Welcome back to our Triage Thursday™ blog series! We’re excited to share this week’s detection updates with you. In these quick posts, we highlight the latest malware families detections that have been added.
New Windows Families This Week
- Added detection and configuration extractor for GoGRPC backdoors, variants Giver / Kind / Lep / Pet
- Added detection and extraction for QatarRAT, Windows RAT
- QatarRAT sample:
- Added detection and config extractor for VShell, cross-platform RAT
- VShell samples:
- Windows: 260814-vwb18aer6s
- Linux: 260814-vxf2kayvbv
- VShell samples:
- Added detection for Quest aka Voog, Windows stealer
- Quest sample:
- Added extractor support for WallStealer aka VoidStealer
- WallStealer sample:
- Added detection for ZLogger, Windows keylogger
- ZLogger sample:
- Added detection for ZStealer, Windows stealer
- ZStealer sample:
- Added detection for KynxStealer, Windows stealer
- KynxStealer sample:
- Added detection for Supper Backdoor, Windows backdoor
- Supper sample:
- Added detection for CRPx0, Windows ransomware
- CRPx0 sample:
Detection for macOS
- Added detection for MacSyncStealer, macOS stealer
- MacSyncStealer sample:
Detection for Android
- Added detection and extraction for NFCShare, Android NFC-based trojan
- NFCShare sample:
- Added detection for TeleRAT, Android RAT
- TeleRAT sample:
- Added detection for Ztorg, Android SMS trojan
- Ztorg sample:
Detection for Linux and Network Families
- Added detection and extractor for Rebirth, Linux botnet
- Rebirth sample:
- Added detection for Fodcha, Linux botnet
- Fodcha sample:
- Added detection for Glassworm, JS-based trojan
- Glassworm sample:
Detection for APT Groups
- Added detection and extractor for SnowLight Linux variant, UNC5174
- SnowLight sample:
- Added detection and extractor for NightLedger, MIRAGE KITTEN aka UNC1549 (Iran-nexus)
- NightLedger sample:
- Added detection for ChocoShell, Midnight Blizzard aka Storm-2945
- ChocoShell sample:
- Added detection for CornFlake, Midnight Blizzard aka Storm-2945
- CornFlake sample:
Updates for Existing Families
- Updated detection for Remus stealer to extract another variant
- Remus sample:
- Updated detection for SalatStealer
- SalatStealer sample:
- Updated detection and extraction for new version of Octo, Android banking trojan
- Octo sample:
- Updated detection for Amos Stealer, macOS
- Amos sample:
- Updated Mirai config extractor
- Mirai sample:
If you have any feedback, questions, or issues about Triage™ feel free to reach out to us any time - we do our best to respond to all feedback but even if we can’t get back to you straight away your files will go into our list of things to review and help us prioritize tasks.
You can find us directly through the website, or using the Feedback option on an analysis report page.
Not signed up yet? Head over to tria.ge to register for a free account.