Welcome back to our Triage Thursday™ blog series! We’re excited to share this week’s detection updates with you. In these quick posts, we highlight the latest malware families detections that have been added.
New Windows Families This Week
- Added detection and extraction for Overlord, Windows RAT
- Overlord sample:
- Added detection and extraction for OnyxC2, Windows backdoor
- OnyxC2 sample:
- Added extraction support for XoriumStealer, Windows stealer
- XoriumStealer sample:
- Added detection for KralcanStealer, Windows NodeJS stealer
- KralcanStealer sample:
- Added detection for LokiRAT, Windows RAT
- LokiRAT sample:
- Added detection for SilentNet, Java-based stealer
- SilentNet sample:
- Added detection for TiFlux, RMM tool abused as backdoor
- sample: 260610-t5eyssew8k
Detection for Android
- Added detection for GPlayed, Android trojan
- GPlayed sample:
- Added detection for HilalRAT, Android RAT
- HilalRAT sample:
- Added detection for KnSpy, Android spyware
- KnSpy sample:
- Added detection for KSREMOTE, Android infostealer
- KSREMOTE sample:
- Added detection for Loki, Android infostealer
- Loki sample:
- Added detection for LokiBot, Android banking trojan
- LokiBot sample:
- Added detection for LuckyCat, Android RAT
- LuckyCat sample:
- Added detection for LunaSpy, Android spyware
- LunaSpy sample:
Detection for Linux Families
- Added detection for Vulcan, multi-architecture Linux botnet
- Vulcan sample:
- Added detection for Minocat, Linux tunneler
- Minocat sample:
- Added detection for PUMAKIT, Linux rootkit
- PUMAKIT sample:
Detection for Ransomware
Updates for Existing Families
- Updated detection and extraction for Vidar v2.0 new version
- Vidar sample:
- Updated signatures for BlackBasta ransomware
- BlackBasta sample:
- Updated detection for new version of BTMOB, Android RAT
- BTMOB sample:
If you have any feedback, questions, or issues about Triage™ feel free to reach out to us any time - we do our best to respond to all feedback but even if we can’t get back to you straight away your files will go into our list of things to review and help us prioritize tasks.
You can find us directly through the website, or using the Feedback option on an analysis report page.
Not signed up yet? Head over to tria.ge to register for a free account.