Malware
Ymir
According to Kaspersky, this malware sticks out as performing a large set of operations in memory with the help of the malloc, memmove and memcmp function calls.
Ymir is a Windows malware family.
Background
Kaspersky notes that what distinguishes this malware is its heavy reliance on in-memory operations, carried out through extensive use of the malloc, memmove and memcmp function calls.
Source: Malpedia (Fraunhofer FKIE).