Software
Malware and tool entries linked to techniques, groups, and campaigns.
Software results
Results are validated against normalized ATT&CK source records when available; sample records are used only in development or empty-data environments.
S1026: Mongall
Mongall is a backdoor that has been used since at least 2013, including by Aoqin Dragon.[1]
S0407: Monokle
S0149: MoonWind
S0284: More_eggs
More_eggs is a JScript backdoor used by Cobalt Group and FIN6. Its name was given based on the variable "More_eggs" being present in its code. There are at least two different versions of the backdoor being used, version 2.0 and version 4.4. [1][2]
S1047: Mori
Mori is a backdoor that has been used by MuddyWater since at least January 2022.[1][2]
S0256: Mosquito
S9032: MuddyViper
MuddyViper is custom backdoor written in C and C++ used by MuddyWater for command and control (C2) communications and persistence. MuddyViper is loaded by Fooder and sends frequent messages to the C2 server.[1]
S1135: MultiLayer Wiper
MultiLayer Wiper is wiper malware written in .NET associated with Agrius operations. Observed samples of MultiLayer Wiper have an anomalous, future compilation date suggesting possible metadata manipulation.[1]
S0699: Mythic
S0590: NBTscan
S0272: NDiskMonitor
NDiskMonitor is a custom backdoor written in .NET that appears to be unique to Patchwork. [1]
S0034: NETEAGLE
S0198: NETWIRE
S1106: NGLite
NGLite is a backdoor Trojan that is only capable of running commands received through its C2 channel. While the capabilities are standard for a backdoor, NGLite uses a novel C2 channel that leverages a decentralized network based on the legitimate NKN to communicate between the backdoor and the actors.[1]
S1192: NICECURL
S1107: NKAbuse
S0353: NOKKI
S9025: NOOPLDR
NOOPLDR is a shellcode loader with XML/C# and DLL versions that has been used by MirrorFace to load HiddenFace.[1]
S1131: NPPSPY
NPPSPY is an implementation of a theoretical mechanism first presented in 2004 for capturing credentials submitted to a Windows system via a rogue Network Provider API item. NPPSPY captures credentials following submission and writes them to a file on the victim system for follow-on exfiltration.[1][2]
S0205: Naid
S0228: NanHaiShu
S0336: NanoCore
S0637: NativeZone
NativeZone is the name given collectively to disposable custom Cobalt Strike loaders used by APT29 since at least 2021.[1][2]
S0247: NavRAT
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.