Malware adversary profiles & threat intelligence

Attack chains, MITRE ATT&CK mappings, IOCs, and detection guidance for ransomware operations, infostealers, loaders, and emerging malware campaigns.

Infostealer

Lumma Stealer

Steals credentials, session cookies, crypto wallets, and browser data.

Published on

View attack dissection
Loader

CastleLoader

Profiles infected devices and delivers additional malware payloads.

Published on

View attack dissection
Ransomware

Medusa Ransomware

Steals data and encrypts systems for double-extortion attacks.

Published on

View attack dissection
Discovered by ManageEngine
Infostealer

Fake Maccy Stealer

Impersonates a macOS app to steal credentials and sensitive data.

Published on

View attack dissection
Ransomware

LockBit Ransomware

Spreads across enterprise environments and encrypts critical systems.

Published on

View attack dissection
Ransomware

Akira Ransomware

Disables defenses, steals data, and encrypts Windows and Linux systems.

Published on

View attack dissection
Ransomware

The Gentlemen Ransomware

Destroys recovery options before encrypting networked systems.

Published on

View attack dissection
Ransomware

Qilin Ransomware

Steals data, disables defenses, destroys backups, and encrypts Windows, Linux, and VMware ESXi systems.

Published on

View attack dissection
Ransomware

Jadepuffer Ransomware

LLM-driven malware that turns AI into an attack weapon.

Published on

View attack dissection
Infostealer

Agent Tesla

.NET-based infostealer and RAT that harvests credentials, keystrokes, screenshots, and other sensitive data.

Published on

View attack dissection
Loader

DOUBLECUP

ClickFix loader service that uses browser-cached images to deliver CountLoader and DeviceManager.

Published on

View attack dissection
Loader

Chaindrop

Self-propagating npm supply-chain worm that steals developer credentials and compromises additional packages.

Published on

View attack dissection
Ransomware

StormEncryptor

Ransomware that encrypts files and appends the .encrypted extension during Storm-1175 attacks.

Published on

View attack dissection
Ransomware

Conti Ransomware

Human-operated RaaS ransomware that uses credential theft, lateral movement, and data exfiltration before domain-wide encryption.

Published on

View attack dissection
Ransomware

Carbanak Ransomware

Banking backdoor and intrusion set used for surveillance, credential theft, remote access, financial fraud, and ransomware operations.

Published on

View attack dissection
Ransomware

Spirals Ransomware

Rust-based ransomware that rapidly moves across compromised networks, disables defenses, and performs network-wide encryption.

Published on

View attack dissection
RAT/Espionage

Device Manager

Windows RAT that provides remote access, persistence, reconnaissance, and command execution.

Published on

View attack dissection
RAT/Espionage

GoSerpent

Go-based RAT used in cyberespionage campaigns to maintain access and collect sensitive information.

Published on

View attack dissection
RAT/Espionage

Turla Snake

Stealthy cyberespionage backdoor used by Turla for persistent access, command execution, and data collection.

Published on

View attack dissection
Verified by independent analysts & test labs

Ransomware Prevention Solutions

Recognized for advanced ransomware detection and prevention capabilities.

Business Main-Test Series

Approved Business Product across two consecutive test cycles.

Business Security Test Cycle

Approved Business Product in consecutive AV-Comparatives evaluations.

Stop adversaries before they reach impact

Malware Protection Plus detects stealers, loaders, and ransomware on Windows and macOS endpoints — with behavioral coverage across the kill chain.