Welcome back to our Triage Thursday™ blog series! We’re excited to share this week’s detection updates with you. In these quick posts, we highlight the latest malware families detections that have been added.
New Windows Families This Week
- Added detection and extraction for GeckoStealer, Windows stealer
- GeckoStealer sample:
- Added detection and extraction for NeedleStealer, Windows stealer
- NeedleStealer sample:
- Added detection and extraction for AstarionRat, Windows RAT
- AstarionRat sample:
- Added detection for Eternidade Stealer and Eternidade Loader, Windows stealer
- Eternidade sample:
- Added detection for NebulaStealer, Windows stealer
- NebulaStealer sample:
- Added detection for NexusStealer, Windows stealer
- NexusStealer sample:
- Added detection for DarkLoader, Windows loader
- DarkLoader sample:
- Added detection for SeroRAT, Windows RAT
- SeroRAT sample:
Detection for Android
- Added detection for AnubisSpy, Android spyware
- AnubisSpy sample:
- Added detection for BankBot-YNRK, Android banking trojan
- BankBot-YNRK sample:
- Added detection for GnatSpy, Android spyware
- GnatSpy sample:
- Added detection for PixBankBot, Android banking trojan
- Added detection for Skygofree, Android spyware
- Skygofree sample:
- Added detection for Slempo, Android banking trojan
- Slempo sample:
- Added detection for ThiefBot, Android banking trojan
- ThiefBot sample:
- Added detection for VAMP, Android spyware
- VAMP sample:
Detection for Linux and Network Families
- Added detection for DeadBolt, Linux ransomware
- DeadBolt sample:
- Added detection for Diamorphine, Linux rootkit
- Diamorphine sample:
- Added detection for Slnya, Linux ransomware
- Slnya sample:
- Added detection for Specter, Linux botnet
- Specter sample:
- Added detection for SSHdKit, Linux credential-theft trojan
- SSHdKit sample:
- Added detection for xHide, Linux hacktool
- [xHide] sample:
- Added detection for KadNap, router botnet
- KadNap sample:
- Added detection for Equation Laser, Windows backdoor (APT Equation Group)
- EquationLaser sample:
Detection for Ransomware
- Cockblocker sample:
- CryptoDarkRubix sample:
- CryptoPatronum sample:
- Cylance sample:
- DarkWorld sample:
- Rex sample:
- Vovabol sample:
Updates for Existing Families
- Updated detection and extraction for Remus stealer, new variant
- Remus sample:
- Updated detection and extraction for Vidar
- Vidar sample:
- Updated detection and extraction for LotusLite, Windows backdoor
- LotusLite sample:
If you have any feedback, questions, or issues about Triage™ feel free to reach out to us any time - we do our best to respond to all feedback but even if we can’t get back to you straight away your files will go into our list of things to review and help us prioritize tasks.
You can find us directly through the website, or using the Feedback option on an analysis report page.
Not signed up yet? Head over to tria.ge to register for a free account.