Malware Families page 12 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

CryptoMix-Azer ransomware
CryptoMix-Azer is a ransomware variant known for encrypting files on infected systems and demanding ransom payments for decryption keys.
CryptoMix-Backup ransomware
CryptoMix-Backup is a ransomware family that encrypts victim files and demands a ransom for decryption.
CryptoMix-CK ransomware
CryptoMix-CK is a variant of ransomware that encrypts files on an infected system and demands payment for decryption.
CryptoMix-Coban ransomware
CryptoMix-Coban is a type of ransomware that encrypts user files and demands a ransom for the decryption key.
CryptoMix-DLL ransomware
CryptoMix-DLL is a ransomware variant known for encrypting users' files and demanding a ransom payment for the decryption key.
CryptoMix-Empty ransomware
Ransomware
CryptoMix-Error ransomware
CryptoMix-Error is a variant of the CryptoMix ransomware family, primarily targeting healthcare and public sector organizations.
CryptoMix-Exte ransomware
CryptoMix-Exte is a variant of the CryptoMix ransomware family that encrypts user data and demands a ransom payment for decryption.
CryptoMix-MOLE66 ransomware
CryptoMix-MOLE66 is a variant of the CryptoMix ransomware family, known for encrypting files on infected systems and demanding a ransom…
CryptoMix-Noob ransomware
CryptoMix-Noob is a ransomware variant known for encrypting victim files and demanding a ransom payment in Bitcoin.
CryptoMix-Ogonia ransomware
CryptoMix-Ogonia is a ransomware family that encrypts files on the victim's system and demands a ransom for decryption.
CryptoMix-Pirate ransomware
CryptoMix-Pirate is a ransomware variant that encrypts files on an infected system and demands a ransom for decryption.
CryptoMix-Revenge ransomware
CryptoMix-Revenge is a ransomware variant known for encrypting files and demanding a ransom payment.
CryptoMix-Shark ransomware
Also known as Shark CryptoMix. CryptoMix-Shark is a type of ransomware that encrypts files on infected systems and demands payment in cryptocurrency for decryption keys.
CryptoMix-System ransomware
Also known as System CryptoMix. CryptoMix-System, also known as System CryptoMix, is a ransomware family that encrypts files on compromised systems and demands a ransom…
CryptoMix-Tastylock ransomware
Also known as Tastylock CryptoMix. CryptoMix, also known as Tastylock, is a ransomware family that encrypts files on infected machines and demands a ransom for decryption.
CryptoMix-Test ransomware
Also known as Test CryptoMix. CryptoMix is a ransomware family that encrypts files on the infected systems and demands a ransom for file decryption.
CryptoMix-Wallet ransomware
CryptoMix-Wallet is a ransomware variant that encrypts victim files, demanding a ransom payment for decryption.
CryptoMix-XZZX ransomware
Also known as XZZX CryptoMix. CryptoMix-XZZX, also known as XZZX CryptoMix, is a ransomware family that encrypts files on the infected system, demanding a ransom for…
CryptoMix-Zayka ransomware
Also known as Zayka CryptoMix. CryptoMix-Zayka is a ransomware variant that encrypts files on infected systems and demands a ransom payment in Bitcoin to retrieve the…
CryptoMix-x1881 ransomware
Also known as x1881 CryptoMix. CryptoMix-x1881 is a variant of the CryptoMix ransomware family, which encrypts files on infected systems and demands a ransom for…
CryptoNar ransomware
When the CryptoNar, or Crypto Nar, Ransomware encrypts a victims files it will perform the encryption differently depending on the type of…
CryptoNight cryptominer
CryptoNight is a WebAssembly-based crypto miner used to mine cryptocurrency by utilizing the resources of compromised systems.
CryptoPatronum ransomware
CryptoPatronum is a ransomware family known for encrypting files on the victim's computer and demanding a cryptocurrency payment to…
CryptoPokemon ransomware
CryptoPokemon is a ransomware malware that encrypts files on the infected system and demands a cryptocurrency payment for decryption.
CryptoRansomeware ransomware
CryptoRansomware is a type of malware designed to encrypt files on affected systems and demand a ransom in cryptocurrency for decryption.
CryptoRoger ransomware
CryptoRoger is a ransomware variant that encrypts files on the infected system and demands a ransom payment in cryptocurrency for the…
CryptoShadow ransomware
CryptoShadow is a type of ransomware that encrypts the victim's data and demands a cryptocurrency payment for the decryption key.
CryptoShield ransomware
CryptoShield is a ransomware family that encrypts files on infected systems and demands a cryptocurrency payment for decryption.
CryptoShield 1.0 Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
CryptoShield 2.0 ransomware
CryptoShield 2.0 is a ransomware variant that encrypts files on infected systems and demands a ransom in cryptocurrency for decrypting them.
CryptoShocker ransomware
CryptoShocker is a ransomware family known for encrypting user files and demanding a cryptocurrency ransom for decryption keys.
CryptoShuffler credential-stealer
CryptoShuffler is a Trojan that targets cryptocurrency users by manipulating clipboard contents to redirect payments to…
CryptoSpider ransomware
CryptoSpider is a ransomware that encrypts files on victim machines, demanding a cryptocurrency payment for decryption.
CryptoSweetTooth Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
CryptoTorLocker2015 ransomware
CryptoTorLocker2015 is a ransomware that encrypts files on the infected system and demands a ransom payment for decryption.
CryptoTrooper ransomware
CryptoTrooper is a ransomware strain that encrypts victims' files and demands payment for the decryption keys.
CryptoViki ransomware
CryptoViki is a ransomware malware family known for encrypting victims' data and demanding cryptocurrency as ransom.
CryptoWall 1 ransomware
CryptoWall 1 is a ransomware that spreads primarily through phishing campaigns.
CryptoWall 2 ransomware
CryptoWall 2 is a variant of the CryptoWall ransomware family, known for encrypting files and demanding a ransom in Bitcoin for decryption…
CryptoWall 3 ransomware
CryptoWall 3 is a notorious ransomware variant known for encrypting files on infected systems and demanding a ransom payment in Bitcoin…
CryptoWall 4 ransomware
CryptoWall 4 is a form of ransomware that encrypts victims' files and demands payment for the decryption key.
CryptoWire keylogger
CryptoWire is a keylogger malware family used to record and exfiltrate keystrokes and other input data from infected systems.
CryptoWire Ransomeware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Crypto_Lab ransomware
Crypto_Lab is a sophisticated ransomware family known for encrypting victim data and demanding ransoms for decryption keys.
Cryptoistic backdoor
Cryptoistic is a backdoor, written in Swift, that has been used by Lazarus Group.
CryptolockerEmulator ransomware
CryptolockerEmulator is a type of ransomware designed to mimic the notorious Cryptolocker, encrypting files and demanding a ransom for…
Cryptomix-FILE ransomware
Cryptomix-FILE is a ransomware variant that encrypts files on the compromised system, demanding a ransom payment for file decryption.
Cryptomix-SERVER ransomware
Also known as SERVER Cryptomix. Cryptomix-SERVER is a variant of the ransomware family which encrypts files on infected systems and demands a ransom for the decryption key.
Cryptomix-WORK ransomware
Also known as WORK CryptoMix. Cryptomix-WORK, also known as WORK CryptoMix, is a family of ransomware that encrypts user files and demands a ransom for the decryption…
Crypton ransomware
Crypton is a type of ransomware that encrypts victims' files and demands a ransom for decryption.
Crypton Ransomware ransomware
Also known as Nemesis, X3M. This is most likely to affect English speaking users, since the note is written in English.
CryptorBit ransomware
CryptorBit is a type of ransomware that encrypts files on the infected devices and demands payment for the decryption key.
Cryptorium ransomware
Cryptorium is a ransomware family known for encrypting files and demanding payment in cryptocurrency for decryption.
Cryptorium (Fake Ransomware) ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Cryptowall ransomwaretrojan
CryptoWall is a ransomware, is usually spread by spam and phishing emails, malicious ads, hacked websites, or other malware and uses a…
Cryptre ransomware
Cryptre is a type of ransomware known for encrypting files on infected systems and demanding cryptocurrency payment for decryption.
Crypute Ransomware ransomware
Also known as m0on Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
Crysis XTBL ransomware
Crysis XTBL is a variant of ransomware that encrypts files on the victim's system and demands a ransom for the decryption key.
Crystal ransomware
Crystal is a ransomware family that encrypts files on affected systems, demanding payment for decryption.
Crystal Rans0m ransomware
Also known as CrystalRansom. Crystal Rans0m, also known as CrystalRansom, is a ransomware family targeting various sectors, including financial services and healthcare.
CrystalCrypt ransomware
CrystalCrypt is a ransomware family designed to encrypt files on victims' machines, demanding a ransom for the decryption key.
Crytox ransomware
Crytox is a type of ransomware that encrypts files on victims' computers, demanding payment for decryption keys.
CsExt backdoorrat
CsExt is a sophisticated remote access Trojan (RAT) used primarily in cyber espionage campaigns.
Cthulhu Stealer credential-stealer
Cthulhu Stealer is a credential-stealing malware family known for exfiltrating sensitive data from infected systems.
Cuba ransomware
Also known as COLDDRAW, Fidel. Cuba is a Windows-based ransomware family that has been used against financial institutions, technology, and logistics organizations in…
Cuckoo Stealer spywarecredential-stealertrojan
Cuckoo Stealer is a macOS malware with characteristics of spyware and an infostealer that has been in use since at least 2024.
Cuegoe trojanbackdoor
Cuegoe is a sophisticated malware family known for its capabilities in espionage operations.
Cueisfry trojan
Cueisfry is a financial-targeted trojan primarily aiming at banking credentials in the financial services industry.
CukieGrab credential-stealertrojan
Also known as Roblox Trade Assist. CukieGrab, also known as Roblox Trade Assist, is a credential-stealing malware targeting users of the online gaming platform Roblox.
Cur1Downloader downloader
Cur1Downloader is a downloader linked to the Lazarus group, potentially targeting sectors in South Korea, the United States, and Japan.
Curator ransomware
Also known as Ever101, SunnyDay. Curator, also known as Ever101 or SunnyDay, is a ransomware family targeting various industries, notably healthcare, financial services…
CurlBack RAT rat
CurlBack RAT is a Remote Access Trojan used for cyber espionage activities.
Cursed Murderer ransomware
Cursed Murderer is a type of ransomware known for encrypting sensitive data and demanding a ransom for its decryption, targeting various…
Curumim ransomware
Curumim is a type of ransomware known for encrypting files on the compromised systems and demanding a ransom for decryption.
CustomerLoader loaderdropper
CustomerLoader is a .Net-based loader that drops more than 40 different malware families.
CuteRansomware ransomware
Also known as my-Little-Ransomware. CuteRansomware is a ransomware variant based on my-Little-Ransomware, known for encrypting users' files and demanding a ransom for…
Cutekitty ransomware
Cutekitty is a type of ransomware that encrypts files on the infected system and demands a ransom payment for decryption.
Cutlet trojan
Cutlet is malware designed to target automated teller machines (ATMs) and enable unauthorized cash withdrawals.
Cutwail botnetddos
Cutwail is a notorious botnet primarily used for sending spam emails and conducting DDoS attacks.
Cyber Drill Exercise ransomware
Also known as Ransomuhahawhere. It’s directed to English speaking users, therefore is able to infect worldwide.
Cyber Eye RAT rat
Cyber Eye RAT is a remote access tool used primarily for cyber espionage.
Cyber Police HT ransomware
Cyber Police HT is a ransomware strain known for targeting healthcare and governmental sectors primarily in the United States, United…
Cyber SpLiTTer Vbs ransomware
Also known as CyberSplitter. Cyber SpLiTTer Vbs is a ransomware variant based on the open-source HiddenTear project, utilizing VBS scripting to deliver its payload.
CyberAzov wiper
CyberAzov is a wiper malware associated with cyberattacks primarily targeting Ukraine, aimed at disrupting critical infrastructure and…
CyberDrill2 ransomware
CyberDrill2 is a ransomware that targets various industries, often encrypting files and demanding payment for decryption keys.
CyberGate ratcredential-stealer
Also known as Rebhip. According to Subex Secure, CyberGate is a Remote Access Trojan (RAT) that allows an attacker to gain unauthorized access to the victim’s…
CyberResearcher ransomware
CyberResearcher is a ransomware that encrypts files on the target's system and demands a ransom for decryption.
CyberSCCP ransomware
CyberSCCP is a ransomware strain targeting critical infrastructure sectors such as healthcare and financial services, leveraging…
CyberSoldier ransomware
CyberSoldier is a ransomware family targeting key sectors such as financial services, healthcare, and government.
CyberSplitter ratspyware
CyberSplitter is a family of remote access trojans primarily used for espionage and cybercrime activities.
Cyborg Ransomware ransomware
Ransomware delivered using fake Windows Update spam
CycBot botnetddos
CycBot is a malware family known to operate as a botnet, primarily targeting financial services and government sectors.
Cyclone ransomware
Cyclone is a ransomware known for targeting various industries including financial services, healthcare, and government sectors.
Cyclops Blink botnetworm
Cyclops Blink is a modular malware that has been used in widespread campaigns by Sandworm Team since at least 2019 to target Small/Home…
CyclopsBlink botnet
According to CISA, Cyclops Blink appears to be a replacement framework for the VPNFilter malware exposed in 2018, and which exploited…
CypherPy ransomware
CypherPy is a ransomware that encrypts user files and demands a ransom in cryptocurrency for decryption.
Cyrat ransomware
Cyrat is a ransomware malware known for encrypting files and demanding a ransom for decryption.
Cyron ransomware
claims it detected "Children Pornsites" in your browser history
Cyspt ransomware
Cyspt is a type of ransomware known for encrypting user data and demanding payment for the decryption key.