Ravartar malware family
Ravartar is a malware family tracked by MalwareAnalyzer by Cyble across 15 publicly analyzed samples. First seen 2026-07-31, most recently 2026-08-14. Observed ATT&CK techniques include T1112, T1543.003, T1105.
Corpus statistics
- Publicly analyzed samples: 15
- First seen: 2026-07-31
- Last seen: 2026-08-14
- Verdicts: malicious 15
- File types: pe 9, lnk 4, office-ole 2
ATT&CK techniques used by Ravartar
Recent Ravartar samples
- 7fb2eb86c91debed78749d740ef93e36e900426039c1c40588e87701aa0495d6.exe - malicious (2026-08-14)
- 3ac58fa52f4692eed350cb4f92a27c5e6c43690f0c6a417a396f407d8da7435b.exe - malicious (2026-08-11)
- 396169f548a22508b32c068cc32af729858787dd0bad0a888da441cb98a3b998.exe - malicious (2026-08-11)
- 2ee9d81f5ac5a4a77fbca866ef5043d0f16d59be8a25d9e7e21bac0bbba73025.exe - malicious (2026-08-10)
- 2c8fb59e7dde79637aefe2d7ec6aaba0b6e5c6f6eacf0f7f0b6b9598b895bb7b.exe - malicious (2026-08-10)
- 209eff3e115e645149c2429bde02ed699f257fba9f3e7d6662156f8ea14d8174.exe - malicious (2026-08-09)
- cbd7e2c7304c1af65fb0d0af5e9a667c0e933662dfd7d4175a6ddaea416c4100.msi - malicious (2026-08-07)
- 113f9b3017f0cac7a64800a8b986c35da6db02b45ab0b573411777b12054c955.exe - malicious (2026-08-05)
- 7df9619f4ebfbfae75755efb99f044815ecfb17a8077fe90b300da86fc9e49e7.xlsx - malicious (2026-08-03)
- virussign.com_5ba1835522b0e4547386f84c32ab5e00.vir - malicious (2026-08-01)
- virussign.com_5dfbf9607f81e0ba8fe8c655406bb5e0.vir - malicious (2026-07-31)
- photov_336948176123.lnk - malicious (2026-07-31)
- photov_351499307841.lnk - malicious (2026-07-31)
- photov_489461938126.lnk - malicious (2026-07-31)
- photov_593373192028.lnk - malicious (2026-07-31)
Frequently asked about Ravartar
- What is Ravartar?
- Ravartar is a malware family tracked by MalwareAnalyzer by Cyble across 15 publicly analyzed samples. First seen 2026-07-31, most recently 2026-08-14. Observed ATT&CK techniques include T1112, T1543.003, T1105.
- How many Ravartar samples have been analyzed?
- MalwareAnalyzer by Cyble holds 15 publicly analyzed samples attributed to Ravartar, first seen 2026-07-31 and most recently 2026-08-14. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Ravartar use?
- Across our Ravartar samples the most frequently observed techniques are T1112 (8), T1543.003 (5), T1105 (2). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Ravartar use?
- Ravartar samples in this corpus are distributed as pe (9), lnk (4), office-ole (2).
- Is Ravartar malicious?
- 15 of 15 analyzed Ravartar samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends