RATs, ransomware & infostealers
Curated profiles for well-known, well-documented malware families, cross-referenced against every detection rule Sigma Watch tracks. Each profile links out to authoritative sources — MITRE ATT&CK, CISA advisories, and vendor threat-intel writeups — for eradication and remediation guidance, rather than us writing our own removal steps that could go stale or be wrong.
Agent Tesla
Agent Tesla is a .NET-based remote access trojan/spyware active since 2014, sold commercially and widely pirated/cracked for criminal use rather than run as a f…
Astaroth
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0373) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Bonadan
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0486) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Carberp
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0484) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Chaes
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0631) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Cuckoo Stealer
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S1153) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Ebury
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0377) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Fooder
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S9033) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
H1N1
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0132) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Hancitor
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0499) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
KGH_SPY
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0526) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
LAMEHUG
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S9035) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
LP-Notes
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S9036) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Lokibot
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0447) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Lumma Stealer
Lumma Stealer is a Windows information-stealing malware active since late 2022, sold as malware-as-a-service on Telegram and Russian-language forums (subscripti…
Mini Shai-Hulud
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S9043) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
MirrorStealer
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S9022) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
OwaAuth
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0072) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
PACEMAKER
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S1109) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Pony
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0453) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
QuietSieve
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0686) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Raccoon Stealer
Raccoon Stealer is a Windows information-stealing malware sold as malware-as-a-service (roughly $200/month) since 2019, targeting browser passwords, cookies and…
Ramsay
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0458) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
RedLine Stealer
RedLine Stealer is a Windows information-stealing malware, active since 2020, sold as malware-as-a-service via one-time purchases or monthly subscriptions on un…
StealC
StealC is a lightweight (~80KB) Windows information stealer that emerged on Russian-speaking underground forums (XSS, BHF) in January 2023, sold as malware-as-a…
StrelaStealer
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S1183) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
StrongPity
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0491) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
TeamPCP Cloud Stealer
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S9041) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Troll Stealer
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S1196) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
USBferry
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0452) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Valak
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0476) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
Vidar Stealer
Vidar is a Windows information-stealing trojan first observed in late 2018, derived from the Arkei stealer lineage and sold/rented on dark-web and underground f…
WARPWIRE
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S1116) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …
XLoader
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S1207) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's …