| Campaign | Family | Actor | Platform | Type | Date | Coverage |
|---|---|---|---|---|---|---|
| PolinRider | BeaverTail → InvisibleFerret | DPRK / Lazarus | npm | Supply chain | 2026-06-22 | YARA · Sigma · KQL · IOCs |
| Shai-Hulud (nhmpy) | Shai-Hulud · Hades wave | Unattributed | PyPI | Supply chain | 2026-06-14 | YARA · Sigma · KQL · IOCs |
| MuddyWater | MuddyWater backdoor RAT | MuddyWater (Iran-nexus) | Office macro / PowerShell | APT | 2019-01-11 | — |
| Noblis In-dev | Noblis | Unattributed | Python / PyInstaller | Ransomware | 2017-12-13 | — |
| File-Spider | Spider ransomware | Unattributed | Office macro | Ransomware | 2017-12-11 | — |
| LockCrypt | LockCrypt | Unattributed | Windows PE | Ransomware | 2017-12-01 | — |
| JS-spread ransomware | Batch file-crypter | Unattributed | JavaScript | Ransomware | 2016-06-06 | — |
Threat Tracker
A filterable index of malware campaigns, ransomware families and APT operations analysed on Melted in Hex, with actor attribution, platform, ATT&CK mapping and detection coverage.