Malware Library
Copy link

The Malware Library page displays a centralized list of malware associated with campaign and threat actor profiles curated by Rapid7 Labs. Select a malware profile to view its details.

The malware profile overview page includes this information:

FieldDescription
AliasesAlternative or previous names for the malware.
DescriptionAn overview of the activities attributed to the threat actors using this malware.
Targeted locationsGeographic areas actively targeted or affected by this malware.
Targeted industriesSpecific market sectors or commercial domains actively targeted or affected by this malware.
First and last seenThe dates when the first and most recent IOC linked to the malware was spotted.
Confirmed capabilitiesActions the malware is known to take if it reaches your environment.
Behavioral notesUnusual or distinctive activity patterns that go beyond standard attack technique classifications.
Related articlesExternal articles related to the malware. Select an article to open it in a new browser tab.

The malware profile overview page includes these tabs:

TabDescription
CampaignsLists the campaigns associated with this malware. Select a campaign to open its overview page.
Threat actorsLists the threat actors associated with this malware. Select a threat actor to open its overview page.
CVEsLists the CVEs associated with the malware. Select a CVE to open it in the Rapid7 AttackerKB feed  in a new browser tab, where you can view descriptions and public references.
IOCsLists the IOCs associated with this malware. Select the briefcase icon to open the IOC in the Threat Investigations page for further enriched information. Select the magnifying glass icon to open a pre-built query for the IOC in Log Search .
Registry pathsLists the registry paths targeted by the threat actors behind the malware.
ScriptsLists the scripts observed in malicious use by the threat actors behind the malware. Select a script to view the underlying code.
Hunting rulesLists the hunting rules the Rapid7 Labs team created to identify suspicious or malicious activity associated with the malware. Select a hunting rule to view the underlying rule logic in the Hunting Rule Details.