Cymt malware family
Cymt is a malware family tracked by MalwareAnalyzer by Cyble across 11 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-23. Observed ATT&CK techniques include T1057, T1105, T1112.
Corpus statistics
- Publicly analyzed samples: 11
- First seen: 2026-07-28
- Last seen: 2026-08-23
- Verdicts: malicious 11
- File types: pe 11
ATT&CK techniques used by Cymt
Extracted command-and-control infrastructure
- http://curl.haxx.se/docs/http-cookies.html - 6 samples
Recent Cymt samples
- d0e552ceac8861b35167f14101ecedafea957b49cac0c9e9b078324955b487e9 - malicious (2026-08-23)
- virussign.com_c385f440ee5e0e7471065ad9dffb7c90.vir - malicious (2026-08-19)
- virussign.com_4d43367303abcc2fe886f69064e9ff80.vir - malicious (2026-08-18)
- virussign.com_fef91c28e92258417c9e473ed6752780.vir - malicious (2026-08-16)
- virussign.com_6c4f50c73c3095eead8bec853356e5e0.vir - malicious (2026-08-15)
- 8f8520d4a78d982224e1ea40e6cecf605d214594dd7a10475f29aca53194b413 - malicious (2026-08-15)
- virussign.com_66948d6a207e53bacd1e477badd7f9f0.vir - malicious (2026-08-11)
- 65db3fb5649b175c085930c165dd11d010df1b72bba7fdd7de8092485c90e263 - malicious (2026-08-11)
- 888dd4f96f63c9db306d32ed13673d535bf7a63053e86bcf3bbd5a1bfd260b97 - malicious (2026-08-10)
- bc8ae95aff73b0ee01926a1abbd2c4a00ad8e868e3caeee9a8baaf2124450e03 - malicious (2026-08-10)
- virussign.com_208588d6d1cfc823f90c809889826ea0.vir - malicious (2026-07-28)
Frequently asked about Cymt
- What is Cymt?
- Cymt is a malware family tracked by MalwareAnalyzer by Cyble across 11 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-23. Observed ATT&CK techniques include T1057, T1105, T1112.
- How many Cymt samples have been analyzed?
- MalwareAnalyzer by Cyble holds 11 publicly analyzed samples attributed to Cymt, first seen 2026-07-28 and most recently 2026-08-23. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Cymt use?
- Across our Cymt samples the most frequently observed techniques are T1057 (4), T1105 (2), T1112 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Cymt use?
- Cymt samples in this corpus are distributed as pe (11).
- Does Cymt use command-and-control infrastructure?
- Yes. 1 distinct command-and-control indicator has been extracted from Cymt samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Cymt malicious?
- 11 of 11 analyzed Cymt samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends