2 actors
Sliver
BishopFox's open-source adversary emulation framework, found deployed as a live C2 by more than one operator.
UTA-2026-001UTA-2026-024
loader · 1 report · 5 rules · 1 actor
HijackLoader
UTA-2026-007
stealer · 1 report · 5 rules
EvilSoul-Engine
A Node and Electron stealer-builder forked from the xaitax ChromElevator project and sold as a service.
rat · 1 report · 5 rules · 1 actor
CloudSync
A custom C++ RAT with a Tor-reachable panel, found with the .NET SvchostPayload RAT on the same assembler toolkit.
UTA-2026-021
rat · 1 report · 5 rules · 1 actor
ShadowRAT
UTA-2026-003
c2 framework · 2 reports · 5 rules · 1 actor
A2A C2
A bespoke Python agent-to-agent C2 built by a Russian-speaking operator, with an LLM-assisted credential pipeline behind it.
UTA-2026-012
kit · 2 reports · 4 rules · 1 actor
BellaMain
An operator-developed PHP phishing-as-a-service panel with brand-impersonation kits.
UTA-2026-008
c2 framework · 1 report · 4 rules · 1 actor
Matrix C2
An operator-built, AI-co-authored controller for a Mirai-derived botnet.
UTA-2026-014
botnet · 2 reports · 3 rules · 1 actor
Pandora-Mirai
A Sora-fork Mirai derivative, built with an AI coding agent in the loop.
UTA-2026-014
stealer · 1 report · 3 rules
SogouStealer
rat · 2 reports · 3 rules
KAIDO
A rebranded 64-bit Quasar RAT fork with HVNC, sold as a product.
c2 framework · 1 report · 3 rules · 1 actor
AdaptixC2
UTA-2026-006
cryptominer · 1 report · 2 rules
NsMiner
rat · 1 report · 2 rules
SvchostPayload
rat · 1 report · 2 rules
NjRAT
rat · 2 reports · 2 rules
Quasar RAT
The open-source .NET RAT that several rebranded forks on this site descend from.
c2 framework · 1 report · 2 rules · 1 actor
Covenant
UTA-2026-002
c2 framework · 1 report · 2 rules · 1 actor
XiebroC2
UTA-2026-002
c2 framework · 2 reports · 2 rules · 1 actor
Cobalt Strike
The commercial red-team framework, seen on the site only as cracked builds staged by criminal operators.
UTA-2026-004
toolkit · 1 report · 1 rule · 1 actor
ScareCrow
UTA-2026-001
exploit · 1 report · 1 rule
PrintSpoofer
tunnel · 1 report · 1 rule · 1 actor
CovertVPN
UTA-2026-004
tunnel · 1 report · 1 rule
revsocks
tunnel · 1 report · 1 rule · 2 actors
Ligolo-ng
UTA-2026-006UTA-2026-024
webshell · 1 report · 1 rule
InsomniaShell
webshell · 1 report · 1 rule
Godzilla
backdoor · 1 report · 1 rule
GSocket
botnet · 1 report · 1 rule
Tofsee
rat · 1 report · 1 rule · 1 actor
EtherRAT
A Node.js bot whose C2 address is resolved from an Ethereum contract (EtherHiding).
UTA-2026-024
rat · 1 report · 1 rule · 1 actor
Orcus RAT
UTA-2026-005
rat · 1 report · 1 rule
Pulsar RAT
rat · 1 report · 1 rule
RavenRAT
rat · 1 report · 1 rule
PureRAT
tunnel · 0 reports · 0 rules · 4 actors
chisel
The open-source TCP/UDP tunnel, the single most shared piece of tooling across the actors tracked here.
UTA-2026-006UTA-2026-018UTA-2026-023UTA-2026-024
cryptominer · 2 reports · 0 rules · 3 actors
XMRig
The open-source Monero miner every cryptojacking kit on the site deploys.
UTA-2026-016UTA-2026-017UTA-2026-020
loader · 1 report · 0 rules
SmokeLoader
stealer · 1 report · 0 rules
SentinelStealer
stealer · 1 report · 0 rules
RedLine Stealer

The vocabulary that decides each family's canonical name lives in _data/families.yml; a label it does not know is listed by name in the generated index rather than guessed into a page.