Downware malware family
Downware is a malware family tracked by MalwareAnalyzer by Cyble across 9 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-16. Observed ATT&CK techniques include T1112.
Corpus statistics
- Publicly analyzed samples: 9
- First seen: 2026-07-28
- Last seen: 2026-08-16
- Verdicts: malicious 9
- File types: pe 9
ATT&CK techniques used by Downware
- T1112 - 5 samples
Recent Downware samples
- virussign.com_f50c2a818aba28977daf3191a255e790.vir - malicious (2026-08-16)
- 7cf69b54668f146abec4ab0114f5d0bc624ade55f0264fa0248fe2323e73ca85 - malicious (2026-08-14)
- virussign.com_7ec6c7e5e9430985a46fe5866535d590.vir - malicious (2026-08-13)
- virussign.com_82833b3f098bb13057a9173cf7f106e0.vir - malicious (2026-08-11)
- d3d14c684db75ac98d9a034ae2800bfafa156f6d74e5933b3968813bb4f080e4 - malicious (2026-08-10)
- virussign.com_c0c77ea799d17d16925eebb798aa9830.vir - malicious (2026-07-28)
- virussign.com_425427b3035e13aecbf0f7cce27e13c0.vir - malicious (2026-07-28)
- virussign.com_9d6149aca5bcf8b0b3126c9e38c6dc50.vir - malicious (2026-07-28)
- virussign.com_da6a0e08cde64514b182823dd6b76070.vir - malicious (2026-07-28)
Frequently asked about Downware
- What is Downware?
- Downware is a malware family tracked by MalwareAnalyzer by Cyble across 9 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-16. Observed ATT&CK techniques include T1112.
- How many Downware samples have been analyzed?
- MalwareAnalyzer by Cyble holds 9 publicly analyzed samples attributed to Downware, first seen 2026-07-28 and most recently 2026-08-16. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Downware use?
- Across our Downware samples the most frequently observed techniques are T1112 (5). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Downware use?
- Downware samples in this corpus are distributed as pe (9).
- Is Downware malicious?
- 9 of 9 analyzed Downware samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends