Welcome back to our Triage Thursday™ blog series! We’re excited to share this week’s detection updates with you. In these quick posts, we highlight the latest malware families detections that have been added.
New Windows Families This Week
- Added detection and extraction for Grunt aka Covenant, Windows loader
- Grunt sample:
- Added detection and extraction for Corebot, Windows stealer
- Corebot sample:
- Added detection and extraction for EvolutionStealer, Windows stealer
- EvolutionStealer sample:
- Added detection for NotDoor, Windows backdoor
- NotDoor sample:
- Added detection for Jadtre, Windows trojan
- Jadtre sample:
- Added detection for VTFlooder, Windows trojan
- VTFlooder sample:
- Added extraction support for UnixStealer, Windows stealer
- UnixStealer sample:
- Added detection for Empire, Windows post-exploitation framework
- Empire sample:
Detection for Android
- Added detection for BuzzOut, Android spyware
- BuzzOut sample:
- Added detection for Dark Caracal, Android surveillanceware
- DarkCaracal sample:
- Added detection for GoldenCup, Android spyware
- GoldenCup sample:
- Added detection for Hornbill, Android surveillanceware
- Hornbill sample:
- Added detection for Moonshine, Android surveillanceware
- Moonshine sample:
- Added detection for SunBird, Android surveillanceware
- SunBird sample:
Detection for Linux Families
- Added detection for BruteEntry, Linux botnet
- BruteEntry sample:
- Added detection for PeerTime, Linux backdoor
- PeerTime sample:
APT Equation Group
- Added detection for Equation Drug platform, APT Equation Group
- EquationDrug sample:
- Added detection for FannyWorm, APT Equation Group
- FannyWorm sample:
Detection for Ransomware
- BallerWare sample:
- Doitman sample:
- EduRansom sample:
- Ekati sample:
- ElmersGlue sample:
- EncoderCSL sample:
- Encrpt3d sample:
- Erebus (Linux ransomware) sample:
- Kangaroo sample:
- Lalia sample:
- NBLock Black sample:
- Odyssey sample:
- VileRansomware sample:
Updates for Existing Families
- Updated detection and extraction for AdaptixC2, Linux and Windows versions
- AdaptixC2 samples:
- Linux samples:
- Windows PNG hidden sample:
- AdaptixC2 samples:
- Updated detection and extraction for Ngate, Android NFC-based trojan
- Ngate sample:
- Updated detection and extraction for VanillRAT, Windows RAT
- VanillaRAT sample:
- Updated detection for HiddenTear aka Cryptear, Windows ransomware
- HiddenTear sample:
If you have any feedback, questions, or issues about Triage™ feel free to reach out to us any time - we do our best to respond to all feedback but even if we can’t get back to you straight away your files will go into our list of things to review and help us prioritize tasks.
You can find us directly through the website, or using the Feedback option on an analysis report page.
Not signed up yet? Head over to tria.ge to register for a free account.