Welcome back to our Triage Thursday™ blog series! We’re excited to share this week’s detection updates with you. In these quick posts, we highlight the latest malware families detections that have been added.
New Windows Families This Week
- Added detection for SnowStealer, Windows stealer
- SnowStealer sample:
- Added detection and extractor for C2Looper, Windows backdoor
- C2Looper sample:
- Added detection and extractor for Archer, Windows RAT
- Archer sample:
Detection for macOS
- Added detection for CrashStealer, macOS stealer
- CrashStealer sample:
Detection for Android
- Added detection for Clientor, Android proxy malware
- Clientor sample:
- Added detection for WireX, Android botnet
- WireX sample:
- Added detection for BusyGasper, Android spyware
- BusyGasper sample:
- Added detection for AdultSwine, Android adware
- AdultSwine sample:
- Added detection for Cynos, Android trojan
- Cynos sample:
- Added detection for PhantomLance, Android spyware
- PhantomLance sample:
Updates for Existing Families
- Updated detection for RavenStealer
- Updated detection for BXBD Ransomware
- BXBD sample:
- Updated detection for RemoteX
- RemoteX sample:
- Updated detection for XV-Clipper
- XVClipper sample:
- Extended detection and extraction for OverlordRAT (obfuscated variants)
- OverlordRAT sample:
- Updated extraction for BruteRatel samples (fixed FPs and config extraction)
- BruteRatel sample:
- Hardened detection for Moonrise
- Updated detection and extraction for Rust variant of NeedleStealer
- NeedleStealer sample:
If you have any feedback, questions, or issues about Triage™ feel free to reach out to us any time - we do our best to respond to all feedback but even if we can’t get back to you straight away your files will go into our list of things to review and help us prioritize tasks.
You can find us directly through the website, or using the Feedback option on an analysis report page.
Not signed up yet? Head over to tria.ge to register for a free account.