Software
Malware and tool entries linked to techniques, groups, and campaigns.
Software results
Results are validated against normalized ATT&CK source records when available; sample records are used only in development or empty-data environments.
S1048: macOS.OSAMiner
macOS.OSAMiner is a Monero mining trojan that was first observed in 2018; security researchers assessed macOS.OSAMiner may have been circulating since at least 2015. macOS.OSAMiner is known for embedding one run-only AppleScript into another, which helped the malware evade full analysis for five years due to a lack of Apple event (AEVT) analysis tools.[1][2]
S0175: meek
meek is an open-source Tor plugin that tunnels Tor traffic through HTTPS connections.
S1059: metaMain
S0102: nbtstat
S0108: netsh
S0104: netstat
S0508: ngrok
S0385: njRAT
S0067: pngdowner
pngdowner is malware used by Putter Panda. It is a simple tool with limited functionality and no persistence mechanism, suggesting it is used only as a simple "download-and- execute" utility. [1]
S0006: pwdump
S1187: reGeorg
S0103: route
S0111: schtasks
S0227: spwebmember
spwebmember is a Microsoft SharePoint enumeration and data dumping tool written in .NET. [1]
S0225: sqlmap
S0653: xCaon
S0123: xCmd
S0248: yty
S0350: zwShell
zwShell is a remote access tool (RAT) written in Delphi that has been seen in the wild since the spring of 2010 and used by threat actors during Night Dragon.[1]
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.