Documentation

This page documents the malware and threat actors that Cert Central has identified. This page is a work in progress and will be updated as it can be updated. Not all malware we identify is associated with clear threat actors or malware families, but a naming system will be provided for researchers looking for particular malware or relations between malware.

Search Documentation

Contents

Threat Groups

Russian Cybercrime

Lumma Stealer

A malware sold in the form as "malware as a service". Used by a large range of actors.

Quakbot/Qakbot

Pending discussion of Quakbot.

PikaBot

Pending description of Pikabot

RUS-2

Cluster of seemingly related certificates. Likely issued by the same threat actor.

RUS-51

Threat actor targeted German organizations with vishing. Likely pre-ransomware. The actor was documented here: https://threadreaderapp.com/thread/1890384174671941869.html

NetSupport RAT

The use of NetSupport RAT being loaded into an installer and signed.

Indian Cybercrime

IND-1

Indian tech support scam

Nation State

DPRK

MATA

MATA is a malware used by DPRK to target Russian speaking users and organizations.

Unknown Cybercrime

UNK-50

Malware from this actor is not from a known group or known malware family. Malware from this actor targets Spanish speaking countries.