Malware Families page 10 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Cobian RAT ratbackdoor
Cobian RAT is a backdoor, remote access tool that has been observed since 2016.
Cobra Carbon System rat
Also known as Carbon. Cobra Carbon System, also known as Carbon, is an advanced persistent threat (APT) tool used primarily in cyber-espionage operations.
CobraLocker ransomware
CobraLocker is a type of ransomware known for encrypting victims' data and demanding a ransom for decryption.
CockBlocker
CockBlocker is a malware with currently limited publicly available information.
CockBlocker Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Code Virus Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
CodeCore ransomware
CodeCore is a ransomware family known for encrypting files and demanding payment for decryption.
CodeKey trojanbackdoor
CodeKey is a sophisticated malware family known to facilitate unauthorized remote access to compromised systems.
Codemanager ransomware
A ransomware variant named Codemanager, known for encrypting sensitive data and demanding payment for decryption keys.
CoderCrypt ransomware
CoderCrypt is a ransomware family that encrypts victims' files and demands a ransom for decryption.
CoffeeLoader downloaderloader
Zscaler ThreatLabz states that this sophisticated malware family likely originated around September 2024.
Cohhoc rat
Cohhoc is a remote access Trojan (RAT) primarily used for cyber espionage purposes.
Coin Locker ransomware
Coin Locker is a type of ransomware that encrypts the victim's files and demands a cryptocurrency payment for the decryption key.
CoinThief trojancredential-stealerbackdoor
CoinThief was a malware package designed to steal Bitcoins from the victim, consisting of a binary patcher, browser extensions, and a…
CoinTicker backdoortrojan
CoinTicker is a malicious application that poses as a cryptocurrency price ticker and installs components of the open source backdoors…
CoinVault ransomware
Ransomware CryptoGraphic Locker family. Has a GUI. Do not confuse with CrypVault!
Coinminer cryptominer
Coinminer is an unwanted malicious software which uses the victim's computational power (CPU and RAM mostly) to mine for coins (for…
Cold$eal cryptominer
Also known as ColdSeal. Cold$eal is a packer for encrypting (sealing) malware.
ColdLock ransomware
ColdLock is a ransomware family known for targeting financial services and governmental organizations primarily in Taiwan and Hong Kong.
ColdStealer credential-stealer
ColdStealer is a relatively new malicious program that was discovered in 2022.
Coldroot rat
Coldroot, a remote access trojan (RAT), is still undetectable by most antivirus engines, despite being uploaded and freely available on…
Coldroot RAT ratkeylogger
Coldroot RAT is a multi-platform remote access trojan that primarily targets macOS systems.
Colibri Loader loader
According to cloudsek, Colibri Loader is a form of malware designed to facilitate the installation of additional malware types on an…
Collection RAT rat
Collection RAT is a cyber espionage tool used for remote access and data exfiltration, primarily targeting government and technology…
CollectorGoomba credential-stealer
Also known as Collector Stealer. CollectorGoomba, also known as Collector Stealer, is an information-stealing malware primarily focused on harvesting credentials from…
Colony ratspyware
Also known as Bandios, GrayBird. Colony, also known as Bandios or GrayBird, is a Remote Access Trojan (RAT) and spyware used to gain unauthorized access to computers.
ComLook backdoor
ComLook is a malicious plugin for the mail client "The Bat!", written in C++ and compiled with MSVC 10.0.
ComRAT rat
ComRAT is a second stage implant suspected of being a descendant of Agent.btz and used by Turla.
Combojack credential-stealer
Combojack is a malware family focused on stealing cryptocurrency by monitoring clipboard activity and replacing wallet addresses with…
Combos
Combos is a name associated with malicious software, but no detailed information is currently available about its capabilities, targets…
ComeBacker downloaderbackdoor
ComeBacker was found in a backdoored Visual Studio project that was used to target security researchers in Q4 2020 and early 2021.
CometBot botnetddos
CometBot is a versatile botnet malware that has been known to leverage compromised devices for launching distributed denial-of-service…
Comfoo rat
Comfoo is a remote access trojan (RAT) used in cyber-espionage campaigns, primarily targeting the government and public sector.
CommonMagic backdoorspyware
CommonMagic is a cyber espionage malware used to target government entities.
CommonRansom ransomware
A new ransomware called CommonRansom was discovered that has a very bizarre request.
Comnie backdoor
Comnie is a remote backdoor which has been used in attacks in East Asia.
Comodo Unite
Comodo Unite is another free remote access program that creates a secure VPN between multiple computers.
ComodoSec
ComodoSec is a malware entry with no publicly available detailed description.
Computrace spywarerootkit
Also known as lojack. Computrace, also known as LoJack, is a persistence-oriented spyware that is pre-installed on many commercial laptops and desktops.
Comrade Circle Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Comrade HT ransomware
Comrade HT is a type of ransomware used to encrypt data on infected systems, demanding a ransom for decryption.
ComradeCircle spywarerat
ComradeCircle is a sophisticated malware family primarily used in cyber-espionage campaigns against government and defense sectors.
Concipit1248 spyware
Also known as Corona Updates. Concipit1248 is iOS spyware that was discovered using the same name as the developer of the Android spyware Corona Updates.
Conficker
Also known as Downadup, Kido. Conficker is a computer worm that targets Microsoft Windows and was first detected in November 2008.
Conficker wormbotnet
Also known as Kido, Downadup, downadup. Conficker is a computer worm first detected in October 2008 that targeted Microsoft Windows using the MS08-067 Windows vulnerability to…
Confucius spyware
Confucius is a cyber espionage group primarily targeting South Asian countries.
ConnectBack backdoorrat
Also known as Getshell. ConnectBack malware is a type of malicious software designed to establish unauthorized connections from an infected system to a remote…
ConnectWise rat
Also known as ScreenConnect. ConnectWise is a legitimate remote administration tool that has been used since at least 2016 by threat actors including MuddyWater and…
Connic trojan
Also known as SpyBanker. Connic, also known as SpyBanker, is a banking Trojan that primarily targets financial institutions.
Consciousness ransomware
Consciousness is a ransomware that encrypts files on the victim's system, demanding a ransom for decryption keys.
ConsoleApplication1 Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
ContagiousDrop dropperdownloader
According to SentinelOne, these applications, typically implemented in app.js files, are deployed on ClickFix malware distribution servers.
Conti ransomware
Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019.
Conti (ELF) ransomware
Also known as Conti Locker. Conti is a sophisticated ransomware family that encrypts a victim's data and demands ransom for decryption.
Conti (Windows) ransomware
Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems.
Contopee backdoorrat
Also known as WHITEOUT. FireEye described this malware as a proxy-aware backdoor that communicates using a custom-encrypted binary protocol.
Convuster trojancredential-stealer
Convuster is a sophisticated trojan primarily targeting financial services and government sectors.
CookieBag credential-stealer
CookieBag is a credential-stealing malware family that targets financial and government sectors, primarily aiming to collect sensitive…
CookieMiner cryptominercredential-stealer
CookieMiner is mac-based malware that targets information associated with cryptocurrency exchanges as well as enabling cryptocurrency…
Coom ransomware
Coom is a type of ransomware that encrypts files on the infected system and demands a ransom for the decryption key.
Cooming ransomware
Cooming is a ransomware family previously using the clearnet domain coomingproject.com.
Coper trojanrat
Also known as ExobotCompact, Octo. Coper is an Android banking trojan and RAT descended from ExobotCompact, itself a rewrite of Exobot.
CopperStealer credential-stealerdownloader
Also known as Mingloa. According to PCRIsk, CopperStealer, also known as Mingloa, is a malicious program designed to steal sensitive/personal information.
CopperStealth rootkitdownloaderdropper
According to Trend Micro, CopperStealth’s infection chain involves dropping and loading a rootkit, which later injects its payload into…
Copybara ransomwaretrojan
Copybara is a ransomware and trojan malware family known for targeting financial services and government sectors to exfiltrate sensitive…
CorKLOG keylogger
CorKLOG is a keylogger known to be leveraged by Mustang Panda and was first observed utilized in 2024.
CoreDN backdoor
CoreDN is a persistent malware known for its ability to establish backdoor access on compromised systems.
Corebot trojancredential-stealerbotnet
Corebot is a trojan malware family known for stealing credentials.
Corona Updates spyware
Also known as Wabi Music, Concipit1248. Corona Updates is Android spyware that took advantage of the Coronavirus pandemic.
CoronaVirus ransomwaretrojanwiper
A new ransomware called CoronaVirus has been distributed through a fake web site pretending to promote the system optimization software…
CoronaVirus Ransomware ransomware
Also known as CoronaVirus Cover-Ransomware. CoronaVirus Ransomware is a type of malicious software designed to encrypt files on an infected system and demand a ransom for the…
Coronavirus Android Worm worm
Poses as an app that can offer a "corona safety mask" but phone's address book and sends sms to contacts, spreading its own download link.
CorruptCrypt ransomware
CorruptCrypt is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption.
Coruna exploit-kit
According to Google, this is a new and powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September…
CosmicDuke credential-stealerspywarebackdoor
Also known as TinyBaron, BotgenStudios, NemesisGemina. CosmicDuke is malware that was used by APT29 from 2010 to 2015.
CostaBricks loader
CostaBricks is a loader that was used to deploy 32-bit backdoors in the CostaRicto campaign.
Cotx RAT rat
Cotx RAT is a remote access tool used for cyber-espionage activities, primarily targeting financial services and government sectors.
CountLoader downloaderloader
According to Silent Push, this malware exists in multiple versions, including .NET, PowerShell, and JScript.
Cova botnettrojan
Cova is a type of banking trojan that targets financial institutions and public sector organizations primarily in English-speaking…
Covenant rat
Covenant is a multi-platform command and control framework written in .NET.
Coverton ransomware
Coverton is a ransomware malware known for encrypting files on compromised systems and demanding a ransom for decryption.
Covicli backdoor
Also known as Covically. Covicli is a modified SSLeay32 dynamic library designated as a backdoor.
Covid22 wipervirus
Destructive "joke" malware that ultimately deploys a wiper for the MBR.
CovidLock ransomware
Mobile ransomware. The Zscaler ThreatLabZ team recently came across a URL named hxxp://coronavirusapp[.]site/mobile.html, which portrays…
CozyCar backdoorrat
Also known as CozyDuke, CozyBear, Cozer. CozyCar is malware that was used by APT29 from 2010 to 2015.
CpuMeaner cryptominer
CpuMeaner is a cryptomining malware that exploits infected systems to mine cryptocurrency, utilizing excessive CPU resources.
Cpuminer (Android) cryptominer
Cpuminer is a type of malware targeting Android devices to exploit their computational power for mining cryptocurrency.
Cpuminer (ELF) cryptominer
This was observed to be pushed by IoT malware, abusing devices for LiteCoin and BitCoin mining.
Cr1ptT0r ransomware
Also known as Criptt0r, Cr1pt0r, Cripttor. Cr1ptT0r Ransomware Targets NAS Devices with Old Firmware.
CrackMapExec credential-stealer
CrackMapExec, or CME, is a post-exploitation tool developed in Python and designed for penetration testing against networks.
CrackedCantil dropperloadercryptominer
According to ANY.RUN, this is a dropper for win.privateloader and its execution will lead to a cascade of downloads with a large variety…
CradleCore rat
CradleCore is a remote access trojan (RAT) that provides attackers with control over compromised systems, potentially targeting critical…
Craftul ransomware
Craftul is a ransomware family that encrypts files on infected systems, demanding payment for decryption keys.
CraxsRAT rat
CraxsRAT is a remote access trojan (RAT) that allows attackers to remotely control infected systems.
CrazyHunter ratspyware
CrazyHunter is a sophisticated remote access trojan used in cyber-espionage campaigns.
Creal Stealer credential-stealer
Creal is an open-source grabber/credential stealer that was originally made by a GitHub user named Ayhuuu, who even advertised a "premium"…
CreamPie Ransomware ransomware
Jakub Kroustek found what appears to be an in-dev version of the CreamPie Ransomware.
CreateHiddenAccount trojan
A tool that implements the creation of a hidden account on Windows through cloning accounts via the Registry.
CreativeUpdater backdoortrojan
CreativeUpdater is a sophisticated malware known for its capability to deliver backdoors and facilitate cyber-espionage activities.
CredoMap credential-stealer
CredoMap is a credential-stealing malware used in targeted attacks primarily against Ukrainian government entities.