Skip to main content

Malicious Tools Index

This index links to one defensive page per malware family, implant, web shell, backdoor, wiper, or dual-use tool tracked in data/tool-intelligence.csv.

The tool pages are generated. They summarize behavior, hash/IOC availability, actor linkage, source references, hunting notes, mapped detections, and handling rules.

The repository does not store malware binaries, exploit code, credentials, or bulk copied IOC dumps. Hashes are included only when already present in public source reporting and are treated as pivots, not attribution proof.

ToolActorTypeConfidenceHash / IOC Status
AridSpyAPT-C-23Mobile RATHighRepresentative ESET-published SHA1s include 797073511A15EB85C1E9D8584B26BAA3A0B14C9E, 5F0213BA62B84221C9628F7D0A0CF87F27A45A28, E71F1484B1E3ACB4C8E8525BA1F5F8822AB7238B, and 16C8725362D1EBC8443C97C5AB79A1B6428FF87D; use full ESET IOC table for current coverage.
Desert ScorpionAPT-C-23Mobile malwareMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
FrozenCellAPT-C-23Mobile malwareMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
MicropsiaAPT-C-23BackdoorMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
PhenakiteAPT-C-23Mobile malwareMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
RedAlert.apkAPT-C-23Mobile spyware / trojanized appLowHash not committed; provisional until primary Acronis reporting is available.
SpyC23APT-C-23Mobile spywareMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
ANTAK / ASPXSPYAPT39Web shellsMediumHash not committed; use source-linked IOCs and local webroot baselines.
CadelspyAPT39BackdoorMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
CrackMapExecAPT39Post-exploitation / credential validation toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
MechaFlounderAPT39BackdoorMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
MimikatzAPT39Credential access toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
NBTscanAPT39Network scannerMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
PsExecAPT39Remote execution utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
RemexiAPT39Malware / collection toolMediumHash not committed; use MITRE references and original vendor reports.
Windows Credential EditorAPT39Credential access toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
ftpAPT39Living-off-the-land utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
pwdumpAPT39Credential access toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
NICECURLAPT42Backdoor / C2 toolMediumHash not committed; retrieve current IOCs from linked source or vendor appendix.
POWERPOSTAPT42Script / collection toolMediumHash not committed; source-linked behavior only.
TAMECATAPT42Backdoor / C2 toolMediumHash not committed; retrieve current IOCs from linked source or vendor appendix.
ASPXSpyAgriusWeb shellMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
ApostleAgriusWiper / ransomware-like malwareMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
BFG AgonizerAgriusWiperMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
BlackShadowAgriusRansomware / personaMediumHash not committed; persona claims require corroboration.
DEADWOODAgriusWiperMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
IPsec HelperAgriusMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
MimikatzAgriusCredential access toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
MoneybirdAgriusRansomware / destructive malwareMediumHash not committed; source IOC appendix should be used if needed.
MultiLayer WiperAgriusWiperMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
NBTscanAgriusNetwork scannerMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
WezRatCotton SandstormModular infostealer / RATHighHash not committed; use Check Point and government IOC references for current sample hashes, lure senders, domains, and C2 paths.
Cyber Toufan supplier-access playbookCyber ToufanCredential and admin-interface abuseMediumNot malware; no hash. Track claims and exposure indicators.
IOControlCyberAv3ngersOT/IoT malwareHighClaroty-published SHA256 1b39f9b2b96a6586c4a11ab2fdbff8fdf16ba5a0ac7603149023d73f33b84498; VT enrichment found an ELF with public detections and label trojan.iocontrol/multiverze.
Unitronics Vision PLC Web/HMICyberAv3ngersTargeted technologyHighNot malware; no hash. Exposure and configuration indicators only.
DarkBit ransomwareDarkBitPseudo-ransomware / destructive malwareMediumHash not committed; incident-specific IOCs should come from INCD/Microsoft source material.
IMAPLoaderImperial Kitten.NET downloader / loaderHighHash not committed; use PwC or vendor IOC appendix/current report for current sample hashes and mail-account indicators.
StandardKeyboardImperial KittenBackdoor / C2 toolMediumHash not committed; use CrowdStrike source if available.
Caterpillar WebShellLebanese CedarWeb ShellMediumHash not committed; use ClearSky report references.
Explosive RATLebanese CedarRemote Access TrojanMediumHash not committed; use ClearSky report references.
BITSAdminLyceumLiving-off-the-land binaryMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
DanBotLyceumRemote Access TrojanMediumHash not committed; use MITRE references and primary reports.
DnsSystemLyceumBackdoorMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
EmpireLyceumPost-exploitation frameworkMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
KevinLyceumBackdoorLowHash not committed; use MITRE references and primary reports.
MilanLyceumBackdoorMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
MimikatzLyceumCredential access toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
PingLyceumNetwork utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
PoshC2LyceumPost-exploitation frameworkMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
SharkLyceumBackdoorLowHash not committed; use MITRE references and primary reports.
ipconfigLyceumSystem discovery utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
netstatLyceumSystem discovery utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
CharmPowerMagic HoundPowerShell backdoorMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
DownPaperMagic HoundBackdoorMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
FRP / PlinkMagic HoundDual-use tunneling / proxy toolingMediumNo malware hash; dual-use binary monitoring and local allowlisting required.
ImpacketMagic HoundPython network protocol toolkitMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
MimikatzMagic HoundCredential access toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
Mimikatz / SQLMap / HavijMagic HoundPublic offensive/security toolingMediumNo stable actor-specific hash; use process, command-line, and control-plane telemetry.
NetMagic HoundSystem administration utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
PingMagic HoundNetwork utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
PowerLessMagic HoundBackdoorMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
PsExecMagic HoundRemote execution utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
PupyMagic HoundRAT / post-exploitation frameworkMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
SysteminfoMagic HoundSystem discovery utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
ipconfigMagic HoundSystem discovery utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
netshMagic HoundNetwork configuration utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
BlackBeardMuddyWaterBackdoorMediumHash not committed; use INCD source-linked IOCs.
BugSleepMuddyWaterBackdoorHighHash not committed from source page; use Check Point IOC appendix/current report if sample-level matching is required.
ConnectWiseMuddyWaterRemote monitoring and management toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
CrackMapExecMuddyWaterPost-exploitation / credential validation toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
DCHSpyMuddyWaterMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
DindoorMuddyWaterBackdoorLowHash not committed; use source-linked IOCs only.
EmpireMuddyWaterPost-exploitation frameworkMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
FakesetMuddyWaterBackdoorLowHash not committed; use source-linked IOCs only.
Fooder / MuddyViperMuddyWaterLoader and backdoorMediumHash not committed; validate ESET IOC availability before IOC-level use.
KoadicMuddyWaterPost-exploitation frameworkMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
LP-NotesMuddyWaterMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
LaZagneMuddyWaterCredential access toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
MimikatzMuddyWaterCredential access toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
MoriMuddyWaterMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
Out1MuddyWaterMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
POWERSTATSMuddyWaterMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
PowGoopMuddyWaterMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
PowerSploitMuddyWaterPowerShell post-exploitation frameworkMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
RcloneMuddyWaterCloud sync / exfiltration utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
Remote Monitoring and Management toolsMuddyWaterLiving-off-the-land toolingHighNo malware hash; inventory and signed binary allowlist required.
RemoteUtilitiesMuddyWaterRemote administration toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
RustyWaterMuddyWaterMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
SHARPSTATSMuddyWaterMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
STARWHALEMuddyWaterMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
Small SieveMuddyWaterMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
Tsundere BotnetMuddyWaterMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
BONDUPDATEROilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
HelminthOilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
ISMInjectorOilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
LaZagneOilRigCredential access toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
MangoOilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
MimikatzOilRigCredential access toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
NetOilRigSystem administration utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
ODAgentOilRigMITRE-listed software/toolHighImported SHA1 seed 7E498B3366F54E936CB0AF767BFC3D1F92D80687 returned VT not_found and remains unpromoted pending primary hash verification.
OilBoosterOilRigDownloaderHighPrimary source confirms tool behavior; imported SHA1 seed 1B2FEDD5F2A37A0152231AE4099A13C8D4B73C9E returned VT not_found and remains unpromoted pending primary hash verification.
OilCheckOilRigMITRE-listed software/toolHighImported SHA1 seed 8D84D32DF5768B0D4D2AB8B1327C43F17F182001 returned VT not_found and remains unpromoted pending primary hash verification.
OopsIEOilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
POWRUNEROilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
PowerExchangeOilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
PsExecOilRigRemote execution utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
QUADAGENTOilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
RDATOilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
RGDoorOilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
RegOilRigRegistry utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
SEASHARPEEOilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
SaitamaOilRigDNS-tunneling backdoorHighHash not committed; use Unit 42 IOC references if needed.
SampleCheck5000OilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
SideTwistOilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
SolarOilRigMITRE-listed software/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
SysteminfoOilRigSystem discovery utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
TasklistOilRigProcess discovery utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
ZeroCleareOilRigWiperMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
certutilOilRigLiving-off-the-land binaryMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
ftpOilRigLiving-off-the-land utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
ipconfigOilRigSystem discovery utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
netstatOilRigSystem discovery utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
ngrokOilRigTunneling / proxy toolingMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
NGROK / LigoloPioneer KittenTunneling / proxy toolingHighNo malware hash; monitor tool binary, process, account, and network usage against approved admin list.
LiontailScarred ManticorePassive backdoor frameworkHighHash not committed; use Check Point source report references and local IIS module baselines.
IronWindTA402Initial access downloader / staged malwareHighProofpoint-published SHA256 indicators include 9b2a16cbe5af12b486d31b68ef397d6bc48b2736e6b388ad8895b588f1831f47, 5d773e734290b93649a41ccda63772560b4fa25ba715b17df7b9f18883679160, 19f452239dadcd7544f055d26199cb482c1f6ae5486309bde1526174e926146a, A4bf96aee6284effb4c4fe0ccfee7b32d497e45408e253fb8e1199454e5c65a3, and 26cb6055be1ee503f87d040c84c0a7cacb245b4182445e3eee47ed6e073eca47; use full Proofpoint IOC list for operational use.
CRYPTOSLAYUNC1860Associated familyMediumFamily confirmed by Malpedia; no per-sample hash committed in this repo.
PipeSnoopUNC1860Referenced tool/family termLowReference confirmed by Malpedia; no per-sample hash committed in this repo.
SASHEYAWAYUNC1860Dropper / access-enablement toolingHighMandiant publishes activity-level MD5 IOCs and a VT collection; this repo does not map every hash to SASHEYAWAY.
STAYSHANTEUNC1860Web shell / handoff toolingHighMandiant publishes activity-level MD5 IOCs and a VT collection; this repo does not map every hash to STAYSHANTE.
TEMPLEDOORUNC1860Passive backdoor familyHighRepresentative Mandiant MD5s include c57e59314aee7422e626520e495effe0 and b219672bcd60ce9a81b900217b3b5864. VT enrichment found b219672bcd60ce9a81b900217b3b5864 as Win32 EXE/System.dll with 47 malicious public detections; c57e59314aee7422e626520e495effe0 returned VT not_found.
TEMPLEDROPUNC1860Passive backdoor / driver-abuse implantHighMandiant reports related Sheed AV MD5 0c93cac9854831da5f761ee98bb40c37 and WINTAPIX/TOFUDRV MD5s 286bd9c2670215d3cb4790aac4552f22 and b4b1e285b9f666ae7304a456da01545e in the same report; VT enrichment found the Sheed AV reference as signed and not malicious by public verdicts.
TEMPLELOCKUNC1860Defense-evasion utilityHighHash not committed; use Mandiant activity-level IOC list.
TEMPLEPLAYUNC1860GUI malware controllerHighMandiant reports MD5 c517519097bff386dc1784d98ad93f9d for TEMPLEPLAY; VT enrichment returned not_found on 2026-05-16.
VIROGREENUNC1860GUI exploitation / post-exploitation frameworkHighHash not committed; use Mandiant source and technical annex where accessible.
SUGARUSH / SUGARDUMPUNC3890Information stealerMediumHash not committed; use Mandiant source references.
BiBi / BiBi Wiper lineageVoid Manticore / HandalaWiper / destructive malware lineageMediumHash not committed; use primary wiper reports for active IOCs.
CHIMNEYSWEEPVoid Manticore / HandalaWiperMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
Handala-linked destructive installer chainsVoid Manticore / HandalaInstaller-led destructive chainMediumHash not committed; chain behavior matters more than static IOCs.
ImpacketVoid Manticore / HandalaPython network protocol toolkitMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
MimikatzVoid Manticore / HandalaCredential access toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
ROADSWEEPVoid Manticore / HandalaWiperMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
RawDiskVoid Manticore / HandalaDisk access driver/toolMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
ZeroCleareVoid Manticore / HandalaWiperMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
ftpVoid Manticore / HandalaLiving-off-the-land utilityMediumHash not committed; use the linked MITRE references and original source reports for current IOCs.
AshTagWIRTEModular .NET malware suiteHighRepresentative Unit 42 SHA256s include f554c43707f5d87625a3834116a2d22f551b1d9a5aff1e446d24893975c431bc, 739a5199add1d970ba22d69cc10b4c3a13b72136be6d45212429e8f0969af3dc, 6bd3d05aef89cd03d6b49b20716775fe92f0cf8a3c2747094404ef98f96e9376, 30490ba95c42cefcca1d0328ea740e61c26eaf606a98f68d26c4a519ce918c99, and 66ab29d2d62548faeaeadaad9dd62818163175872703fda328bb1b4894f5e69e; use full Unit 42 IOC table for coverage.
SameCoinWIRTEWiperHighCheck Point publishes lure hash b7c5af2d7e1eb7651b1fe3a224121d3461f3473d081990c02ef8ab4ace13f785; component hashes should be pulled from the primary Check Point/HarfangLab references before blocking.