Netskope Threat Labs

Threat Research

Threat Library

A searchable index of malware and IPS signatures from the Netskope One Platform.

Search alert names, families, CVEs, SIDs, and groups — or narrow results by engine.

Start typing to search across every malware and IPS signature from the Netskope One Platform.

ClickFix

ClickFix is a social engineering technique in which cyberattackers present a fake CAPTCHA, browser update, or error message and instruct users to copy an obfuscated command and paste it into the Windows Run dialog or a terminal. Because users run the command themselves, the attack bypasses email filters, browser sandboxes, and other defenses that block malicious file downloads, and it has become a leading delivery method for infostealers such as Lummastealer and Amatera since late 2024.

Shai-Hulud

Shai-Hulud is a self replicating worm that spreads through package registries and developer toolchains, and the worm plants itself in code repositories and build systems. Its campaigns stole credentials and secrets from developer environments and used them to push infected packages onward, creating a chain of compromise that spread without user interaction. Researchers analyzed one of its major waves, and the family has become a reference point for supply chain worm risks in software ecosystems.

XWorm

XWorm is a remote access trojan written in C sharp that provides extensive control over infected systems, including remote desktop, keylogging, clipboard monitoring, and ransomware style features. Its cheap builder and active developer updates made it one of the most widely deployed commodity RATs, and its campaigns spread through phishing, USB drives, and loader chains. Researchers documented a major version update and its new capabilities and delivery techniques.

Remcos

Remcos is a remote access trojan sold as a legitimate surveillance product that provides an extensive list of features to remotely control devices, and cyberattackers popularly abuse it in many campaigns. Its capabilities include remote desktop, keystroke logging, camera access, and file management, and its builder produces customized implants for each buyer. Distributed through phishing and loader chains, it remains one of the most commonly detected commercial RATs.

Bumblebee

Bumblebee is an alternate detection name for the BumbleBee malware loader, a delivery tool that emerged in 2022 and installs heavier payloads on infected systems. Its operators distribute it through phishing emails with striped archive attachments, and it commonly fetches remote access trojans, information stealers, and command and control beacons for ransomware operators. The loader's operators rewrite it regularly to defeat analysis and detection.

Latrodectus

Latrodectus is a malware loader that emerged in late 2023 with rapid evolution and new payload features that caught researchers' attention in 2024. Distributed through phishing campaigns and search engine poisoning, it establishes persistence and downloads payloads such as remote access trojans and command and control frameworks. Researchers view it as the successor to IcedID's loader role, and its developers iterate quickly to defeat detection and analysis.

Azorult

Azorult (a.k.a. PuffStealer) is an information stealer sold on underground forums that harvests saved passwords, browser cookies, cryptocurrency wallets, and other sensitive data from infected systems. It first appeared around 2016, and its leaked source code has enabled cyberattackers to produce numerous modified variants. Distributors commonly bundle it with fake software installers, cracked applications, and loaders sold through malware as a service marketplaces.