Somhoveran malware family
Somhoveran is a malware family tracked by MalwareAnalyzer by Cyble across 191 publicly analyzed samples. First seen 2026-07-26, most recently 2026-08-20. Observed ATT&CK techniques include T1112, T1543.003, T1105.
Corpus statistics
- Publicly analyzed samples: 191
- First seen: 2026-07-26
- Last seen: 2026-08-20
- Verdicts: malicious 191
- File types: pe 191
ATT&CK techniques used by Somhoveran
Recent Somhoveran samples
- virussign.com_5fa3b4720242dd7bba9e8f905f5f43f0.vir - malicious (2026-08-20)
- virussign.com_9eab0561c45b3a94a7e602add94eb9f0.vir - malicious (2026-08-19)
- net.cpl - malicious (2026-08-18)
- wlogon.dll - malicious (2026-08-18)
- wlogon.dll - malicious (2026-08-18)
- virussign.com_b7b29c8cbd1d43fb1985f7c4f0d29500.vir - malicious (2026-08-18)
- lcss.exe - malicious (2026-08-18)
- net.cpl - malicious (2026-08-18)
- net.cpl - malicious (2026-08-18)
- lcss.exe - malicious (2026-08-18)
- crypto.dll - malicious (2026-08-18)
- wlogon.dll - malicious (2026-08-18)
- lcss.exe - malicious (2026-08-18)
- crypto.dll - malicious (2026-08-18)
- net.cpl - malicious (2026-08-18)
- lcss.exe - malicious (2026-08-18)
- lcss.exe - malicious (2026-08-18)
- wlogon.dll - malicious (2026-08-18)
- lcss.exe - malicious (2026-08-18)
- crypto.dll - malicious (2026-08-18)
- wlogon.dll - malicious (2026-08-18)
- crypto.dll - malicious (2026-08-18)
- net.cpl - malicious (2026-08-18)
- wlogon.dll - malicious (2026-08-18)
Frequently asked about Somhoveran
- What is Somhoveran?
- Somhoveran is a malware family tracked by MalwareAnalyzer by Cyble across 191 publicly analyzed samples. First seen 2026-07-26, most recently 2026-08-20. Observed ATT&CK techniques include T1112, T1543.003, T1105.
- How many Somhoveran samples have been analyzed?
- MalwareAnalyzer by Cyble holds 191 publicly analyzed samples attributed to Somhoveran, first seen 2026-07-26 and most recently 2026-08-20. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Somhoveran use?
- Across our Somhoveran samples the most frequently observed techniques are T1112 (82), T1543.003 (82), T1105 (47). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Somhoveran use?
- Somhoveran samples in this corpus are distributed as pe (191).
- Is Somhoveran malicious?
- 191 of 191 analyzed Somhoveran samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends