Malware Families page 13 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Czech ransomware
- Czech is a type of ransomware that encrypts files on infected systems, demanding payment for decryption keys.
- D00mEd ransomware
- D00mEd is a ransomware strain that encrypts data on victims' systems and demands a ransom for decryption.
- D2+D ransomware
- D2+D is a ransomware strain that encrypts files on infected systems.
- DAAM botnetspyware
- Also known as BouldSpy. According to PCrisk, DAAM is an Android malware utilized to gain unauthorized access to targeted devices since 2021.
- DADJOKE downloaderloader
- DADJOKE was discovered as being distributed via email, targeting a South-East Asian Ministry of Defense.
- DADSTACHE backdoor
- DADSTACHE is a sophisticated backdoor malware with capabilities for data exfiltration.
- DARKDEW worm
- Mandiant associates this with UNC4191, this malware spreads to removable drives.
- DBGer Ransomware ransomwarecredential-stealer
- The authors of the Satan ransomware have rebranded their "product" and they now go by the name of DBGer ransomware, according to security…
- DBatLoader loader
- Also known as ModiLoader, NatsoLoader. This Delphi loader misuses Cloud storage services, such as Google Drive to download the Delphi stager component.
- DBoxAgent rat
- DBoxAgent is a remote access trojan (RAT) that leverages Dropbox as a command and control (C&C) channel to evade detection.
- DCHSpy spyware
- DCHSpy is an Android spyware likely used by MuddyWater.
- DCRAT ratspyware
- Also known as DarkCrystal RAT. DCRAT is a variant of the open-source AsyncRAT developed in C# with additional capabilities such as patching Microsoft’s Antimalware Scan…
- DCRTR ransomware
- DCRTR is a ransomware known for encrypting user data and demanding a ransom for decryption.
- DCRTR-WDM ransomware
- DCRTR-WDM is a type of ransomware known for encrypting victim files and demanding a ransom for the decryption key.
- DCSrv wiperransomware
- Also known as DCrSrv. DCSrv is destructive malware that has been used by Moses Staff since at least September 2021.
- DCry ransomware
- DCry is a ransomware that encrypts victims' files and demands a ransom for decryption.
- DDE ransomware
- DDE is a form of ransomware that encrypts files on a victim's system, demanding payment for decryption keys.
- DDG botnetcryptominer
- First activity observed in October 2017. DDG is a botnet with P2P capability that is targeting crypto currency mining (Monero).
- DDKONG rat
- DDKONG is a malware sample that was part of a campaign by Rancor.
- DDKeylogger keylogger
- DDKeylogger is a malicious software that records and monitors keystrokes on infected systems.
- DEADBOLT ransomware
- DEADBOLT is a linux ransomware written in Go, targeting QNAP NAS devices worldwide.
- DEADEYE loader
- Also known as DEADEYE.EMBED, DEADEYE.APPEND. DEADEYE is a malware launcher that has been used by APT41 since at least May 2021.
- DEADWOOD wiper
- Also known as Agrius, DETBOSIT, SQLShred. DEADWOOD is wiper malware written in C++ using Boost libraries.
- DEATHRANSOM ransomware
- Also known as wacatac. DEATHRANSOM is ransomware written in C that has been used since at least 2020, and has potential overlap with FIVEHANDS and HELLOKITTY.
- DECAF ransomware
- DECAF is a ransomware variant developed in Go, known for its robust encryption and ability to target critical infrastructure sectors.
- DEDCryptor ransomware
- DEDCryptor is a ransomware variant based on EDA2, designed to encrypt files on infected systems and demand a ransom for decryption keys.
- DEEPDATA trojan
- According to Volexity, DEEPDATA is a modular post-exploitation tool for Windows that facilitates collection of sensitive information from…
- DEEPPOST spywaretrojan
- According to Volexity, DEEPPOST is a post-exploitation data exfiltration tool used to send files to a remote system.
- DEFENSOR ID trojancredential-stealer
- Also known as Defensor Digital. DEFENSOR ID is a banking trojan capable of clearing a victim’s bank account or cryptocurrency wallet and taking over email or social media…
- DEWMODE webshell
- FireEye discovered the DEWMODE webshell starting mid-December 2020 after exploitation of zero-day vulnerabilities in Accellion's File…
- DEcovid19 ransomware
- DEcovid19 is a ransomware variant that emerged during the COVID-19 pandemic.
- DILLJUICE rat
- DILLJUICE is a modified version of the open-source Quasar RAT used by APT10 for cyber-espionage operations.
- DISGOMOJI trojan
- DISGOMOJI is a Trojan malware with limited information available.
- DLRAT rat
- DLRAT is a remote access trojan (RAT) used for covert cyber-espionage activities.
- DMA Locker ransomware
- DMA Locker is a ransomware family that encrypts victims' files and demands a ransom for decryption.
- DMA Locker 1.0-2.0-3.0 ransomware
- DMA Locker is a ransomware strain that aims to encrypt users' files and demand payment for their release.
- DMA Locker 4.0 ransomware
- DMA Locker 4.0 is a variant of ransomware designed to encrypt files and demand a ransom from victims.
- DMALocker ransomware
- Ransomware no extension change Encrypted files have prefix: Version 1: ABCXYZ11 - Version 2: !DMALOCK - Version 3: !DMALOCK3.0 - Version…
- DMALocker 3.0 ransomware
- DMALocker 3.0 is a ransomware variant that encrypts files on infected machines and demands a ransom payment for decryption.
- DMALocker Imposter ransomware
- DMALocker Imposter is a ransomware variant known for encrypting files and demanding a ransom for decryption.
- DMSniff trojan
- DMSniff is a point-of-sale malware previously only privately sold.
- DN ransomware
- Also known as Fake. It’s directed to English speaking users, therefore is able to infect worldwide.
- DNRansomware ransomware
- Ransomware Code to decrypt: 83KYG9NW-3K39V-2T3HJ-93F3Q-GT
- DNSChanger trojan
- DNSChanger is a type of trojan that modifies a computer's DNS settings to direct users to malicious websites.
- DNSMessenger rat
- Talos recently analyzed an interesting malware sample that made use of DNS TXT record queries and responses to create a bidirectional…
- DNSRat rat
- Also known as DNSbot. DNSRat is a remote access trojan (RAT) that uses DNS for command and control communication, making it difficult to detect and analyze.
- DNSpionage spywaretrojan
- Also known as Agent Drable, AgentDrable, Webmask. DNSpionage is a cyber-espionage malware primarily used for conducting surveillance and exfiltrating data.
- DOGCALL backdoor
- DOGCALL is a backdoor used by APT37 that has been used to target South Korean government and military organizations in 2017.
- DONOT spywarerat
- Donot malware is a sophisticated, high-level malware toolkit designed to collect and exfiltrate information from vulnerable systems.
- DOPLUGS backdoortrojan
- DOPLUGS is a backdoor Trojan often employed in cyber-espionage campaigns.
- DORRA ransomware
- A new ransomware variant has been identified, named DORRA.
- DOSTEALER credential-stealerkeyloggerscreen-capture
- According to Mandiant, DOSTEALER is a dataminer that mines browser login and cookie data.
- DOUBLEBACK backdoor
- DOUBLEBACK is a newly discovered fileless malware deployed as part of an attack campaign that took place in December 2020.
- DOUBLELOADER loader
- DOUBLELOADER is a malware loader known for delivering various payloads in cybercriminal operations.
- DOWNIISSA downloader
- DOWNIISSA is a shellcode downloader that has been used by MirrorFace since at least 2022 to deploy payloads, including the LODEINFO…
- DRAT rat
- DRAT is a remote access tool often used for surveillance and unauthorized access to sensitive systems, particularly targeting government…
- DRATzarus rat
- Also known as ThreatNeedle, ThreatNeedleTea. DRATzarus is a remote access tool (RAT) that has been used by Lazarus Group to target the defense and aerospace organizations globally…
- DRIFTPIN backdoorratscreen-capture
- Also known as Spy.Agent.ORM, Toshliph. Driftpin is a small and simple backdoor that enables the attackers to assess the victim.
- DROPSHOT dropperransomware
- DROPSHOT is a malware family known to be associated with ransomware, frequently used as a dropper to deliver various types of ransomware…
- DRYHOOK credential-stealer
- DRYHOOK is Python script used to steal credentials.
- DUBrute credential-stealer
- DUBrute is a brute-force malware family known for targeting SSH servers.
- DUCKTAIL spywarecredential-stealer
- According to Tony Lambert, this is a malware written in .NET.
- DUMB Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- DUSTMAN wiper
- In 2019, multiple destructive attacks were observed targeting entities within the Middle East.
- DUSTPAN dropper
- Also known as StealthVector. DUSTPAN is an in-memory dropper written in C/C++ used by APT41 since 2021 that decrypts and executes an embedded payload.
- DUSTTRAP backdoorloadertrojan
- Also known as CurveLoad, DodgeBox, StealthReacher. DUSTTRAP is a multi-stage plugin framework associated with APT41 operations with multiple components.
- DXXD ransomware
- DXXD is a ransomware known for encrypting files on a victim's system and demanding ransom payments for decryption.
- DYEPACK trojan
- Also known as BanSwift, swift. DYEPACK, also known as BanSwift, is a trojan malware specifically targeting the financial services industry.
- Dablio Ransomware ransomware
- Dablio Ransomware is known for encrypting users' files and demanding a ransom for decryption.
- Dacls rat
- Dacls is a multi-platform remote access tool used by Lazarus Group since at least December 2019.
- Dacls (ELF) rat
- According to PCrisk, Dacls is the name of a remote access Trojan (RAT), a malicious program that allows cyber criminals to control…
- Dacls (OS X) rat
- According to PCrisk, Dacls is the name of a remote access Trojan (RAT), a malicious program that allows cyber criminals to control…
- Dacls (Windows) rat
- Also known as MATA. According to PCrisk, Dacls is the name of a remote access Trojan (RAT), a malicious program that allows cyber criminals to control…
- Dairy
- No description available.
- Daixin ransomware
- Daixin Team is a ransomware and data extortion group active since at least June 2022, known for targeting the healthcare sector, including…
- Dale Ransomware ransomware
- Also known as DaleLocker Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- Damage Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- DameWare Mini Remote Control rat
- Also known as dameware. Affordable remote control software for all your customer support and help desk needs.
- DanBot rat
- DanBot is a first-stage remote access Trojan written in C# that has been used by HEXANE since at least 2018.
- DanaBot trojancredential-stealer
- Also known as DanaTools. Proofpoints describes DanaBot as the latest example of malware focused on persistence and stealing useful information that can later be…
- DanderSpritz rat
- Also known as Dsz. DanderSpritz is a modular remote access tool (RAT) developed by a sophisticated adversary often linked to nation-state cyber-espionage…
- Dangerous Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Dante spyware
- According to Kaspersky Labs, Dante is the commercial spyware developed by Memento Labs (formerly Hacking Team).
- Daolpu trojan
- Daolpu is a trojan malware primarily involved in illegal activities such as click fraud and data exfiltration.
- Dark botnetworm
- Also known as Dark.IoT. Mirai variant exploiting CVE-2021-20090 and CVE2021-35395 for spreading.
- Dark DDoSeR ddosbotnet
- Dark DDoSeR is a botnet malware primarily used to execute distributed denial-of-service (DDoS) attacks.
- Dark Nexus botnetddos
- Dark Nexus is a botnet primarily targeting Internet of Things (IoT) devices, using them for distributed denial-of-service (DDoS) attacks.
- Dark Power ransomware
- Dark Power is a ransomware group first observed in January 2023, known for targeting small to mid-sized organizations across education…
- Dark Shades keyloggerspyware
- Also known as Rogue. Dark Shades, also known as Rogue, is a malware family known for its keylogging and spyware capabilities.
- DarkBit ransomware
- DarkBit is a ransomware variant discovered in 2023, known for targeting the education sector and public sector organizations in Iran and…
- DarkCloud Stealer credential-stealertrojan
- DarkCloud Stealer is credential-stealing malware written in Visual Basic, aimed at extracting sensitive information from infected systems.
- DarkComet backdoorratkeylogger
- Also known as DarkKomet, Fynloski, Krademok. DarkComet is a Windows remote administration tool and backdoor.
- DarkCracks downloader
- A sophisticated payload delivery and upgrade framework, discovered in 2024.
- DarkEye rat
- DarkEye is a sophisticated remote access trojan (RAT) primarily used for cyber-espionage.
- DarkGate credential-stealercryptominertrojan
- Also known as Meh, MehCrypter. DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber…
- DarkHotel ratspywarebackdoor
- DarkHotel is an advanced persistent threat group known for its cyber-espionage campaigns.
- DarkIRC botnetratcryptominer
- DarkIRC is a type of botnet malware that has the capability to establish remote access, deploy cryptominers, and conduct various malicious…
- DarkKomet rat
- DarkKomet is a remote access trojan (RAT) that facilitates unauthorized access and control over targeted systems.
- DarkLoader loader
- DarkLoader is a malware framework primarily used to deliver various payloads such as information stealers and ransomware.
- DarkLocker ransomware
- DarkLocker is a type of ransomware that encrypts files on infected systems, demanding a ransom for decryption.