EYLR malware family
EYLR is a malware family tracked by MalwareAnalyzer by Cyble across 7 publicly analyzed samples. First seen 2026-07-29, most recently 2026-08-15. Observed ATT&CK techniques include T1112, T1105.
Corpus statistics
- Publicly analyzed samples: 7
- First seen: 2026-07-29
- Last seen: 2026-08-15
- Verdicts: malicious 7
- File types: pe 7
ATT&CK techniques used by EYLR
Recent EYLR samples
- 4be2b258e96df071001e073cc20687a040623d4359bc4825422b19583e0a2a77 - malicious (2026-08-15)
- db29448900bc8ac7f8b2cfc9ccb053127868c8ef07c2bbb9ebe6475e7f70aeb7 - malicious (2026-08-09)
- 4b59f672bca39dc53629e2bc017e428c91a08051995182cf7ca0ea1db0dca933 - malicious (2026-08-09)
- 43e1d3ac7a18b73a80298791a9bf3f084c244873bd8e8a5894b35baf09e6647f - malicious (2026-08-09)
- b0f0da7b1cd401c152bc611f03bc0693d5619b9d30b1e165c79ae6c15aa32c0f - malicious (2026-08-08)
- 818fc91035001088985191fa3925f90d080c5b1bc271a0768d4d581eabcab415 - malicious (2026-07-29)
- 2e251f134fec649859a6b2db5edd0a78ac4b51af2e1015c70c3903684e99b6b7 - malicious (2026-07-29)
Frequently asked about EYLR
- What is EYLR?
- EYLR is a malware family tracked by MalwareAnalyzer by Cyble across 7 publicly analyzed samples. First seen 2026-07-29, most recently 2026-08-15. Observed ATT&CK techniques include T1112, T1105.
- How many EYLR samples have been analyzed?
- MalwareAnalyzer by Cyble holds 7 publicly analyzed samples attributed to EYLR, first seen 2026-07-29 and most recently 2026-08-15. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does EYLR use?
- Across our EYLR samples the most frequently observed techniques are T1112 (4), T1105 (2). Counts are the number of analyzed samples in which each technique was observed.
- What file types does EYLR use?
- EYLR samples in this corpus are distributed as pe (7).
- Is EYLR malicious?
- 7 of 7 analyzed EYLR samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends