Malware Families page 10 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Cobian RAT ratbackdoor
- Cobian RAT is a backdoor, remote access tool that has been observed since 2016.
- Cobra Carbon System rat
- Also known as Carbon. Cobra Carbon System, also known as Carbon, is an advanced persistent threat (APT) tool used primarily in cyber-espionage operations.
- CobraLocker ransomware
- CobraLocker is a type of ransomware known for encrypting victims' data and demanding a ransom for decryption.
- CockBlocker
- CockBlocker is a malware with currently limited publicly available information.
- CockBlocker Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Code Virus Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- CodeCore ransomware
- CodeCore is a ransomware family known for encrypting files and demanding payment for decryption.
- CodeKey trojanbackdoor
- CodeKey is a sophisticated malware family known to facilitate unauthorized remote access to compromised systems.
- Codemanager ransomware
- A ransomware variant named Codemanager, known for encrypting sensitive data and demanding payment for decryption keys.
- CoderCrypt ransomware
- CoderCrypt is a ransomware family that encrypts victims' files and demands a ransom for decryption.
- CoffeeLoader downloaderloader
- Zscaler ThreatLabz states that this sophisticated malware family likely originated around September 2024.
- Cohhoc rat
- Cohhoc is a remote access Trojan (RAT) primarily used for cyber espionage purposes.
- Coin Locker ransomware
- Coin Locker is a type of ransomware that encrypts the victim's files and demands a cryptocurrency payment for the decryption key.
- CoinThief trojancredential-stealerbackdoor
- CoinThief was a malware package designed to steal Bitcoins from the victim, consisting of a binary patcher, browser extensions, and a…
- CoinTicker backdoortrojan
- CoinTicker is a malicious application that poses as a cryptocurrency price ticker and installs components of the open source backdoors…
- CoinVault ransomware
- Ransomware CryptoGraphic Locker family. Has a GUI. Do not confuse with CrypVault!
- Coinminer cryptominer
- Coinminer is an unwanted malicious software which uses the victim's computational power (CPU and RAM mostly) to mine for coins (for…
- Cold$eal cryptominer
- Also known as ColdSeal. Cold$eal is a packer for encrypting (sealing) malware.
- ColdLock ransomware
- ColdLock is a ransomware family known for targeting financial services and governmental organizations primarily in Taiwan and Hong Kong.
- ColdStealer credential-stealer
- ColdStealer is a relatively new malicious program that was discovered in 2022.
- Coldroot rat
- Coldroot, a remote access trojan (RAT), is still undetectable by most antivirus engines, despite being uploaded and freely available on…
- Coldroot RAT ratkeylogger
- Coldroot RAT is a multi-platform remote access trojan that primarily targets macOS systems.
- Colibri Loader loader
- According to cloudsek, Colibri Loader is a form of malware designed to facilitate the installation of additional malware types on an…
- Collection RAT rat
- Collection RAT is a cyber espionage tool used for remote access and data exfiltration, primarily targeting government and technology…
- CollectorGoomba credential-stealer
- Also known as Collector Stealer. CollectorGoomba, also known as Collector Stealer, is an information-stealing malware primarily focused on harvesting credentials from…
- Colony ratspyware
- Also known as Bandios, GrayBird. Colony, also known as Bandios or GrayBird, is a Remote Access Trojan (RAT) and spyware used to gain unauthorized access to computers.
- ComLook backdoor
- ComLook is a malicious plugin for the mail client "The Bat!", written in C++ and compiled with MSVC 10.0.
- ComRAT rat
- ComRAT is a second stage implant suspected of being a descendant of Agent.btz and used by Turla.
- Combojack credential-stealer
- Combojack is a malware family focused on stealing cryptocurrency by monitoring clipboard activity and replacing wallet addresses with…
- Combos
- Combos is a name associated with malicious software, but no detailed information is currently available about its capabilities, targets…
- ComeBacker downloaderbackdoor
- ComeBacker was found in a backdoored Visual Studio project that was used to target security researchers in Q4 2020 and early 2021.
- CometBot botnetddos
- CometBot is a versatile botnet malware that has been known to leverage compromised devices for launching distributed denial-of-service…
- Comfoo rat
- Comfoo is a remote access trojan (RAT) used in cyber-espionage campaigns, primarily targeting the government and public sector.
- CommonMagic backdoorspyware
- CommonMagic is a cyber espionage malware used to target government entities.
- CommonRansom ransomware
- A new ransomware called CommonRansom was discovered that has a very bizarre request.
- Comnie backdoor
- Comnie is a remote backdoor which has been used in attacks in East Asia.
- Comodo Unite
- Comodo Unite is another free remote access program that creates a secure VPN between multiple computers.
- ComodoSec
- ComodoSec is a malware entry with no publicly available detailed description.
- Computrace spywarerootkit
- Also known as lojack. Computrace, also known as LoJack, is a persistence-oriented spyware that is pre-installed on many commercial laptops and desktops.
- Comrade Circle Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Comrade HT ransomware
- Comrade HT is a type of ransomware used to encrypt data on infected systems, demanding a ransom for decryption.
- ComradeCircle spywarerat
- ComradeCircle is a sophisticated malware family primarily used in cyber-espionage campaigns against government and defense sectors.
- Concipit1248 spyware
- Also known as Corona Updates. Concipit1248 is iOS spyware that was discovered using the same name as the developer of the Android spyware Corona Updates.
- Conficker
- Also known as Downadup, Kido. Conficker is a computer worm that targets Microsoft Windows and was first detected in November 2008.
- Conficker wormbotnet
- Also known as Kido, Downadup, downadup. Conficker is a computer worm first detected in October 2008 that targeted Microsoft Windows using the MS08-067 Windows vulnerability to…
- Confucius spyware
- Confucius is a cyber espionage group primarily targeting South Asian countries.
- ConnectBack backdoorrat
- Also known as Getshell. ConnectBack malware is a type of malicious software designed to establish unauthorized connections from an infected system to a remote…
- ConnectWise rat
- Also known as ScreenConnect. ConnectWise is a legitimate remote administration tool that has been used since at least 2016 by threat actors including MuddyWater and…
- Connic trojan
- Also known as SpyBanker. Connic, also known as SpyBanker, is a banking Trojan that primarily targets financial institutions.
- Consciousness ransomware
- Consciousness is a ransomware that encrypts files on the victim's system, demanding a ransom for decryption keys.
- ConsoleApplication1 Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- ContagiousDrop dropperdownloader
- According to SentinelOne, these applications, typically implemented in app.js files, are deployed on ClickFix malware distribution servers.
- Conti ransomware
- Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019.
- Conti (ELF) ransomware
- Also known as Conti Locker. Conti is a sophisticated ransomware family that encrypts a victim's data and demands ransom for decryption.
- Conti (Windows) ransomware
- Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems.
- Contopee backdoorrat
- Also known as WHITEOUT. FireEye described this malware as a proxy-aware backdoor that communicates using a custom-encrypted binary protocol.
- Convuster trojancredential-stealer
- Convuster is a sophisticated trojan primarily targeting financial services and government sectors.
- CookieBag credential-stealer
- CookieBag is a credential-stealing malware family that targets financial and government sectors, primarily aiming to collect sensitive…
- CookieMiner cryptominercredential-stealer
- CookieMiner is mac-based malware that targets information associated with cryptocurrency exchanges as well as enabling cryptocurrency…
- Coom ransomware
- Coom is a type of ransomware that encrypts files on the infected system and demands a ransom for the decryption key.
- Cooming ransomware
- Cooming is a ransomware family previously using the clearnet domain coomingproject.com.
- Coper trojanrat
- Also known as ExobotCompact, Octo. Coper is an Android banking trojan and RAT descended from ExobotCompact, itself a rewrite of Exobot.
- CopperStealer credential-stealerdownloader
- Also known as Mingloa. According to PCRIsk, CopperStealer, also known as Mingloa, is a malicious program designed to steal sensitive/personal information.
- CopperStealth rootkitdownloaderdropper
- According to Trend Micro, CopperStealth’s infection chain involves dropping and loading a rootkit, which later injects its payload into…
- Copybara ransomwaretrojan
- Copybara is a ransomware and trojan malware family known for targeting financial services and government sectors to exfiltrate sensitive…
- CorKLOG keylogger
- CorKLOG is a keylogger known to be leveraged by Mustang Panda and was first observed utilized in 2024.
- CoreDN backdoor
- CoreDN is a persistent malware known for its ability to establish backdoor access on compromised systems.
- Corebot trojancredential-stealerbotnet
- Corebot is a trojan malware family known for stealing credentials.
- Corona Updates spyware
- Also known as Wabi Music, Concipit1248. Corona Updates is Android spyware that took advantage of the Coronavirus pandemic.
- CoronaVirus ransomwaretrojanwiper
- A new ransomware called CoronaVirus has been distributed through a fake web site pretending to promote the system optimization software…
- CoronaVirus Ransomware ransomware
- Also known as CoronaVirus Cover-Ransomware. CoronaVirus Ransomware is a type of malicious software designed to encrypt files on an infected system and demand a ransom for the…
- Coronavirus Android Worm worm
- Poses as an app that can offer a "corona safety mask" but phone's address book and sends sms to contacts, spreading its own download link.
- CorruptCrypt ransomware
- CorruptCrypt is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption.
- Coruna exploit-kit
- According to Google, this is a new and powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September…
- CosmicDuke credential-stealerspywarebackdoor
- Also known as TinyBaron, BotgenStudios, NemesisGemina. CosmicDuke is malware that was used by APT29 from 2010 to 2015.
- CostaBricks loader
- CostaBricks is a loader that was used to deploy 32-bit backdoors in the CostaRicto campaign.
- Cotx RAT rat
- Cotx RAT is a remote access tool used for cyber-espionage activities, primarily targeting financial services and government sectors.
- CountLoader downloaderloader
- According to Silent Push, this malware exists in multiple versions, including .NET, PowerShell, and JScript.
- Cova botnettrojan
- Cova is a type of banking trojan that targets financial institutions and public sector organizations primarily in English-speaking…
- Covenant rat
- Covenant is a multi-platform command and control framework written in .NET.
- Coverton ransomware
- Coverton is a ransomware malware known for encrypting files on compromised systems and demanding a ransom for decryption.
- Covicli backdoor
- Also known as Covically. Covicli is a modified SSLeay32 dynamic library designated as a backdoor.
- Covid22 wipervirus
- Destructive "joke" malware that ultimately deploys a wiper for the MBR.
- CovidLock ransomware
- Mobile ransomware. The Zscaler ThreatLabZ team recently came across a URL named hxxp://coronavirusapp[.]site/mobile.html, which portrays…
- CozyCar backdoorrat
- Also known as CozyDuke, CozyBear, Cozer. CozyCar is malware that was used by APT29 from 2010 to 2015.
- CpuMeaner cryptominer
- CpuMeaner is a cryptomining malware that exploits infected systems to mine cryptocurrency, utilizing excessive CPU resources.
- Cpuminer (Android) cryptominer
- Cpuminer is a type of malware targeting Android devices to exploit their computational power for mining cryptocurrency.
- Cpuminer (ELF) cryptominer
- This was observed to be pushed by IoT malware, abusing devices for LiteCoin and BitCoin mining.
- Cr1ptT0r ransomware
- Also known as Criptt0r, Cr1pt0r, Cripttor. Cr1ptT0r Ransomware Targets NAS Devices with Old Firmware.
- CrackMapExec credential-stealer
- CrackMapExec, or CME, is a post-exploitation tool developed in Python and designed for penetration testing against networks.
- CrackedCantil dropperloadercryptominer
- According to ANY.RUN, this is a dropper for win.privateloader and its execution will lead to a cascade of downloads with a large variety…
- CradleCore rat
- CradleCore is a remote access trojan (RAT) that provides attackers with control over compromised systems, potentially targeting critical…
- Craftul ransomware
- Craftul is a ransomware family that encrypts files on infected systems, demanding payment for decryption keys.
- CraxsRAT rat
- CraxsRAT is a remote access trojan (RAT) that allows attackers to remotely control infected systems.
- CrazyHunter ratspyware
- CrazyHunter is a sophisticated remote access trojan used in cyber-espionage campaigns.
- Creal Stealer credential-stealer
- Creal is an open-source grabber/credential stealer that was originally made by a GitHub user named Ayhuuu, who even advertised a "premium"…
- CreamPie Ransomware ransomware
- Jakub Kroustek found what appears to be an in-dev version of the CreamPie Ransomware.
- CreateHiddenAccount trojan
- A tool that implements the creation of a hidden account on Windows through cloning accounts via the Registry.
- CreativeUpdater backdoortrojan
- CreativeUpdater is a sophisticated malware known for its capability to deliver backdoors and facilitate cyber-espionage activities.
- CredoMap credential-stealer
- CredoMap is a credential-stealing malware used in targeted attacks primarily against Ukrainian government entities.