Malware Families page 13 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Czech ransomware
Czech is a type of ransomware that encrypts files on infected systems, demanding payment for decryption keys.
D00mEd ransomware
D00mEd is a ransomware strain that encrypts data on victims' systems and demands a ransom for decryption.
D2+D ransomware
D2+D is a ransomware strain that encrypts files on infected systems.
DAAM botnetspyware
Also known as BouldSpy. According to PCrisk, DAAM is an Android malware utilized to gain unauthorized access to targeted devices since 2021.
DADJOKE downloaderloader
DADJOKE was discovered as being distributed via email, targeting a South-East Asian Ministry of Defense.
DADSTACHE backdoor
DADSTACHE is a sophisticated backdoor malware with capabilities for data exfiltration.
DARKDEW worm
Mandiant associates this with UNC4191, this malware spreads to removable drives.
DBGer Ransomware ransomwarecredential-stealer
The authors of the Satan ransomware have rebranded their "product" and they now go by the name of DBGer ransomware, according to security…
DBatLoader loader
Also known as ModiLoader, NatsoLoader. This Delphi loader misuses Cloud storage services, such as Google Drive to download the Delphi stager component.
DBoxAgent rat
DBoxAgent is a remote access trojan (RAT) that leverages Dropbox as a command and control (C&C) channel to evade detection.
DCHSpy spyware
DCHSpy is an Android spyware likely used by MuddyWater.
DCRAT ratspyware
Also known as DarkCrystal RAT. DCRAT is a variant of the open-source AsyncRAT developed in C# with additional capabilities such as patching Microsoft’s Antimalware Scan…
DCRTR ransomware
DCRTR is a ransomware known for encrypting user data and demanding a ransom for decryption.
DCRTR-WDM ransomware
DCRTR-WDM is a type of ransomware known for encrypting victim files and demanding a ransom for the decryption key.
DCSrv wiperransomware
Also known as DCrSrv. DCSrv is destructive malware that has been used by Moses Staff since at least September 2021.
DCry ransomware
DCry is a ransomware that encrypts victims' files and demands a ransom for decryption.
DDE ransomware
DDE is a form of ransomware that encrypts files on a victim's system, demanding payment for decryption keys.
DDG botnetcryptominer
First activity observed in October 2017. DDG is a botnet with P2P capability that is targeting crypto currency mining (Monero).
DDKONG rat
DDKONG is a malware sample that was part of a campaign by Rancor.
DDKeylogger keylogger
DDKeylogger is a malicious software that records and monitors keystrokes on infected systems.
DEADBOLT ransomware
DEADBOLT is a linux ransomware written in Go, targeting QNAP NAS devices worldwide.
DEADEYE loader
Also known as DEADEYE.EMBED, DEADEYE.APPEND. DEADEYE is a malware launcher that has been used by APT41 since at least May 2021.
DEADWOOD wiper
Also known as Agrius, DETBOSIT, SQLShred. DEADWOOD is wiper malware written in C++ using Boost libraries.
DEATHRANSOM ransomware
Also known as wacatac. DEATHRANSOM is ransomware written in C that has been used since at least 2020, and has potential overlap with FIVEHANDS and HELLOKITTY.
DECAF ransomware
DECAF is a ransomware variant developed in Go, known for its robust encryption and ability to target critical infrastructure sectors.
DEDCryptor ransomware
DEDCryptor is a ransomware variant based on EDA2, designed to encrypt files on infected systems and demand a ransom for decryption keys.
DEEPDATA trojan
According to Volexity, DEEPDATA is a modular post-exploitation tool for Windows that facilitates collection of sensitive information from…
DEEPPOST spywaretrojan
According to Volexity, DEEPPOST is a post-exploitation data exfiltration tool used to send files to a remote system.
DEFENSOR ID trojancredential-stealer
Also known as Defensor Digital. DEFENSOR ID is a banking trojan capable of clearing a victim’s bank account or cryptocurrency wallet and taking over email or social media…
DEWMODE webshell
FireEye discovered the DEWMODE webshell starting mid-December 2020 after exploitation of zero-day vulnerabilities in Accellion's File…
DEcovid19 ransomware
DEcovid19 is a ransomware variant that emerged during the COVID-19 pandemic.
DILLJUICE rat
DILLJUICE is a modified version of the open-source Quasar RAT used by APT10 for cyber-espionage operations.
DISGOMOJI trojan
DISGOMOJI is a Trojan malware with limited information available.
DLRAT rat
DLRAT is a remote access trojan (RAT) used for covert cyber-espionage activities.
DMA Locker ransomware
DMA Locker is a ransomware family that encrypts victims' files and demands a ransom for decryption.
DMA Locker 1.0-2.0-3.0 ransomware
DMA Locker is a ransomware strain that aims to encrypt users' files and demand payment for their release.
DMA Locker 4.0 ransomware
DMA Locker 4.0 is a variant of ransomware designed to encrypt files and demand a ransom from victims.
DMALocker ransomware
Ransomware no extension change Encrypted files have prefix: Version 1: ABCXYZ11 - Version 2: !DMALOCK - Version 3: !DMALOCK3.0 - Version…
DMALocker 3.0 ransomware
DMALocker 3.0 is a ransomware variant that encrypts files on infected machines and demands a ransom payment for decryption.
DMALocker Imposter ransomware
DMALocker Imposter is a ransomware variant known for encrypting files and demanding a ransom for decryption.
DMSniff trojan
DMSniff is a point-of-sale malware previously only privately sold.
DN ransomware
Also known as Fake. It’s directed to English speaking users, therefore is able to infect worldwide.
DNRansomware ransomware
Ransomware Code to decrypt: 83KYG9NW-3K39V-2T3HJ-93F3Q-GT
DNSChanger trojan
DNSChanger is a type of trojan that modifies a computer's DNS settings to direct users to malicious websites.
DNSMessenger rat
Talos recently analyzed an interesting malware sample that made use of DNS TXT record queries and responses to create a bidirectional…
DNSRat rat
Also known as DNSbot. DNSRat is a remote access trojan (RAT) that uses DNS for command and control communication, making it difficult to detect and analyze.
DNSpionage spywaretrojan
Also known as Agent Drable, AgentDrable, Webmask. DNSpionage is a cyber-espionage malware primarily used for conducting surveillance and exfiltrating data.
DOGCALL backdoor
DOGCALL is a backdoor used by APT37 that has been used to target South Korean government and military organizations in 2017.
DONOT spywarerat
Donot malware is a sophisticated, high-level malware toolkit designed to collect and exfiltrate information from vulnerable systems.
DOPLUGS backdoortrojan
DOPLUGS is a backdoor Trojan often employed in cyber-espionage campaigns.
DORRA ransomware
A new ransomware variant has been identified, named DORRA.
DOSTEALER credential-stealerkeyloggerscreen-capture
According to Mandiant, DOSTEALER is a dataminer that mines browser login and cookie data.
DOUBLEBACK backdoor
DOUBLEBACK is a newly discovered fileless malware deployed as part of an attack campaign that took place in December 2020.
DOUBLELOADER loader
DOUBLELOADER is a malware loader known for delivering various payloads in cybercriminal operations.
DOWNIISSA downloader
DOWNIISSA is a shellcode downloader that has been used by MirrorFace since at least 2022 to deploy payloads, including the LODEINFO…
DRAT rat
DRAT is a remote access tool often used for surveillance and unauthorized access to sensitive systems, particularly targeting government…
DRATzarus rat
Also known as ThreatNeedle, ThreatNeedleTea. DRATzarus is a remote access tool (RAT) that has been used by Lazarus Group to target the defense and aerospace organizations globally…
DRIFTPIN backdoorratscreen-capture
Also known as Spy.Agent.ORM, Toshliph. Driftpin is a small and simple backdoor that enables the attackers to assess the victim.
DROPSHOT dropperransomware
DROPSHOT is a malware family known to be associated with ransomware, frequently used as a dropper to deliver various types of ransomware…
DRYHOOK credential-stealer
DRYHOOK is Python script used to steal credentials.
DUBrute credential-stealer
DUBrute is a brute-force malware family known for targeting SSH servers.
DUCKTAIL spywarecredential-stealer
According to Tony Lambert, this is a malware written in .NET.
DUMB Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
DUSTMAN wiper
In 2019, multiple destructive attacks were observed targeting entities within the Middle East.
DUSTPAN dropper
Also known as StealthVector. DUSTPAN is an in-memory dropper written in C/C++ used by APT41 since 2021 that decrypts and executes an embedded payload.
DUSTTRAP backdoorloadertrojan
Also known as CurveLoad, DodgeBox, StealthReacher. DUSTTRAP is a multi-stage plugin framework associated with APT41 operations with multiple components.
DXXD ransomware
DXXD is a ransomware known for encrypting files on a victim's system and demanding ransom payments for decryption.
DYEPACK trojan
Also known as BanSwift, swift. DYEPACK, also known as BanSwift, is a trojan malware specifically targeting the financial services industry.
Dablio Ransomware ransomware
Dablio Ransomware is known for encrypting users' files and demanding a ransom for decryption.
Dacls rat
Dacls is a multi-platform remote access tool used by Lazarus Group since at least December 2019.
Dacls (ELF) rat
According to PCrisk, Dacls is the name of a remote access Trojan (RAT), a malicious program that allows cyber criminals to control…
Dacls (OS X) rat
According to PCrisk, Dacls is the name of a remote access Trojan (RAT), a malicious program that allows cyber criminals to control…
Dacls (Windows) rat
Also known as MATA. According to PCrisk, Dacls is the name of a remote access Trojan (RAT), a malicious program that allows cyber criminals to control…
Dairy
No description available.
Daixin ransomware
Daixin Team is a ransomware and data extortion group active since at least June 2022, known for targeting the healthcare sector, including…
Dale Ransomware ransomware
Also known as DaleLocker Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
Damage Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
DameWare Mini Remote Control rat
Also known as dameware. Affordable remote control software for all your customer support and help desk needs.
DanBot rat
DanBot is a first-stage remote access Trojan written in C# that has been used by HEXANE since at least 2018.
DanaBot trojancredential-stealer
Also known as DanaTools. Proofpoints describes DanaBot as the latest example of malware focused on persistence and stealing useful information that can later be…
DanderSpritz rat
Also known as Dsz. DanderSpritz is a modular remote access tool (RAT) developed by a sophisticated adversary often linked to nation-state cyber-espionage…
Dangerous Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Dante spyware
According to Kaspersky Labs, Dante is the commercial spyware developed by Memento Labs (formerly Hacking Team).
Daolpu trojan
Daolpu is a trojan malware primarily involved in illegal activities such as click fraud and data exfiltration.
Dark botnetworm
Also known as Dark.IoT. Mirai variant exploiting CVE-2021-20090 and CVE2021-35395 for spreading.
Dark DDoSeR ddosbotnet
Dark DDoSeR is a botnet malware primarily used to execute distributed denial-of-service (DDoS) attacks.
Dark Nexus botnetddos
Dark Nexus is a botnet primarily targeting Internet of Things (IoT) devices, using them for distributed denial-of-service (DDoS) attacks.
Dark Power ransomware
Dark Power is a ransomware group first observed in January 2023, known for targeting small to mid-sized organizations across education…
Dark Shades keyloggerspyware
Also known as Rogue. Dark Shades, also known as Rogue, is a malware family known for its keylogging and spyware capabilities.
DarkBit ransomware
DarkBit is a ransomware variant discovered in 2023, known for targeting the education sector and public sector organizations in Iran and…
DarkCloud Stealer credential-stealertrojan
DarkCloud Stealer is credential-stealing malware written in Visual Basic, aimed at extracting sensitive information from infected systems.
DarkComet backdoorratkeylogger
Also known as DarkKomet, Fynloski, Krademok. DarkComet is a Windows remote administration tool and backdoor.
DarkCracks downloader
A sophisticated payload delivery and upgrade framework, discovered in 2024.
DarkEye rat
DarkEye is a sophisticated remote access trojan (RAT) primarily used for cyber-espionage.
DarkGate credential-stealercryptominertrojan
Also known as Meh, MehCrypter. DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber…
DarkHotel ratspywarebackdoor
DarkHotel is an advanced persistent threat group known for its cyber-espionage campaigns.
DarkIRC botnetratcryptominer
DarkIRC is a type of botnet malware that has the capability to establish remote access, deploy cryptominers, and conduct various malicious…
DarkKomet rat
DarkKomet is a remote access trojan (RAT) that facilitates unauthorized access and control over targeted systems.
DarkLoader loader
DarkLoader is a malware framework primarily used to deliver various payloads such as information stealers and ransomware.
DarkLocker ransomware
DarkLocker is a type of ransomware that encrypts files on infected systems, demanding a ransom for decryption.