Collection of YARA signatures from recent malware research
Dacls Trojan
APT32 KerrDown
ACBackdoor - Linux build
Unnamed Linux Golang Ransomware
KPOT v2
WatchBog Linux botnet
EvilGnome Linux malware
APT34 PICKPOCKET
APT34 LONGWATCH
APT34 VALUEVAULT
RedGhost Linux tool
SilentTrinity
DNSpionage
TA505 FlowerPippi
REMCOS RAT
GodLua Linux Backdoor
APT32 Ratsnif
OSX/CrescentCore
side note: when will we all decide to change mac sig names to macOS/
WarZone RAT aka Ave Maria Stealer
Winnti Linux