Wanna malware family
Wanna is a malware family tracked by MalwareAnalyzer by Cyble across 9 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-17. Observed ATT&CK techniques include T1071.001, T1486, T1112.
Corpus statistics
- Publicly analyzed samples: 9
- First seen: 2026-07-28
- Last seen: 2026-08-17
- Verdicts: malicious 9
- File types: pe 9
ATT&CK techniques used by Wanna
Recent Wanna samples
- 9d769ee6c8365659c7a703f221caab25f1a972bf1324dc3623d08e2eaa5b4856.exe - malicious (2026-08-17)
- a08521395145577e6227ece283b7fb0f0ee05c02ef587a7b4ea84284bc374722.exe - malicious (2026-08-17)
- 6b465dc7cc21ba92d848425f8eabae3dc9f72d873d92a7b18639fd79814c7b1b.dll - malicious (2026-08-17)
- 2f7cb9e74f3396213418db82f7c723a4c168ace04fc791e7c0eb372fa87afb68.exe - malicious (2026-08-16)
- 9be73437f744884e7ee2af167deb9ffb93551419c2ad9b4f8852d3f7c5f3bb8b.exe - malicious (2026-08-14)
- 7fb8b06a9ac3c0c6b475948d1b981586cea76a2fc53f57c54163352fd90f0c63.exe - malicious (2026-08-14)
- 273c96eb5d64f3a07e8e741ac70c64dfb375f73e478bdf751508f033a9a36f3b.exe - malicious (2026-08-02)
- cc47c62f4d5bcc822047d79b90527bf66e30c294117c2d84337a87b124ae2db9.exe - malicious (2026-07-28)
- 8ec6066000f5585d6fefbc1d5a30fa094ac9893456dbf4085fec81e6b71cef3b.exe - malicious (2026-07-28)
Frequently asked about Wanna
- What is Wanna?
- Wanna is a malware family tracked by MalwareAnalyzer by Cyble across 9 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-17. Observed ATT&CK techniques include T1071.001, T1486, T1112.
- How many Wanna samples have been analyzed?
- MalwareAnalyzer by Cyble holds 9 publicly analyzed samples attributed to Wanna, first seen 2026-07-28 and most recently 2026-08-17. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Wanna use?
- Across our Wanna samples the most frequently observed techniques are T1071.001 (9), T1486 (9), T1112 (3). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Wanna use?
- Wanna samples in this corpus are distributed as pe (9).
- Is Wanna malicious?
- 9 of 9 analyzed Wanna samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends