Kolab malware family
Kolab is a malware family tracked by MalwareAnalyzer by Cyble across 7 publicly analyzed samples. First seen 2026-08-13, most recently 2026-08-23. Observed ATT&CK techniques include T1071.001, T1056.001, T1547.001.
Corpus statistics
- Publicly analyzed samples: 7
- First seen: 2026-08-13
- Last seen: 2026-08-23
- Verdicts: malicious 7
- File types: pe 7
ATT&CK techniques used by Kolab
Recent Kolab samples
- ffa8b7cf81db9b0fc2c08f87d3d54b8e0d3852afe677d85b9b4d873d466c905c - malicious (2026-08-23)
- 8aeab8e691ea33cd91ebdc395c83949496df77ae6e712f142d16da64aae484ff - malicious (2026-08-23)
- cce290d975ec5f1b0f6e51881c8c22fa16a56c86dcb024ccdcdcf7a0c159eab8 - malicious (2026-08-21)
- c739915dc5b268190f6934ef6d220e2d29b1198ead0b4a53338318cd3f9b72de - malicious (2026-08-21)
- 9d624899f4e67ea1b6bafbad78ee75af4bd98f40ccd5254423d080fc15938362 - malicious (2026-08-19)
- 855221a08bf7d0e5a235ef097c2b82daf978ebdeec7f99b6ceeb1c175471f23f - malicious (2026-08-16)
- c41e738472ec02f93af629810b3db493a9a251443963f93865862b7773e14fd3 - malicious (2026-08-13)
Frequently asked about Kolab
- What is Kolab?
- Kolab is a malware family tracked by MalwareAnalyzer by Cyble across 7 publicly analyzed samples. First seen 2026-08-13, most recently 2026-08-23. Observed ATT&CK techniques include T1071.001, T1056.001, T1547.001.
- How many Kolab samples have been analyzed?
- MalwareAnalyzer by Cyble holds 7 publicly analyzed samples attributed to Kolab, first seen 2026-08-13 and most recently 2026-08-23. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Kolab use?
- Across our Kolab samples the most frequently observed techniques are T1071.001 (3), T1056.001 (1), T1547.001 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Kolab use?
- Kolab samples in this corpus are distributed as pe (7).
- Is Kolab malicious?
- 7 of 7 analyzed Kolab samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends