Welcome back to our Triage Thursday™ blog series! We’re excited to share this week’s detection updates with you. In these quick posts, we highlight the latest malware families detections that have been added. This edition consolidates the wk25 and wk26 releases.
New Windows Families This Week
- Added detection and extraction for LissaC2, Windows backdoor
- LissaC2 sample:
- Added detection and extraction for LxBaseRAT, Windows RAT
- LxBaseRAT sample:
- Added detection and extraction for PaloRAT, Windows RAT
- PaloRAT sample:
- Added detection and extraction for SirisuRAT, Windows RAT
- SirisuRAT samples:
- Added detection and extraction for chaarlottte, Windows RAT
- chaarlottte sample:
- Added detection and extraction for OvinRAT, Windows RAT
- OvinRAT sample:
- Added detection for Prysmax Stealer, Windows stealer
- PrysmaxStealer sample:
- Added detection for VBVStealer, Windows information stealer
- VBVStealer sample:
- Added detection for ZuqraStealer, Windows stealer
- ZuqraStealer sample:
- Added detection for MegaStealer, Windows stealer
- MegaStealer sample:
- Added detection for OverWatch, Windows stealer
- OverWatch sample:
- Added detection for DissoluteStealer, Windows stealer
- DissoluteStealer sample:
- Added detection for CloudzRAT, Windows RAT
- CloudzRAT sample:
- Added detection for MotionEyeRAT, Windows RAT
- MotionEyeRAT sample:
- Added detection for DeepSideRAT, Windows RAT
- DeepSideRAT sample:
- Added detection for TernDoor, Windows backdoor
- TernDoor sample:
- Added detection for HavocKiller, Windows EDR-killer hacktool (Gentleman campaigns)
- HavocKiller sample:
- Added detection for RoguePlanet, Windows local privilege escalation 0-day (Nightmare-Eclipse toolset)
- sample: 260626-kjabraaw9q
- Added detection for SeroWorms, Windows worm with ransomware capabilities
- SeroWorms sample:
- Added detection for DeadLock, Windows ransomware
- DeadLock sample:
Detection for Android
- Added detection for pcTattletale, Android surveillanceware
- pcTattletale sample:
- Added detection for TemptingCedar, Android spyware
- TemptingCedar sample:
- Added detection for Triout, Android spyware
- Triout sample:
- Added detection for xHelper, Android trojan
- xHelper sample:
- Added detection for ZooPark, Android spyware
- ZooPark sample:
- Added detection for HARDRAIN, Android RAT
- HARDRAIN sample:
- Added detection for XRAT, Android surveillanceware
- XRAT sample:
- Added detection for Zen, Android trojan
- Zen sample:
- Added detection for Xbor, Android banking trojan
- Xbor sample:
- Added detection for Viper RAT, Android RAT
- ViperRAT sample:
Detection for Linux Families
- Added detection for P2Pinfect, Linux worm
- P2Pinfect sample:
- Added detection for Chalubo, Linux botnet
- Chalubo sample:
- Added detection for TeamTNT
- TeamTNT sample:
- Added detection for Bootkitty family, cross-platform bootkit
- Bootkitty samples:
- Added detection for RapperBot, Linux botnet
- RapperBot sample:
- Added detection for Plague, Linux backdoor
- Plague sample:
- Added detection for Ballista, Linux botnet
- Ballista sample:
- Added detection for Satori, Linux botnet
- Satori sample:
- Added detection for IPStorm, multi-platform botnet
- IPStorm sample:
- Added detection for ReverseSSH, open-source reverse-SSH tool (Golang)
- sample: 260626-kk3ppaax5r
Detection for APT Groups
- Added detection for Turla RAT, Turla APT
- TurlaRAT sample:
- Added detection for Pygmy Goat Backdoor, APT Tstark
- PygmyGoat sample:
- Added detection for MASOL cross-platform RAT backdoor, APT Earth Estries
- MASOL sample:
- Added detection for iocontrol Backdoor, APT Cyber Av3ngers
- iocontrol sample:
- Added detection for Melofee backdoor, APT41
- Melofee sample:
- Added detection for HyperSSL backdoor, APT27
- HyperSSL sample:
Updates for Existing Families
- Updated detection and extraction for NanoCore v2, Windows botnet
- NanoCore sample:
- Updated signatures for new variant of Tsunami aka Kaiten multi-arch botnet
- Kaiten sample:
If you have any feedback, questions, or issues about Triage™ feel free to reach out to us any time - we do our best to respond to all feedback but even if we can’t get back to you straight away your files will go into our list of things to review and help us prioritize tasks.
You can find us directly through the website, or using the Feedback option on an analysis report page.
Not signed up yet? Head over to tria.ge to register for a free account.