Families
Malware and tool families
46 families named by a published report, detection rule, IOC feed or actor profile. Each page collects every spelling the corpus uses for the family and points back to where it appears. Families are listed by what the evidence calls them; a report that declines to name a family is not given one here.
No families match that filter.
GHOST cryptojacker kit
A Linux cryptojacking kit with an LD_PRELOAD rootkit, competitor-killing and self-spreading stages, run by more than one operator.
ARPA
A Turkish-language observability-harvesting and correlation platform built on an AI agent framework.
XWorm
A commodity .NET RAT sold as malware-as-a-service, among the most frequently recovered families in open directories.
Chaos
The Chaos ransomware builder lineage, here as a TorBrowserTor-named variant with its own crypter.
GOCLOUD
Remcos
Rhadamanthys
OpenStrike
An open-source Cobalt Strike reimplementation, staged alongside cracked Cobalt Strike builds.
Sliver
BishopFox's open-source adversary emulation framework, found deployed as a live C2 by more than one operator.
HijackLoader
EvilSoul-Engine
A Node and Electron stealer-builder forked from the xaitax ChromElevator project and sold as a service.
CloudSync
A custom C++ RAT with a Tor-reachable panel, found with the .NET SvchostPayload RAT on the same assembler toolkit.
ShadowRAT
A2A C2
A bespoke Python agent-to-agent C2 built by a Russian-speaking operator, with an LLM-assisted credential pipeline behind it.
BellaMain
An operator-developed PHP phishing-as-a-service panel with brand-impersonation kits.
Matrix C2
An operator-built, AI-co-authored controller for a Mirai-derived botnet.
Pandora-Mirai
A Sora-fork Mirai derivative, built with an AI coding agent in the loop.
SogouStealer
KAIDO
A rebranded 64-bit Quasar RAT fork with HVNC, sold as a product.
AdaptixC2
NsMiner
SvchostPayload
NjRAT
Quasar RAT
The open-source .NET RAT that several rebranded forks on this site descend from.
Covenant
XiebroC2
Cobalt Strike
The commercial red-team framework, seen on the site only as cracked builds staged by criminal operators.
ScareCrow
PrintSpoofer
CovertVPN
revsocks
Ligolo-ng
InsomniaShell
Godzilla
GSocket
Tofsee
EtherRAT
A Node.js bot whose C2 address is resolved from an Ethereum contract (EtherHiding).
Orcus RAT
Pulsar RAT
RavenRAT
PureRAT
chisel
The open-source TCP/UDP tunnel, the single most shared piece of tooling across the actors tracked here.
XMRig
The open-source Monero miner every cryptojacking kit on the site deploys.
SmokeLoader
SentinelStealer
RedLine Stealer
The vocabulary that decides each family's canonical name lives in _data/families.yml; a label it does not know is listed by name in the generated index rather than guessed into a page.