Crimson is a remote access trojan (RAT) developed using the .NET platform and used by the APT36 advanced persistent threat group.
Mozart is a backdoor that targets Microsoft Windows and uses the DNS protocol for command and control (C2) communication.
First observed in December 2019, Parallax is an MASM-based remote access trojan sold through a number of hacking forums, with its creators offering a number of additional support services as well as bespoke development based on affiliate feedback.
A number of new downloader and remote access trojans (RAT) have been observed in campaigns globally. All five identified tools are believed to have been created by the Hidden Cobra advanced persistent threat group for use in their own campaigns.
First observed in early 2020, KBOT is a polymorphic virus that exfiltrates financial and credential data from affected systems. As of the time of publication, it appears to be the first new virus observed in the wild in several years.
Ragnar Locker is a newly observed ransomware tool targeting organisations in North America, Europe, and East Asia.
Warzone is a C++ based remote access trojan (RAT) offered via a number of dark web sites and hacking forums. It offers a comprehensive malware-as-a-service (MaaS) package, including licensing agreements and customer support, to allow non-technical users to perform sophisticated attacks.
Netwalker (also known as Kazakavkovkiz or KoKo) is a fileless ransomware-as-a-service tool, mainly targeted at enterprise targets in Western Europe and the USA. Previously called Mailto, the name was changed when the creators began offering its services to affiliate users via dark web sites.
BitPyLock is a ransomware tool that attempts to steal sensitive information from systems before encryption. Believed to have been created to target individual users, it has evolved to target entire networks, with operators using the extracted information to get organisations to pay ransom demands.
Ako, also known as MedusaReborn, is a newly observed ransomware tool targeting larger business networks. Despite being used in several active campaigns it appears to still be in active development, with its creators offering daily beta versions for attackers to use.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
