Python Malware

Open-source Python projects categorized as Malware

Top 23 Python Malware Projects

  • hosts

    🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.

    Project mention: Does PiHole block porn? | /r/pihole | 2023-12-06

    Not by default but a blocklist can be found here

  • wifiphisher

    The Rogue Access Point Framework

    Project mention: I am looking for a shortcut to convert PICs like this to a working CSS code using the aid of AI, is it possible ? ( i am studying CyberSec, so i need temps like this from time to time, i am mediocre at programming tho) | /r/ChatGPT | 2023-04-09

    dis but for multiple vendors .. as a project for this semester

  • InfluxDB

    Collect and Analyze Billions of Data Points in Real Time. Manage all types of time series data in a single, purpose-built database. Run at any scale in any environment in the cloud, on-premises, or at the edge.

  • theZoo

    A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.

    Project mention: TheZoo a.k.a. Malware DB | | 2023-08-18
  • volatility

    An advanced memory forensics framework

    Project mention: What is the appropriate uncompressed kernel ELF to use with dwarf2json? [ 5.19.0-42-generic #43~22.04.1-Ubuntu ], in order to create generate a custom symbols table to conduct linux memory forensics on Ubuntu 22.04? | /r/computerforensics | 2023-05-28

    I need this to create generate a custom symbols table (using dwarf2json), in order to run a memory dump acquired by Ubuntu 22.04, as Ubuntu 22.04 kernel does not work anymore with volatility 2 (Issue here: volatilityfoundation/volatility#828)

  • pyWhat

    🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙‍♀️

  • maltrail

    Malicious traffic detection system

    Project mention: Maltrail: Malicious traffic detection system | /r/selfhosted | 2023-07-05

    I just wanted to tell you about Maltrail (

  • qiling

    A True Instrumentable Binary Emulation Framework

  • Onboard AI

    Learn any GitHub repo in 59 seconds. Onboard AI learns any GitHub repo in minutes and lets you chat with it to locate functionality, understand different parts, and generate new code. Use it for free at

  • flare-floss

    FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

    Project mention: Why is this de-compiled code showing a different value in memory sometimes? | /r/ghidra | 2023-03-06

    Depending on how clever the developer was, this tool works well to find hidden strings:

  • malwoverview

    Malwoverview is a first response tool used for threat hunting and offers intel information from Virus Total, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, InQuest and it is able to scan Android devices against VT.


    Interesting APT Report Collection And Some Special IOC

    Project mention: APT_REPORT/WithSecure-Lazarus-No-Pineapple-Threat-Intelligence-Report-2023.pdf at master · blackorbird/APT_REPORT | /r/SecOpsDaily | 2023-02-06
  • volatility3

    Volatility 3.0 development

    Project mention: Volatility 3 2.4.1 - New Linux and Windows plugins | /r/blueteamsec | 2023-04-22
  • CAPEv2

    Malware Configuration And Payload Extraction

  • yarGen

    yarGen is a generator for YARA rules

  • ThePhish

    ThePhish: an automated phishing email analysis tool

    Project mention: How do you deal with phising emails at your company? | /r/cybersecurity | 2023-05-14
  • drakvuf-sandbox

    DRAKVUF Sandbox - automated hypervisor-level malware analysis system

  • intelmq

    IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

  • empyrean

    Easy to use and open-source stealer that's super effective

    Project mention: so uhh help? when i downloaded this, it says that there's "21 security vendors and no sandboxes flagged this file as malicious". is this safe to run? | /r/antivirus | 2023-03-11

    here it is : and this is the thing im tryna download :

  • opensquat

    The openSquat project is an open-source solution for detecting phishing domains and domain squatting. It searches for newly registered domains that impersonate legitimate domains on a daily basis.

    Project mention: Have I Been Squatted? | | 2023-11-27

    A different solution that runs locally is opensquat.

  • Luna-Grabber

    The best discord token grabber made in python

    Project mention: EMERGENCY~!!!! Have been Doxxed | /r/pchelp | 2023-07-05

    I believe the program is something called Luna Grabber which has the ability to know if it is being used on a VM or not. However, there isn't much data on how to actually remove it from the computer.

  • packj

    Packj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain

    Project mention: Rust Without | | 2023-11-14

    Creator of Packj [1] here. How do you envision sandboxing/security policies will be specified? Per-lib policies when you've hundreds of dependencies will become overwhelming. Having built an eBPF-based sandbox [2], I anticipate that accuracy will be another challenge here: too restrictive will block functionality, too permissive defeats the purpose.

    1. flags malicious/risky NPM/PyPI/RubyGems/Rust/Maven/PHP packages by carrying out static+dynamic+metadata analysis.

  • Python-Rootkit

    Python Remote Administration Tool (RAT) to gain meterpreter session

  • MalConfScan

    Volatility plugin for extracts configuration data of known malware

  • misp-galaxy

    Clusters and elements to attach to MISP events or attributes (like threat actors)

    Project mention: Foreign Travel Risks | /r/cybersecurity | 2023-04-26

    MISP Threat Actor Galaxy

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020). The latest post mention was on 2023-12-06.

Python Malware related posts


What are some of the best open-source Malware projects in Python? This list will help you:

Project Stars
1 hosts 24,280
2 wifiphisher 12,304
3 theZoo 10,315
4 volatility 6,636
5 pyWhat 6,182
6 maltrail 5,479
7 qiling 4,323
8 flare-floss 2,841
9 malwoverview 2,581
10 APT_REPORT 2,034
11 volatility3 1,907
12 CAPEv2 1,473
13 yarGen 1,378
14 ThePhish 956
15 drakvuf-sandbox 908
16 intelmq 860
17 empyrean 784
18 opensquat 608
19 Luna-Grabber 605
20 packj 572
21 Python-Rootkit 531
22 MalConfScan 460
23 misp-galaxy 448
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives