Malware Families page 11 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Credraptor credential-stealer
- Credraptor is a credential-stealing malware family that targets sensitive authentication information.
- CreepExfil spywarebackdoor
- CreepExfil is a piece of malware known for exfiltrating sensitive data from compromised systems.
- Creeper ransomware
- Creeper is considered the first known ransomware, designed to demonstrate the concept of self-replicating code.
- Creepy ransomware
- Creepy is a strain of ransomware known for encrypting data and demanding a ransom for decryption keys.
- CreepyDrive backdoor
- CreepyDrive is a custom implant has been used by POLONIUM since at least early 2022 for C2 with and exfiltration to actor-controlled…
- CreepySnail rattrojan
- CreepySnail is a custom PowerShell implant that has been used by POLONIUM since at least 2022.
- Crenufs trojan
- Crenufs is a sophisticated trojan primarily targeting financial and technology sectors.
- Crimson rat
- Also known as MSIL/Crimson. Crimson is a remote access Trojan that has been used by Transparent Tribe since at least 2016.
- Crimson RAT ratspyware
- Also known as SEEDOOR, Scarimson. It was first discovered in 2017 and has since been used to attack organizations around the world.
- CrimsonIAS backdoor
- According to ThreatConnect, CrimsonIAS is a Delphi-written backdoor dating back to at least 2017.
- Cring ransomware
- Cring is a ransomware strain known for targeting organizations in the manufacturing and energy sectors.
- Cripton ransomware
- Cripton is a ransomware family known for encrypting files on infected systems and demanding a ransom payment for decryption.
- Cripton7zp ransomware
- Cripton7zp is a ransomware known for encrypting files on victim systems, demanding payment for the decryption key.
- Crisis trojanrootkit
- Crisis is a versatile Trojan with rootkit capabilities, primarily targeting Windows and Mac OS X operating systems.
- Crocodilus trojan
- Crocodilus is an Android banking Trojan that was discovered in March 2025.
- CronRAT rat
- A malware written in Bash that hides in the Linux calendar system on February 31st.
- CrossRAT rat
- Also known as Trupto. CrossRAT is a cross-platform remote access tool (RAT) that affects Windows, OSX, and Linux systems.
- Crossrider spyware
- Crossrider is a type of adware and spyware known for injecting advertisements into web browsing sessions and altering browser settings.
- Croxloader loader
- According to Trend Micro, this is a custom loader for win.cobalt_strike, used by Earth Longzhi (a subgroup of APT41).
- Crptxxx Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- CruLoader loader
- CruLoader is a malware known for its capabilities to load additional malicious payloads and facilitate cyber attacks.
- Crutch backdoor
- Crutch is a backdoor designed for document theft that has been used by Turla since at least 2015.
- Cry36 ransomware
- Cry36 is a type of ransomware that encrypts files on infected systems, demanding a ransom payment for decryption.
- Cry9 ransomware
- Cry9 is a ransomware variant that encrypts files on infected systems, demanding a ransom payment for decryption keys.
- CryBrazil ransomware
- Mostly Hidden Tear with some codes from Eda2 & seems compiled w/ Italian VS.
- CryCipher ransomware
- Also known as PayPalGenerator2019. CryCipher, also known as PayPalGenerator2019, is a type of ransomware that encrypts files on an infected system, demanding a ransom for…
- CryCryptor ransomware
- Also known as CryCrypter, CryDroid. CryCryptor is a ransomware targeting Android devices, encrypting user data to demand a ransom.
- CryDroid ransomware
- CryDroid is a ransomware targeting Android devices, encrypting user data and demanding a ransom for decryption.
- CryFile ransomware
- CryFile is a ransomware that encrypts files on victim machines and demands a ransom payment, primarily targeting sectors with high-value…
- CryForMe ransomware
- CryForMe is a type of ransomware that encrypts files on the infected system and demands a ransom for the decryption key.
- CryLocker ransomware
- Also known as Cry, CSTO, Central Security Treatment Organization. Ransomware Identifies victim locations w/Google Maps API
- CryMore ransomware
- CryMore is a ransomware family that encrypts files on infected systems and demands a ransom payment for the decryption key.
- CryPy ransomware
- CryPy is a ransomware that encrypts user files and demands a ransom for the decryption key.
- CryTekk ransomware
- CryTekk is a type of ransomware that encrypts files on a victim's machine and demands a ransom payment for decryption.
- Cryaki ransomware
- Cryaki is a ransomware known for encrypting victim's files and demanding a ransom for their decryption.
- Cryakl ransomware
- Also known as CryLock. Cryakl, also known as CryLock, is a ransomware family that encrypts files on infected machines, demanding a ransom for decryption.
- Crybola ransomware
- Crybola is a ransomware family known for encrypting files and demanding a ransom for decryption keys.
- Crying ransomware
- Crying is a type of ransomware that encrypts files on the victim's system and demands payment for the decryption key.
- Crylock ransomware
- Also known as Cryakl. Crylock, also known as Cryakl, is a ransomware malware family that encrypts users' files and demands a ransom for the decryption key.
- Cryp70n1c ransomware
- Cryp70n1c is a ransomware family that encrypts files on infected systems, demanding a ransom payment in cryptocurrency for decryption.
- CrypMIC ransomware
- CrypMIC is a ransomware variant closely related to CryptXXX, known for encrypting files and demanding ransom from victims for file…
- CrypTron ransomware
- CrypTron is a ransomware that targets various industries, employing encryption to lock user data and demanding ransom for decryption.
- Crypren ransomware
- Crypren is a ransomware known for encrypting files on infected systems and demanding a ransom for decryption keys.
- Crypt0 ransomware
- Crypt0 is a ransomware that encrypts a victim's files and demands a ransom payment for the decryption key.
- Crypt0 HT ransomware
- Crypt0 HT is a ransomware strain that encrypts files on infected systems and demands a ransom for decryption.
- Crypt0L0cker ransomware
- Crypt0L0cker is a type of ransomware that encrypts the victim's files and demands a ransom payment to decrypt them.
- Crypt0r ransomware
- Crypt0r is a ransomware family that encrypts files on the infected system, demanding a ransom payment for decryption.
- Crypt0saur ransomware
- Crypt0saur is a ransomware family known for targeting financial services and technology sectors.
- Crypt12 ransomware
- Crypt12 is a type of ransomware known for encrypting files and demanding a ransom for their release.
- Crypt32 ransomware
- Crypt32 is a ransomware known for encrypting users' files and demanding payment for the decryption key.
- Crypt38 ransomware
- Crypt38 is a ransomware family known for encrypting files on affected systems and demanding payment for file decryption.
- CryptBot credential-stealerscreen-capturespyware
- A typical infostealer, capable of obtaining credentials for browsers, crypto currency wallets, browser cookies, credit cards, and creates…
- CryptConsole ransomware
- This ransomware does not actually encrypt your file, but only changes the names of your files, just like Globe Ransomware.
- CryptConsole 2.0 Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- CryptFIle2 ransomware
- Also known as Lesli. CryptFIle2, also known as Lesli, is a ransomware family designed to encrypt victims' files and demand ransom payments.
- CryptFuck ransomware
- CryptFuck is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption keys.
- CryptGh0st ransomware
- CryptGh0st is a sophisticated ransomware variant that encrypts victim's files, demanding payment for decryption.
- CryptInfinite ransomware
- Also known as DecryptorMax. CryptInfinite, also known as DecryptorMax, is a type of ransomware that encrypts files on infected systems, demanding a ransom for…
- CryptXXX ransomware
- Also known as CryptProjectXXX. CryptXXX is a ransomware family that encrypts files on the victim's system and demands a ransom for decryption, often distributed…
- CryptXXX 2.0 ransomware
- Also known as CryptProjectXXX. Ransomware Locks screen. Ransom note names are an ID. Comes with Bedep.
- CryptXXX 3.0 ransomware
- Also known as UltraDeCrypter, UltraCrypter. CryptXXX 3.0 is a ransomware variant that encrypts files on infected systems, demanding a ransom for decryption.
- CryptXXX 3.1 ransomwarecredential-stealer
- CryptXXX 3.1 is a ransomware variant known for its dual capabilities: encrypting the victim's files to demand a ransom and stealing…
- CryptXXXX ransomware
- CryptXXXX is a ransomware family known for encrypting files on infected systems and demanding a ransom for decryption.
- Crypter ransomware
- Ransomware Does not actually encrypt the files, but simply renames them
- CrypticConvo droppertrojan
- CrypticConvo is a dropper trojan which appears to be embedded in an automatic generator framework to deliver the FakeM trojan.
- Crypto-Blocker ransomware
- Crypto-Blocker is a type of ransomware known for encrypting victim files and demanding payment for decryption.
- CryptoApp ransomware
- CryptoApp is a ransomware variant aimed at encrypting user files and demanding payment for decryption.
- CryptoBit ransomware
- Ransomware sekretzbel0ngt0us.KEY - do not confuse with CryptorBit.
- CryptoBlock Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- CryptoBoss ransomware
- CryptoBoss is a type of ransomware designed to encrypt files on a victim's system, demanding a ransom payment for file decryption.
- CryptoCat ransomware
- CryptoCat is a ransomware family that encrypts files on an infected system and demands payment for decryption.
- CryptoClippy credential-stealer
- CryptoClippy is a malicious software known for stealing cryptocurrency information by targeting clipboard data.
- CryptoClone ransomware
- CryptoClone is a type of ransomware known for encrypting victim's files and demanding cryptocurrency as ransom.
- CryptoDark ransomware
- CryptoDark is a sophisticated ransomware targeting critical industries such as financial services, healthcare, and public sectors across…
- CryptoDarkRubix ransomware
- Also known as Ranet. CryptoDarkRubix, also known as Ranet, is a ransomware family that primarily targets the financial services sector.
- CryptoDefense ransomware
- CryptoDefense is a ransomware family known for encrypting victims' files without changing file extensions and demanding a ransom for…
- CryptoDevil Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- CryptoFinancial ransomware
- Also known as Ranscam. CryptoFinancial, also known as Ranscam, is a ransomware family targeting the financial-services industry.
- CryptoFortress ransomware
- Ransomware Mimics Torrentlocker. Encrypts only 50% of each file up to 5 MB
- CryptoGod 2017 ransomware
- CryptoGod 2017 is a ransomware family that encrypts files on infected systems, demanding payment in cryptocurrency for decryption keys.
- CryptoGod 2018 ransomware
- CryptoGod 2018 is a ransomware family known for encrypting victims' files and demanding a ransom for decryption keys.
- CryptoGraphic Locker ransomware
- Ransomware Has a GUI. Subvariants: CoinVault BitCryptor
- CryptoHost ransomware
- Also known as Manamecrypt, Telograph, ROI Locker. CryptoHost is a ransomware known for encrypting victim's files by packaging them into RAR archives.
- CryptoJacky Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- CryptoJoker ransomware
- Also known as PlutoCrypt. CryptoJoker is a ransomware that encrypts victims' files and demands a ransom in cryptocurrency for decryption.
- CryptoKill Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- CryptoLite ransomware
- CryptoLite is a ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
- CryptoLocker ransomware
- CryptoLocker is a notorious ransomware that emerged in 2013, encrypting users' files and demanding payment for the decryption key.
- CryptoLocker 1.0.0 ransomware
- CryptoLocker is a type of ransomware that encrypts files on a compromised system and demands a ransom for decryption keys.
- CryptoLocker 5.1 ransomware
- Ransomware
- CryptoLocker by NTK Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- CryptoLocker3 Ransomware ransomware
- Also known as Fake CryptoLocker. It’s directed to English speaking users, therefore is able to infect worldwide.
- CryptoLockerEU 2016 ransomware
- CryptoLockerEU 2016 is a ransomware variant that encrypts files on infected systems, demanding a ransom for the decryption key.
- CryptoLuck ransomware
- CryptoLuck is a type of ransomware that encrypts the victim's files and demands a payment for decryption.
- CryptoLuck Ransomware ransomware
- Also known as YafunnLocker. This is most likely to affect English speaking users, since the note is written in English.
- CryptoManiac ransomware
- CryptoManiac is a ransomware family known for encrypting victims' files and demanding cryptocurrency payments for decryption.
- CryptoMeister Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- CryptoMix ransomware
- Also known as Zeta, Azer, CryptFile2. CryptoMix is a ransomware family known for encrypting files on infected systems and demanding a ransom for decryption keys.
- CryptoMix-0000 ransomware
- CryptoMix is a ransomware family known for encrypting user files and demanding a ransom for decryption.
- CryptoMix-Arena ransomware
- CryptoMix-Arena is a ransomware strain, part of the CryptoMix family, known for encrypting user files and demanding payment for decryption.