Underground hacking Forums are the part of the Internet where hackers and other cybercriminals advertise various hacking tools, new malware , and more.
Researchers analyzed over 3.9 million posts and came up with the top malware variants advertised on hacking forums. Based on the most popular malicious applications , we can also understand the most popular attacks .
Researchers found different categories of malware in different languages. What they noticed is that Underground hacking Forums in different languages (e.g. English, Chinese) focus on different malware and attack vectors.
The top malware categories typically include dual-use tools, such as MinerGate and Imminent Monitor, as well as open-source malware, such as njRat, AhMyth, Mirai, and Gh0st RAT.
According to the researchers, in hacking forums, where English and Chinese , users are mainly interested in Android. In Chinese forums, the most popular Android Trojans are: SpyNote, AhMyth, and DroidJack. In English-speaking forums, the most common are SpyNote and DroidJack.

Another popular trojan on English-speaking forums is NJRat. NJRat is known for its stealthy operations. It compromises the system without being noticed, while being able to disable Antivirus software and other Windows security features.

The research team found that between May 2018 and May 2019, the top malware categories were ransomware, crypters, trojans , and web shells.

Let's take a look at the Top 10 malware being advertised on Underground hacking Forums right now. They include remote access trojans, information , and other tools.
Top malware and delivery mechanism

Top malware hashes

Sellers on Underground hacking Forums also post various comments about the malware and are constantly adding new variants to attract more buyers.
Organizations and companies should place great emphasis on their security and make frequent updates to their systems to avoid all these risks.
