Welcome back to our Triage Thursday™ blog series! We’re excited to share this week’s detection updates with you. In these quick posts, we highlight the latest malware families detections that have been added.
New Windows Families This Week
- Added detection and config extractor for QtrStealer aka Qatar stealer family, Windows stealer
- QtrStealer sample:
- Added detection for Mettstress, Python-based Windows stealer
- Mettstress sample:
- Added detection for FudRAT, Windows RAT
- FudRAT sample:
- Added detection for GolstaStealer, Windows stealer
- GolstaStealer sample:
- Added detection for SpecterStealer, Windows stealer
- SpecterStealer sample:
- Added detection for NyxLogger, Windows keylogger
- NyxLogger sample:
- Added detection for HelloBackdoor, Windows backdoor
- HelloBackdoor sample:
- Added detection for NightWire, Windows backdoor
- NightWire sample:
Detection for macOS
- Added detection for TodoSwift, macOS backdoor
- TodoSwift sample:
Detection for Android
- Added detection and extraction for Flying Eagle, Android RAT
- FlyingEagle sample:
Updates for Existing Families
- Updated detection for Vidar v2.7
- Vidar sample:
- Updated detection and extractor for ACRStealer v4.x-alpha
- ACRStealer sample:
- Updated detection for new variant of Nova ransomware
- Nova sample:
- Updated detection and extraction for new version of Albiriox, Android RAT
- Albiriox sample:
If you have any feedback, questions, or issues about Triage™ feel free to reach out to us any time - we do our best to respond to all feedback but even if we can’t get back to you straight away your files will go into our list of things to review and help us prioritize tasks.
You can find us directly through the website, or using the Feedback option on an analysis report page.
Not signed up yet? Head over to tria.ge to register for a free account.