CyberSecurityBoardThreat Intel · CVEs · Products

Category: Malware

Malware families, payloads, loaders, ransomware and related tooling.

Malware

Havoc: Post-Exploitation Framework

Havoc is a post-exploitation framework used by attackers, including the 'Poisson' operator, to deploy the Demon agent for command and control.

C2 Demon agent Havoc post-exploitation
June 25, 2026
Malware

Demon Agent: Havoc’s Implant

The Demon agent is the implant component of the Havoc framework, used for in-memory execution and persistence on compromised systems.

Demon agent Havoc implant in-memory
June 25, 2026
Malware

Python Keylogger Used by Poisson Operator

A 70-line Python keylogger was deployed by the attacker to capture keystrokes, storing them locally for manual retrieval, targeting banking and email…

credential theft keylogger keystroke logging Python
June 25, 2026
Malware

ABYSSWORKER Malicious Driver

ABYSSWORKER is a custom-built malicious driver used in BYOVD attacks, previously observed in Medusa ransomware incidents.

ABYSSWORKER BYOVD driver malware
June 25, 2026
Malware

Backdoor.Turn Remote Access Trojan

Backdoor.Turn is a custom Go-based RAT that conceals C2 traffic inside Microsoft Teams relay infrastructure using TURN relays and QUIC sessions, supporting…

Backdoor.Turn C2 Microsoft Teams QUIC
June 25, 2026