Malware Families page 1 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

"prepending (enc) ransomware" (Not an official name) ransomware
Also known as Aperfectday2018. Prepending (enc) ransomware, also known as Aperfectday2018, is a type of malware that encrypts victim files and demands a ransom for the…
$$$ ransomware
The $$$ ransomware encrypts files on infected systems and demands payment in cryptocurrency.
$ucyLocker ransomware
SucyLocker is a type of ransomware known for encrypting files on compromised systems and demanding a ransom for decryption.
.CryptoHasYou. ransomware
The .CryptoHasYou. ransomware is a malicious software designed to encrypt files on targeted systems, demanding a ransom for decryption. It…
000Stealer credential-stealer
000Stealer is a credential-stealing malware primarily targeting financial and retail sectors.
05250lock ransomware
05250lock is a ransomware that encrypts victims' data and demands a ransom payment for decryption keys.
0Mega ransomware
0mega, a new ransomware operation, has been observed targeting organizations around the world.
0apt
This group is newly observed and first observation suggest this is not a serious group, as most - if not all - of the claims cannot be…
0bj3ctivityStealer credential-stealerkeyloggerspyware
Also known as PXRECVOWEIWOEI. Information stealer, based on strings it seems to target crypto currencies, instant messengers, and browser data.
0day
0kilobypt ransomware
0kilobypt is a ransomware strain designed to extort victims by encrypting files and demanding a ransom for recovery.
10001 ransomware
Ransomware identified as '10001'. This malware encrypts files on infected systems, typically demanding a ransom payment to decrypt and…
1337-Locker ransomware
1337-Locker is a ransomware variant that encrypts files on compromised systems, demanding a ransom for decryption.
16x
16x is a malware with limited available details.
2023lock ransomware
2023Lock is a ransomware strain first observed in January 2024, believed to be an evolution of the Venus and Zeoticus families and a…
20dfs ransomware
20dfs is a ransomware primarily targeting sectors such as financial services, healthcare, and technology.
24H ransomware
24H is a ransomware family known for its rapid encryption of files and demanding ransom payments within 24 hours.
32aa ransomware
32aa is a ransomware variant that encrypts files on the victim's system, demanding a ransom for decryption.
3CX Backdoor (OS X) backdoor
The 3CX Backdoor is a malicious software specifically targeting OS X systems.
3CX Backdoor (Windows) backdoor
Also known as SUDDENICON. According to CrowdStrike, this backdoor was discovered being embedded in a legitimate, signed version of 3CXDesktopApp, and thus…
3PARA RAT rat
3PARA RAT is a remote access tool (RAT) programmed in C++ that has been used by Putter Panda.
3am
3nCRY ransomware
3nCRY is a ransomware family known for encrypting files on infected systems and demanding a ransom payment in cryptocurrency for file…
404 Keylogger keyloggercredential-stealerscreen-capture
Also known as 404KeyLogger, Snake Keylogger. Snake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities.
4H RAT rat
4H RAT is malware that has been used by Putter Panda since at least 2007.
4h_rat rat
4h_rat is a remote access tool used for cyber espionage, primarily targeting government, financial, and technology sectors.
4rw5w ransomware
4rw5w is a type of ransomware that encrypts victims' files and demands a ransom payment for decryption.
5.t Downloader downloader
Downloader used in suspected APT attack against Vietnam.
5p00f3r.N$ RAT rat
5p00f3r.N$ RAT is a remote access trojan primarily used for cyber-espionage.
5ss5c Ransomware ransomware
The cybercrime group that brought us Satan, DBGer and Lucky ransomware and perhaps Iron ransomware, has now come up with a new version or…
5ss5c(5ss5cCrypt) ransomware
5ss5cCrypt, also known as 5ss5c, is a type of ransomware that encrypts files on infected machines and demands payment in exchange for…
68-Random-HEX ransomware
68-Random-HEX is a form of ransomware known for encrypting files on infected systems and demanding ransom payments for decryption keys.
777 ransomware
Also known as Sevleg. 777, also known as Sevleg, is a ransomware family that targets critical sectors such as financial, healthcare, and technology by…
777(Legion) ransomware
777(Legion) is a ransomware family known for encrypting victims' data and demanding a ransom for recovery.
7Zipper Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
7ev3n ransomware
Also known as 7ev3n-HONE$T. 7ev3n is a ransomware known for encrypting files and demanding a ransom for decryption.
7h9r ransomware
7h9r is a ransomware variant known for encrypting victims' files and demanding a ransom payment for decryption keys.
7z Portuguese ransomware
7z Portuguese is a type of ransomware that encrypts files on infected systems, demanding a ransom for decryption.
8.t Dropper dropper
Also known as 8t_dropper, RoyalRoad. 8T_Dropper has been used by Chinese threat actor TA428 in order to install Cotx RAT onto victim's machines during Operation LagTime IT.
888 RAT ratspywarecredential-stealer
According to ESET, this is a commercial, multiplatform RAT, originally developed for Windows and extended to Android.
8base ransomware
8Base emerged in early 2022 and rapidly escalated its ransomware operations by mid-2023, positioning itself as a “simple pen tester” while…
8lock8 ransomware
8lock8 is a ransomware that encrypts files on a victim's machine.
9002 rat
The 9002 malware is a remote access trojan (RAT) primarily associated with cyber espionage activities.
A32s RAT rat
A32s RAT is a remote access tool that enables attackers to gain control over infected systems.
A4Zeta ransomware
A4Zeta is a ransomware family known for targeting government and financial services sectors.
AAC ransomware
AAC is a type of ransomware that encrypts victims' files and demands a ransom payment for decryption.
AADInternals exploit-kit
AADInternals is a PowerShell-based framework for administering, enumerating, and exploiting Azure Active Directory.
ABCLocker ransomware
ABCLocker is a ransomware targeting multiple industries by encrypting files and demanding a ransom for decryption keys.
ABCsync backdoor
ABCsync is a backdoor malware that targets technology and telecommunications sectors.
ABK downloader
ABK is a downloader that has been used by BRONZE BUTLER since at least 2019.
ACAD/Medre.A wormspyware
ACAD/Medre.A is a worm that steals operational information.
ACBackdoor (ELF) backdoor
A Linux backdoor that was apparently ported to Windows.
ACBackdoor (Windows) backdoor
A Linux backdoor that was apparently ported to Windows.
ACEHASH credential-stealerloader
ACEHASH is described by FireEye as combined credential harvester that consists of two components, a loader and encrypted/compressed payload.
ACR Stealer credential-stealerspyware
First introduced in March 2024, ACR Stealer is an information stealer sold as a Malware-as-a-Service (MaaS) on Russian-speaking cybercrime…
ADVSTORESHELL backdoorspyware
Also known as AZZY, EVILTOSS, NETUI. ADVSTORESHELL is a spying backdoor that has been used by APT28 from at least 2012 to 2016.
AES-Matrix ransomware
AES-Matrix is a ransomware known for encrypting data and demanding ransom payments in cryptocurrencies.
AES-NI Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
AES-NI: April Edition ransomware
AES-NI ransomware encrypts a victim's files and demands a ransom in cryptocurrency for decryption.
AESMew ransomware
AESMew is a type of ransomware that encrypts files on a victim's system and demands a ransom for decryption.
AESRT ransomware
AESRT is ransomware developed using .NET, known for encrypting user data and demanding ransom for decryption keys.
AES_KEY_GEN_ASSIST Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
AIRASHI ddos
AIRASHI is a DDoS bot known for its ability to participate in distributed denial-of-service attacks.
AIRBREAK backdoor
Also known as Orz. AIRBREAK, a JavaScript-based backdoor which retrieves commands from hidden strings in compromised webpages.
ALFA Ransomware ransomware
ALFA Ransomware is a type of malicious software developed by the creators of the Cerber ransomware.
ALPC Local PrivEsc exploit-kit
The ALPC Local PrivEsc is an exploit that leverages a vulnerability in the Advanced Local Procedure Call (ALPC) interface on Windows…
AMBA ransomware
AMBA is a ransomware strain that communicates with victims through email, specifically using [email protected] for ransom negotiations.
AMOS credential-stealer
Also known as Atomic macOS Stealer. AMOS, also known as Atomic macOS Stealer, is a malware targeting macOS systems to steal sensitive data such as credentials and…
AMTsol trojanbackdoor
Also known as Adupihan. AMTsol, also known as Adupihan, is a trojan and backdoor malware used in cyber espionage campaigns.
ANDROIDOS_ANSERVER.A trojan
ANDROIDOS_ANSERVER.A is Android malware that is unique because it uses encrypted content within a blog site for command and control.
ANDROMEDA botnetloadertrojan
Also known as B106-Gamarue, B67-SS-Gamarue, Gamarue. ANDROMEDA is commodity malware that was widespread in the early 2010's and continues to be observed in infections across a wide variety of…
ANDROSNATCH credential-stealer
ANDROSNATCH is a malware identified by Google as a Chrome cookie stealer, posing a threat to online privacy by exfiltrating browser cookies.
ANELLDR loader
ANELLDR, a loader that has been in use since at least 2018, was designed to decrypt and execute UPPERCUT in memory.
ANGRYREBEL rat
Also known as Ghost RAT. ANGRYREBEL, also known as Ghost RAT, is a remote access trojan primarily utilized in cyber espionage campaigns against government…
ANTAK webshell
Antak is a webshell written in ASP.Net which utilizes PowerShell.
APERETIF backdoor
APERETIF is a sophisticated backdoor malware primarily used in cyber-espionage operations targeting government and financial sectors.
APT Ransomware v.2 ransomware
This is most likely to affect English speaking users, since the note is written in English.
APT3 Keylogger keyloggercredential-stealer
APT3 Keylogger is a malicious tool reportedly linked to the Chinese APT group known for cyber espionage.
ARS VBS Loader ratloader
ARS Loader, also known as ARS VBS Loader, is written in Visual Basic Script and its main purpose is to control an infected machine via…
ARTFULPIE downloadertrojan
ARTFULPIE is a downloader trojan that has been observed targeting government and defense sectors, particularly in the United States and…
ASN1 Encoder Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
ASPC
ASPC is a piece of malware for which detailed information is currently unavailable.
ASPXSpy webshell
Also known as ASPXTool. ASPXSpy is a Web shell. It has been modified by Threat Group-3390 actors to create the ASPXTool version.
ATANK ransomwarewiper
According to Lukas Stefanko, this is an open-source crypto-ransomware found on Github in 2018.
ATI-Agent ratspyware
ATI-Agent is a remote access trojan primarily targeting government and technology sectors.
ATLAS ransomware
ATLAS is a type of ransomware that encrypts the victim's data and demands a ransom for decryption.
ATMSpitter trojan
The ATMSpitter family consists of command-line tools designed to control the cash dispenser of an ATM through function calls to either…
ATMii backdoor
ATMii is a malware that targets ATMs to deploy unauthorized cash withdrawals by injecting a backdoor.
ATMitch backdoor
ATMitch is a type of malware specifically targeting ATMs.
AVCrypt ransomwarewiper
AVCrypt is a form of ransomware that not only encrypts files but also attempts to disable the victim’s security software.
AVrecon ratdownloader
AVrecon is a Linux-based Remote Access Trojan (RAT) targeting small-office/home-office (SOHO) routers and other ARM-embedded devices.
AXLocker ransomware
AXLocker is a ransomware strain that encrypts files on compromised systems, demanding a ransom for decryption.
AbSent Loader loader
AbSent Loader is a type of malware designed to load additional malicious payloads onto compromised systems.
Abaddon ransomwarerat
Abaddon is a multi-functional malware that utilizes Discord as its command and control (C&C) server.
AbaddonPOS credential-stealer
Also known as PinkKite, TinyPOS. MajorGeeks describes this malware as trying to locate credit card data by reading the memory of all processes except itself by first…
Abbath Banker trojancredential-stealer
Abbath Banker is a known malware family targeting banking institutions, primarily in Brazil.
Abcbot botnetddos
Abcbot is a modular Go-based botnet and malware that propagates via exploits and brute force attempts.
Aberebot trojancredential-stealer
Also known as Escobar. Aberebot, also known as Escobar, is an Android banking trojan that targets financial services in certain regions.
Abraham's Ax wiper
Also known as Abrahams_Ax. Abraham's Ax announced their existence and mission through social media channels such as Twitter posts on November 8, 2022.
AbstractEmu rootkittrojan
AbstractEmu is mobile malware that was first seen in Google Play and other third-party stores in October 2021.