Malware Library
The Malware Library page displays a centralized list of malware associated with campaign and threat actor profiles curated by Rapid7 Labs. Select a malware profile to view its details.
The malware profile overview page includes this information:
| Field | Description |
|---|---|
| Aliases | Alternative or previous names for the malware. |
| Description | An overview of the activities attributed to the threat actors using this malware. |
| Targeted locations | Geographic areas actively targeted or affected by this malware. |
| Targeted industries | Specific market sectors or commercial domains actively targeted or affected by this malware. |
| First and last seen | The dates when the first and most recent IOC linked to the malware was spotted. |
| Confirmed capabilities | Actions the malware is known to take if it reaches your environment. |
| Behavioral notes | Unusual or distinctive activity patterns that go beyond standard attack technique classifications. |
| Related articles | External articles related to the malware. Select an article to open it in a new browser tab. |
The malware profile overview page includes these tabs:
| Tab | Description |
|---|---|
| Campaigns | Lists the campaigns associated with this malware. Select a campaign to open its overview page. |
| Threat actors | Lists the threat actors associated with this malware. Select a threat actor to open its overview page. |
| CVEs | Lists the CVEs associated with the malware. Select a CVE to open it in the Rapid7 AttackerKB feed in a new browser tab, where you can view descriptions and public references. |
| IOCs | Lists the IOCs associated with this malware. Select the briefcase icon to open the IOC in the Threat Investigations page for further enriched information. Select the magnifying glass icon to open a pre-built query for the IOC in Log Search . |
| Registry paths | Lists the registry paths targeted by the threat actors behind the malware. |
| Scripts | Lists the scripts observed in malicious use by the threat actors behind the malware. Select a script to view the underlying code. |
| Hunting rules | Lists the hunting rules the Rapid7 Labs team created to identify suspicious or malicious activity associated with the malware. Select a hunting rule to view the underlying rule logic in the Hunting Rule Details. |