Malware Families page 1 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- "prepending (enc) ransomware" (Not an official name) ransomware
- Also known as Aperfectday2018. Prepending (enc) ransomware, also known as Aperfectday2018, is a type of malware that encrypts victim files and demands a ransom for the…
- $$$ ransomware
- The $$$ ransomware encrypts files on infected systems and demands payment in cryptocurrency.
- $ucyLocker ransomware
- SucyLocker is a type of ransomware known for encrypting files on compromised systems and demanding a ransom for decryption.
- .CryptoHasYou. ransomware
- The .CryptoHasYou. ransomware is a malicious software designed to encrypt files on targeted systems, demanding a ransom for decryption. It…
- 000Stealer credential-stealer
- 000Stealer is a credential-stealing malware primarily targeting financial and retail sectors.
- 05250lock ransomware
- 05250lock is a ransomware that encrypts victims' data and demands a ransom payment for decryption keys.
- 0Mega ransomware
- 0mega, a new ransomware operation, has been observed targeting organizations around the world.
- 0apt
- This group is newly observed and first observation suggest this is not a serious group, as most - if not all - of the claims cannot be…
- 0bj3ctivityStealer credential-stealerkeyloggerspyware
- Also known as PXRECVOWEIWOEI. Information stealer, based on strings it seems to target crypto currencies, instant messengers, and browser data.
- 0day
- 0kilobypt ransomware
- 0kilobypt is a ransomware strain designed to extort victims by encrypting files and demanding a ransom for recovery.
- 10001 ransomware
- Ransomware identified as '10001'. This malware encrypts files on infected systems, typically demanding a ransom payment to decrypt and…
- 1337-Locker ransomware
- 1337-Locker is a ransomware variant that encrypts files on compromised systems, demanding a ransom for decryption.
- 16x
- 16x is a malware with limited available details.
- 2023lock ransomware
- 2023Lock is a ransomware strain first observed in January 2024, believed to be an evolution of the Venus and Zeoticus families and a…
- 20dfs ransomware
- 20dfs is a ransomware primarily targeting sectors such as financial services, healthcare, and technology.
- 24H ransomware
- 24H is a ransomware family known for its rapid encryption of files and demanding ransom payments within 24 hours.
- 32aa ransomware
- 32aa is a ransomware variant that encrypts files on the victim's system, demanding a ransom for decryption.
- 3CX Backdoor (OS X) backdoor
- The 3CX Backdoor is a malicious software specifically targeting OS X systems.
- 3CX Backdoor (Windows) backdoor
- Also known as SUDDENICON. According to CrowdStrike, this backdoor was discovered being embedded in a legitimate, signed version of 3CXDesktopApp, and thus…
- 3PARA RAT rat
- 3PARA RAT is a remote access tool (RAT) programmed in C++ that has been used by Putter Panda.
- 3am
- 3nCRY ransomware
- 3nCRY is a ransomware family known for encrypting files on infected systems and demanding a ransom payment in cryptocurrency for file…
- 404 Keylogger keyloggercredential-stealerscreen-capture
- Also known as 404KeyLogger, Snake Keylogger. Snake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities.
- 4H RAT rat
- 4H RAT is malware that has been used by Putter Panda since at least 2007.
- 4h_rat rat
- 4h_rat is a remote access tool used for cyber espionage, primarily targeting government, financial, and technology sectors.
- 4rw5w ransomware
- 4rw5w is a type of ransomware that encrypts victims' files and demands a ransom payment for decryption.
- 5.t Downloader downloader
- Downloader used in suspected APT attack against Vietnam.
- 5p00f3r.N$ RAT rat
- 5p00f3r.N$ RAT is a remote access trojan primarily used for cyber-espionage.
- 5ss5c Ransomware ransomware
- The cybercrime group that brought us Satan, DBGer and Lucky ransomware and perhaps Iron ransomware, has now come up with a new version or…
- 5ss5c(5ss5cCrypt) ransomware
- 5ss5cCrypt, also known as 5ss5c, is a type of ransomware that encrypts files on infected machines and demands payment in exchange for…
- 68-Random-HEX ransomware
- 68-Random-HEX is a form of ransomware known for encrypting files on infected systems and demanding ransom payments for decryption keys.
- 777 ransomware
- Also known as Sevleg. 777, also known as Sevleg, is a ransomware family that targets critical sectors such as financial, healthcare, and technology by…
- 777(Legion) ransomware
- 777(Legion) is a ransomware family known for encrypting victims' data and demanding a ransom for recovery.
- 7Zipper Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- 7ev3n ransomware
- Also known as 7ev3n-HONE$T. 7ev3n is a ransomware known for encrypting files and demanding a ransom for decryption.
- 7h9r ransomware
- 7h9r is a ransomware variant known for encrypting victims' files and demanding a ransom payment for decryption keys.
- 7z Portuguese ransomware
- 7z Portuguese is a type of ransomware that encrypts files on infected systems, demanding a ransom for decryption.
- 8.t Dropper dropper
- Also known as 8t_dropper, RoyalRoad. 8T_Dropper has been used by Chinese threat actor TA428 in order to install Cotx RAT onto victim's machines during Operation LagTime IT.
- 888 RAT ratspywarecredential-stealer
- According to ESET, this is a commercial, multiplatform RAT, originally developed for Windows and extended to Android.
- 8base ransomware
- 8Base emerged in early 2022 and rapidly escalated its ransomware operations by mid-2023, positioning itself as a “simple pen tester” while…
- 8lock8 ransomware
- 8lock8 is a ransomware that encrypts files on a victim's machine.
- 9002 rat
- The 9002 malware is a remote access trojan (RAT) primarily associated with cyber espionage activities.
- A32s RAT rat
- A32s RAT is a remote access tool that enables attackers to gain control over infected systems.
- A4Zeta ransomware
- A4Zeta is a ransomware family known for targeting government and financial services sectors.
- AAC ransomware
- AAC is a type of ransomware that encrypts victims' files and demands a ransom payment for decryption.
- AADInternals exploit-kit
- AADInternals is a PowerShell-based framework for administering, enumerating, and exploiting Azure Active Directory.
- ABCLocker ransomware
- ABCLocker is a ransomware targeting multiple industries by encrypting files and demanding a ransom for decryption keys.
- ABCsync backdoor
- ABCsync is a backdoor malware that targets technology and telecommunications sectors.
- ABK downloader
- ABK is a downloader that has been used by BRONZE BUTLER since at least 2019.
- ACAD/Medre.A wormspyware
- ACAD/Medre.A is a worm that steals operational information.
- ACBackdoor (ELF) backdoor
- A Linux backdoor that was apparently ported to Windows.
- ACBackdoor (Windows) backdoor
- A Linux backdoor that was apparently ported to Windows.
- ACEHASH credential-stealerloader
- ACEHASH is described by FireEye as combined credential harvester that consists of two components, a loader and encrypted/compressed payload.
- ACR Stealer credential-stealerspyware
- First introduced in March 2024, ACR Stealer is an information stealer sold as a Malware-as-a-Service (MaaS) on Russian-speaking cybercrime…
- ADVSTORESHELL backdoorspyware
- Also known as AZZY, EVILTOSS, NETUI. ADVSTORESHELL is a spying backdoor that has been used by APT28 from at least 2012 to 2016.
- AES-Matrix ransomware
- AES-Matrix is a ransomware known for encrypting data and demanding ransom payments in cryptocurrencies.
- AES-NI Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- AES-NI: April Edition ransomware
- AES-NI ransomware encrypts a victim's files and demands a ransom in cryptocurrency for decryption.
- AESMew ransomware
- AESMew is a type of ransomware that encrypts files on a victim's system and demands a ransom for decryption.
- AESRT ransomware
- AESRT is ransomware developed using .NET, known for encrypting user data and demanding ransom for decryption keys.
- AES_KEY_GEN_ASSIST Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- AIRASHI ddos
- AIRASHI is a DDoS bot known for its ability to participate in distributed denial-of-service attacks.
- AIRBREAK backdoor
- Also known as Orz. AIRBREAK, a JavaScript-based backdoor which retrieves commands from hidden strings in compromised webpages.
- ALFA Ransomware ransomware
- ALFA Ransomware is a type of malicious software developed by the creators of the Cerber ransomware.
- ALPC Local PrivEsc exploit-kit
- The ALPC Local PrivEsc is an exploit that leverages a vulnerability in the Advanced Local Procedure Call (ALPC) interface on Windows…
- AMBA ransomware
- AMBA is a ransomware strain that communicates with victims through email, specifically using [email protected] for ransom negotiations.
- AMOS credential-stealer
- Also known as Atomic macOS Stealer. AMOS, also known as Atomic macOS Stealer, is a malware targeting macOS systems to steal sensitive data such as credentials and…
- AMTsol trojanbackdoor
- Also known as Adupihan. AMTsol, also known as Adupihan, is a trojan and backdoor malware used in cyber espionage campaigns.
- ANDROIDOS_ANSERVER.A trojan
- ANDROIDOS_ANSERVER.A is Android malware that is unique because it uses encrypted content within a blog site for command and control.
- ANDROMEDA botnetloadertrojan
- Also known as B106-Gamarue, B67-SS-Gamarue, Gamarue. ANDROMEDA is commodity malware that was widespread in the early 2010's and continues to be observed in infections across a wide variety of…
- ANDROSNATCH credential-stealer
- ANDROSNATCH is a malware identified by Google as a Chrome cookie stealer, posing a threat to online privacy by exfiltrating browser cookies.
- ANELLDR loader
- ANELLDR, a loader that has been in use since at least 2018, was designed to decrypt and execute UPPERCUT in memory.
- ANGRYREBEL rat
- Also known as Ghost RAT. ANGRYREBEL, also known as Ghost RAT, is a remote access trojan primarily utilized in cyber espionage campaigns against government…
- ANTAK webshell
- Antak is a webshell written in ASP.Net which utilizes PowerShell.
- APERETIF backdoor
- APERETIF is a sophisticated backdoor malware primarily used in cyber-espionage operations targeting government and financial sectors.
- APT Ransomware v.2 ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- APT3 Keylogger keyloggercredential-stealer
- APT3 Keylogger is a malicious tool reportedly linked to the Chinese APT group known for cyber espionage.
- ARS VBS Loader ratloader
- ARS Loader, also known as ARS VBS Loader, is written in Visual Basic Script and its main purpose is to control an infected machine via…
- ARTFULPIE downloadertrojan
- ARTFULPIE is a downloader trojan that has been observed targeting government and defense sectors, particularly in the United States and…
- ASN1 Encoder Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- ASPC
- ASPC is a piece of malware for which detailed information is currently unavailable.
- ASPXSpy webshell
- Also known as ASPXTool. ASPXSpy is a Web shell. It has been modified by Threat Group-3390 actors to create the ASPXTool version.
- ATANK ransomwarewiper
- According to Lukas Stefanko, this is an open-source crypto-ransomware found on Github in 2018.
- ATI-Agent ratspyware
- ATI-Agent is a remote access trojan primarily targeting government and technology sectors.
- ATLAS ransomware
- ATLAS is a type of ransomware that encrypts the victim's data and demands a ransom for decryption.
- ATMSpitter trojan
- The ATMSpitter family consists of command-line tools designed to control the cash dispenser of an ATM through function calls to either…
- ATMii backdoor
- ATMii is a malware that targets ATMs to deploy unauthorized cash withdrawals by injecting a backdoor.
- ATMitch backdoor
- ATMitch is a type of malware specifically targeting ATMs.
- AVCrypt ransomwarewiper
- AVCrypt is a form of ransomware that not only encrypts files but also attempts to disable the victim’s security software.
- AVrecon ratdownloader
- AVrecon is a Linux-based Remote Access Trojan (RAT) targeting small-office/home-office (SOHO) routers and other ARM-embedded devices.
- AXLocker ransomware
- AXLocker is a ransomware strain that encrypts files on compromised systems, demanding a ransom for decryption.
- AbSent Loader loader
- AbSent Loader is a type of malware designed to load additional malicious payloads onto compromised systems.
- Abaddon ransomwarerat
- Abaddon is a multi-functional malware that utilizes Discord as its command and control (C&C) server.
- AbaddonPOS credential-stealer
- Also known as PinkKite, TinyPOS. MajorGeeks describes this malware as trying to locate credit card data by reading the memory of all processes except itself by first…
- Abbath Banker trojancredential-stealer
- Abbath Banker is a known malware family targeting banking institutions, primarily in Brazil.
- Abcbot botnetddos
- Abcbot is a modular Go-based botnet and malware that propagates via exploits and brute force attempts.
- Aberebot trojancredential-stealer
- Also known as Escobar. Aberebot, also known as Escobar, is an Android banking trojan that targets financial services in certain regions.
- Abraham's Ax wiper
- Also known as Abrahams_Ax. Abraham's Ax announced their existence and mission through social media channels such as Twitter posts on November 8, 2022.
- AbstractEmu rootkittrojan
- AbstractEmu is mobile malware that was first seen in Google Play and other third-party stores in October 2021.