Malware Families page 11 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Credraptor credential-stealer
Credraptor is a credential-stealing malware family that targets sensitive authentication information.
CreepExfil spywarebackdoor
CreepExfil is a piece of malware known for exfiltrating sensitive data from compromised systems.
Creeper ransomware
Creeper is considered the first known ransomware, designed to demonstrate the concept of self-replicating code.
Creepy ransomware
Creepy is a strain of ransomware known for encrypting data and demanding a ransom for decryption keys.
CreepyDrive backdoor
CreepyDrive is a custom implant has been used by POLONIUM since at least early 2022 for C2 with and exfiltration to actor-controlled…
CreepySnail rattrojan
CreepySnail is a custom PowerShell implant that has been used by POLONIUM since at least 2022.
Crenufs trojan
Crenufs is a sophisticated trojan primarily targeting financial and technology sectors.
Crimson rat
Also known as MSIL/Crimson. Crimson is a remote access Trojan that has been used by Transparent Tribe since at least 2016.
Crimson RAT ratspyware
Also known as SEEDOOR, Scarimson. It was first discovered in 2017 and has since been used to attack organizations around the world.
CrimsonIAS backdoor
According to ThreatConnect, CrimsonIAS is a Delphi-written backdoor dating back to at least 2017.
Cring ransomware
Cring is a ransomware strain known for targeting organizations in the manufacturing and energy sectors.
Cripton ransomware
Cripton is a ransomware family known for encrypting files on infected systems and demanding a ransom payment for decryption.
Cripton7zp ransomware
Cripton7zp is a ransomware known for encrypting files on victim systems, demanding payment for the decryption key.
Crisis trojanrootkit
Crisis is a versatile Trojan with rootkit capabilities, primarily targeting Windows and Mac OS X operating systems.
Crocodilus trojan
Crocodilus is an Android banking Trojan that was discovered in March 2025.
CronRAT rat
A malware written in Bash that hides in the Linux calendar system on February 31st.
CrossRAT rat
Also known as Trupto. CrossRAT is a cross-platform remote access tool (RAT) that affects Windows, OSX, and Linux systems.
Crossrider spyware
Crossrider is a type of adware and spyware known for injecting advertisements into web browsing sessions and altering browser settings.
Croxloader loader
According to Trend Micro, this is a custom loader for win.cobalt_strike, used by Earth Longzhi (a subgroup of APT41).
Crptxxx Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
CruLoader loader
CruLoader is a malware known for its capabilities to load additional malicious payloads and facilitate cyber attacks.
Crutch backdoor
Crutch is a backdoor designed for document theft that has been used by Turla since at least 2015.
Cry36 ransomware
Cry36 is a type of ransomware that encrypts files on infected systems, demanding a ransom payment for decryption.
Cry9 ransomware
Cry9 is a ransomware variant that encrypts files on infected systems, demanding a ransom payment for decryption keys.
CryBrazil ransomware
Mostly Hidden Tear with some codes from Eda2 & seems compiled w/ Italian VS.
CryCipher ransomware
Also known as PayPalGenerator2019. CryCipher, also known as PayPalGenerator2019, is a type of ransomware that encrypts files on an infected system, demanding a ransom for…
CryCryptor ransomware
Also known as CryCrypter, CryDroid. CryCryptor is a ransomware targeting Android devices, encrypting user data to demand a ransom.
CryDroid ransomware
CryDroid is a ransomware targeting Android devices, encrypting user data and demanding a ransom for decryption.
CryFile ransomware
CryFile is a ransomware that encrypts files on victim machines and demands a ransom payment, primarily targeting sectors with high-value…
CryForMe ransomware
CryForMe is a type of ransomware that encrypts files on the infected system and demands a ransom for the decryption key.
CryLocker ransomware
Also known as Cry, CSTO, Central Security Treatment Organization. Ransomware Identifies victim locations w/Google Maps API
CryMore ransomware
CryMore is a ransomware family that encrypts files on infected systems and demands a ransom payment for the decryption key.
CryPy ransomware
CryPy is a ransomware that encrypts user files and demands a ransom for the decryption key.
CryTekk ransomware
CryTekk is a type of ransomware that encrypts files on a victim's machine and demands a ransom payment for decryption.
Cryaki ransomware
Cryaki is a ransomware known for encrypting victim's files and demanding a ransom for their decryption.
Cryakl ransomware
Also known as CryLock. Cryakl, also known as CryLock, is a ransomware family that encrypts files on infected machines, demanding a ransom for decryption.
Crybola ransomware
Crybola is a ransomware family known for encrypting files and demanding a ransom for decryption keys.
Crying ransomware
Crying is a type of ransomware that encrypts files on the victim's system and demands payment for the decryption key.
Crylock ransomware
Also known as Cryakl. Crylock, also known as Cryakl, is a ransomware malware family that encrypts users' files and demands a ransom for the decryption key.
Cryp70n1c ransomware
Cryp70n1c is a ransomware family that encrypts files on infected systems, demanding a ransom payment in cryptocurrency for decryption.
CrypMIC ransomware
CrypMIC is a ransomware variant closely related to CryptXXX, known for encrypting files and demanding ransom from victims for file…
CrypTron ransomware
CrypTron is a ransomware that targets various industries, employing encryption to lock user data and demanding ransom for decryption.
Crypren ransomware
Crypren is a ransomware known for encrypting files on infected systems and demanding a ransom for decryption keys.
Crypt0 ransomware
Crypt0 is a ransomware that encrypts a victim's files and demands a ransom payment for the decryption key.
Crypt0 HT ransomware
Crypt0 HT is a ransomware strain that encrypts files on infected systems and demands a ransom for decryption.
Crypt0L0cker ransomware
Crypt0L0cker is a type of ransomware that encrypts the victim's files and demands a ransom payment to decrypt them.
Crypt0r ransomware
Crypt0r is a ransomware family that encrypts files on the infected system, demanding a ransom payment for decryption.
Crypt0saur ransomware
Crypt0saur is a ransomware family known for targeting financial services and technology sectors.
Crypt12 ransomware
Crypt12 is a type of ransomware known for encrypting files and demanding a ransom for their release.
Crypt32 ransomware
Crypt32 is a ransomware known for encrypting users' files and demanding payment for the decryption key.
Crypt38 ransomware
Crypt38 is a ransomware family known for encrypting files on affected systems and demanding payment for file decryption.
CryptBot credential-stealerscreen-capturespyware
A typical infostealer, capable of obtaining credentials for browsers, crypto currency wallets, browser cookies, credit cards, and creates…
CryptConsole ransomware
This ransomware does not actually encrypt your file, but only changes the names of your files, just like Globe Ransomware.
CryptConsole 2.0 Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
CryptFIle2 ransomware
Also known as Lesli. CryptFIle2, also known as Lesli, is a ransomware family designed to encrypt victims' files and demand ransom payments.
CryptFuck ransomware
CryptFuck is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption keys.
CryptGh0st ransomware
CryptGh0st is a sophisticated ransomware variant that encrypts victim's files, demanding payment for decryption.
CryptInfinite ransomware
Also known as DecryptorMax. CryptInfinite, also known as DecryptorMax, is a type of ransomware that encrypts files on infected systems, demanding a ransom for…
CryptXXX ransomware
Also known as CryptProjectXXX. CryptXXX is a ransomware family that encrypts files on the victim's system and demands a ransom for decryption, often distributed…
CryptXXX 2.0 ransomware
Also known as CryptProjectXXX. Ransomware Locks screen. Ransom note names are an ID. Comes with Bedep.
CryptXXX 3.0 ransomware
Also known as UltraDeCrypter, UltraCrypter. CryptXXX 3.0 is a ransomware variant that encrypts files on infected systems, demanding a ransom for decryption.
CryptXXX 3.1 ransomwarecredential-stealer
CryptXXX 3.1 is a ransomware variant known for its dual capabilities: encrypting the victim's files to demand a ransom and stealing…
CryptXXXX ransomware
CryptXXXX is a ransomware family known for encrypting files on infected systems and demanding a ransom for decryption.
Crypter ransomware
Ransomware Does not actually encrypt the files, but simply renames them
CrypticConvo droppertrojan
CrypticConvo is a dropper trojan which appears to be embedded in an automatic generator framework to deliver the FakeM trojan.
Crypto-Blocker ransomware
Crypto-Blocker is a type of ransomware known for encrypting victim files and demanding payment for decryption.
CryptoApp ransomware
CryptoApp is a ransomware variant aimed at encrypting user files and demanding payment for decryption.
CryptoBit ransomware
Ransomware sekretzbel0ngt0us.KEY - do not confuse with CryptorBit.
CryptoBlock Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
CryptoBoss ransomware
CryptoBoss is a type of ransomware designed to encrypt files on a victim's system, demanding a ransom payment for file decryption.
CryptoCat ransomware
CryptoCat is a ransomware family that encrypts files on an infected system and demands payment for decryption.
CryptoClippy credential-stealer
CryptoClippy is a malicious software known for stealing cryptocurrency information by targeting clipboard data.
CryptoClone ransomware
CryptoClone is a type of ransomware known for encrypting victim's files and demanding cryptocurrency as ransom.
CryptoDark ransomware
CryptoDark is a sophisticated ransomware targeting critical industries such as financial services, healthcare, and public sectors across…
CryptoDarkRubix ransomware
Also known as Ranet. CryptoDarkRubix, also known as Ranet, is a ransomware family that primarily targets the financial services sector.
CryptoDefense ransomware
CryptoDefense is a ransomware family known for encrypting victims' files without changing file extensions and demanding a ransom for…
CryptoDevil Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
CryptoFinancial ransomware
Also known as Ranscam. CryptoFinancial, also known as Ranscam, is a ransomware family targeting the financial-services industry.
CryptoFortress ransomware
Ransomware Mimics Torrentlocker. Encrypts only 50% of each file up to 5 MB
CryptoGod 2017 ransomware
CryptoGod 2017 is a ransomware family that encrypts files on infected systems, demanding payment in cryptocurrency for decryption keys.
CryptoGod 2018 ransomware
CryptoGod 2018 is a ransomware family known for encrypting victims' files and demanding a ransom for decryption keys.
CryptoGraphic Locker ransomware
Ransomware Has a GUI. Subvariants: CoinVault BitCryptor
CryptoHost ransomware
Also known as Manamecrypt, Telograph, ROI Locker. CryptoHost is a ransomware known for encrypting victim's files by packaging them into RAR archives.
CryptoJacky Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
CryptoJoker ransomware
Also known as PlutoCrypt. CryptoJoker is a ransomware that encrypts victims' files and demands a ransom in cryptocurrency for decryption.
CryptoKill Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
CryptoLite ransomware
CryptoLite is a ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
CryptoLocker ransomware
CryptoLocker is a notorious ransomware that emerged in 2013, encrypting users' files and demanding payment for the decryption key.
CryptoLocker 1.0.0 ransomware
CryptoLocker is a type of ransomware that encrypts files on a compromised system and demands a ransom for decryption keys.
CryptoLocker 5.1 ransomware
Ransomware
CryptoLocker by NTK Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
CryptoLocker3 Ransomware ransomware
Also known as Fake CryptoLocker. It’s directed to English speaking users, therefore is able to infect worldwide.
CryptoLockerEU 2016 ransomware
CryptoLockerEU 2016 is a ransomware variant that encrypts files on infected systems, demanding a ransom for the decryption key.
CryptoLuck ransomware
CryptoLuck is a type of ransomware that encrypts the victim's files and demands a payment for decryption.
CryptoLuck Ransomware ransomware
Also known as YafunnLocker. This is most likely to affect English speaking users, since the note is written in English.
CryptoManiac ransomware
CryptoManiac is a ransomware family known for encrypting victims' files and demanding cryptocurrency payments for decryption.
CryptoMeister Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
CryptoMix ransomware
Also known as Zeta, Azer, CryptFile2. CryptoMix is a ransomware family known for encrypting files on infected systems and demanding a ransom for decryption keys.
CryptoMix-0000 ransomware
CryptoMix is a ransomware family known for encrypting user files and demanding a ransom for decryption.
CryptoMix-Arena ransomware
CryptoMix-Arena is a ransomware strain, part of the CryptoMix family, known for encrypting user files and demanding payment for decryption.