Virlock malware family
Virlock is a malware family tracked by MalwareAnalyzer by Cyble across 13 publicly analyzed samples. First seen 2026-07-27, most recently 2026-08-20. Observed ATT&CK techniques include T1112.
Corpus statistics
- Publicly analyzed samples: 13
- First seen: 2026-07-27
- Last seen: 2026-08-20
- Verdicts: malicious 13
- File types: pe 13
ATT&CK techniques used by Virlock
- T1112 - 5 samples
Recent Virlock samples
- virussign.com_958d17c886de929a77b225978075cc90.vir - malicious (2026-08-20)
- virussign.com_b7a455f8cdbb020d25d9162bf1074fb0.vir - malicious (2026-08-19)
- virussign.com_0d773d927989a5d6fd0d6faa22b84e30.vir - malicious (2026-08-12)
- virussign.com_ef94593c1120363eb89c6132cf1f1e40.vir - malicious (2026-08-12)
- virussign.com_eb23b0326b073143ae28acbaa217df80.vir - malicious (2026-08-12)
- virussign.com_db8f1af8c52f8d09f477abaa7cac23c0.vir - malicious (2026-08-12)
- virussign.com_14205f134164be0c9b38c80bba7ca6d0.vir - malicious (2026-08-11)
- virussign.com_fa16178585b301e2a2746b863a964a70.vir - malicious (2026-08-11)
- virussign.com_ff015eb053a57a5c41218d3fc2e054a0.vir - malicious (2026-08-10)
- virussign.com_49373d954d1fe21780a70a2c2aeafa40.vir - malicious (2026-07-31)
- virussign.com_a47bcf4f0979e27869c61b2d0f986a60.vir - malicious (2026-07-27)
- virussign.com_e6f0e6fd4e1b011a6e3de8f97fd2c470.vir - malicious (2026-07-27)
- virussign.com_a6537cc0140a1ee7ca0860bb39e6ac10.vir - malicious (2026-07-27)
Frequently asked about Virlock
- What is Virlock?
- Virlock is a malware family tracked by MalwareAnalyzer by Cyble across 13 publicly analyzed samples. First seen 2026-07-27, most recently 2026-08-20. Observed ATT&CK techniques include T1112.
- How many Virlock samples have been analyzed?
- MalwareAnalyzer by Cyble holds 13 publicly analyzed samples attributed to Virlock, first seen 2026-07-27 and most recently 2026-08-20. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Virlock use?
- Across our Virlock samples the most frequently observed techniques are T1112 (5). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Virlock use?
- Virlock samples in this corpus are distributed as pe (13).
- Is Virlock malicious?
- 13 of 13 analyzed Virlock samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends