Malware Families page 14 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- DarkMe rattrojan
- DarkMe is a remote access trojan (RAT) known for targeting government and financial institutions in Eastern Europe and Russia.
- DarkMegi wiper
- DarkMegi is a wiper malware known for destroying data on infected systems.
- DarkPulsar backdoor
- DarkPulsar is a backdoor malware believed to be associated with Russian Advanced Persistent Threat (APT) actors.
- DarkRadiation ransomware
- DarkRadiation is a ransomware family that targets Linux systems.
- DarkRat rat
- DarkRat is a remote access trojan (RAT) known for its ability to stealthily control compromised systems.
- DarkShell botnetddos
- DarkShell is a DDoS bot seemingly of Chinese origin, discovered in 2011.
- DarkSide (ELF) ransomware
- DarkSide is a notorious ransomware that targets large organizations, encrypting their data and demanding a ransom for decryption.
- DarkSide (Windows) ransomware
- Also known as BlackMatter. FireEye describes DARKSIDE as a ransomware written in C and configurable to target files whether on fixed, removable disks, or network…
- DarkStRat rat
- DarkStRat is a remote access trojan (RAT) known for its stealthy deployment and extensive control capabilities.
- DarkTequila credential-stealerkeyloggerspyware
- Dark Tequila is a complex malicious campaign targeting Mexican users, with the primary purpose of stealing financial information, as well…
- DarkTortilla loadertrojan
- DarkTortilla is a highly configurable .NET-based crypter that has been possibly active since at least August 2015.
- DarkTrack rat
- DarkTrack is a Remote Access Trojan (RAT) capable of compromising target systems for espionage and data theft.
- DarkVNC rattrojan
- According to Enigmasoft, DarkVNC malware is a hacking tool that is available for purchase online.
- DarkVision RAT ratkeyloggerscreen-capture
- DarkVision_RAT is a highly customizable Remote Access Trojan (RAT) first identified in 2020.
- DarkWatchman ratkeylogger
- DarkWatchman is a lightweight JavaScript-based remote access tool (RAT) that avoids file operations; it was first observed in November 2021.
- DarkWisp backdoorspyware
- According to Trend Micro, DarkWisp is a PowerShell-based backdoor and reconnaissance utility designed for unauthorized system access and…
- Darkangel ransomware
- Dark Angels is a highly targeted ransomware and data-extortion group that emerged in spring 2022.
- Darkbit01
- TOX: AB33BC51AFAC64D98226826E70B483593C81CB22E6A3B504F7A75348C38C862F00042F5245AC
- Darkmoon
- Also known as Chymine, Dark Moon.
- Darknet RAT rat
- Also known as Dark NET RAT. Darknet RAT is a remote access tool primarily used for cyber espionage.
- DarkoderCryptor ransomware
- DarkoderCryptor is a ransomware known for encrypting files and demanding a ransom for decryption.
- Darkside ransomware
- Also known as BlackMatter. Darkside, the latest ransomware operation to emerge has been attacking organizations beginning earlier this month.
- Darksky botnetddosdownloader
- DarkSky is a botnet that is capable of downloading malware, conducting a number of network and application-layer distributed…
- Darktrack RAT rat
- According to PCrisk, DarkTrack is a malicious program classified as a Remote Access Trojan (RAT).
- DarthMiner cryptominer
- DarthMiner is a known cryptomining malware primarily targeting macOS systems.
- Daserf backdoorspyware
- Also known as Muirim, Nioupale. Daserf is a backdoor that has been used to spy on and steal from Japanese, South Korean, Russian, Singaporean, and Chinese victims.
- DataExfiltrator
- Also known as FileSender. DataExfiltrator is a malware family used to exfiltrate sensitive data from infected systems.
- DataKeeper ransomware
- DataKeeper is a ransomware family known for encrypting victims' files and demanding a ransom payment for decryption.
- Datacloud ransomware
- Datacloud is a type of ransomware that encrypts files on infected systems, demanding payment in exchange for the decryption key.
- Dataleak credential-stealerspyware
- Dataleak is a spyware and credential-stealing malware family known for targeting government and financial sectors to exfiltrate sensitive…
- Datebatut ransomware
- Datebatut is a ransomware family known for encrypting files on victim machines and demanding payment for decryption keys.
- Datper rat
- Datper is a remote access trojan (RAT) primarily used in cyber espionage campaigns.
- DawDropper dropper
- DawDropper is a malware family used as a dropper for banking trojans on Android devices.
- Daxin backdoor
- Also known as DELIMEAT. Symantec describes this as a malware written as Windows kernel driver, used by China-linked threat actors.
- DazzleSpy spywarebackdoor
- DazzleSpy is a sophisticated malware targeting macOS systems primarily in Hong Kong and Macau.
- DcDcrypt ransomware
- Ransomware written in .NET.
- DeCrypt Protect ransomware
- DeCrypt Protect is a ransomware known for encrypting victims' files and demanding payment for decryption keys.
- DeLpHiMoRix trojan
- Also known as DelphiMorix!. DeLpHiMoRix is a trojan known for its use of Delphi programming language.
- DeadSec-Crypto ransomware
- DeadSec-Crypto is a ransomware strain known for encrypting files on victims' systems and demanding cryptocurrency payments for decryption…
- Deadly Ransomware ransomware
- Also known as Deadly for a Good Purpose Ransomware. This is most likely to affect English speaking users, since the note is written in English.
- DealPly
- DealPly is an adware program that primarily manifests as a browser extension.
- DealersChoice exploit-kit
- DealersChoice is a Flash exploitation framework used by APT28.
- DearCry ransomware
- Also known as DoejoCrypt. DearCry, also known as DoejoCrypt, is a ransomware variant observed exploiting vulnerabilities in Microsoft Exchange servers.
- Death Bitches ransomware
- Death Bitches is a ransomware strain that encrypts files on the victim's device, demanding a ransom for decryption.
- DeathHiddenTear (Large&Small HT) > ransomware
- DeathHiddenTear, also known as Large&Small HT, is a ransomware strain derived from the open-source Hidden Tear project.
- DeathNote ransomware
- DeathNote is a ransomware family known for encrypting files on infected systems and demanding a ransom for the decryption key.
- DeathOfShadow ransomware
- DeathOfShadow is a ransomware that encrypts files on infected machines, demanding a ransom for decryption keys.
- DecService ransomware
- DecService is a ransomware that encrypts files on infected systems and demands a ransom for decryption.
- DecYourData ransomware
- DecYourData is a ransomware strain known for encrypting files on victim computers and demanding a ransom for decryption.
- Decebal rat
- Decebal is a remote access tool (RAT) primarily used for espionage activities.
- Decoy Dog RAT rat
- Decoy Dog RAT is a remote access trojan used for covert data exfiltration and command-and-control operations.
- DecryptFox Ransomware ransomware
- Michael Gillespie found a new ransomware uploaded to ID Ransomware that appends the .encr extension and drops a ransom note named…
- DecryptIomega ransomware
- DecryptIomega is a ransomware family known for encrypting files on the victim's system and demanding a ransom for the decryption key.
- Decryption Assistant ransomware
- Decryption Assistant is a form of ransomware that encrypts files on the victim's computer and demands a ransom for decryption.
- DeepCreep rat
- DeepCreep is a sophisticated remote access tool often used by advanced persistent threat groups.
- DeepRAT rat
- DeepRAT is a sophisticated Remote Access Trojan (RAT) focusing on espionage activities.
- Deeper RAT rat
- Deeper RAT is a sophisticated remote access trojan used in cyber-espionage campaigns.
- DeerStealer credential-stealerbotnetrat
- According to Broadcom, DeerStealer is an information stealer written in Delphi and targeting devices running an windows operating system.
- Defender ransomware
- Defender is a ransomware family known for targeting critical industries such as financial services, healthcare, and the public sector.
- Defray ransomware
- Also known as Glushkov. Defray is ransomware that appeared in 2017, and is targeted ransomware, mainly on the healthcare vertical.
- Defray (Glushkov) ransomware
- Defray is a ransomware that targets multiple sectors including healthcare and education, often delivered via phishing emails with…
- Deimos trojanloader
- Described by Elastic as being associated with win.jupyter, and being used in the context of initial access, persistence, and C&C…
- DeimosC2 rat
- Trend Micro describes DeimosC2 as an open-source C&C framework that was released in June 2020.
- DeliveryCheck trojanwebshell
- Also known as CAPIBAR, GAMEDAY. According to CERT-UA, this malware makes use of XSLT (Extensible Stylesheet Language Transformations) and COM-hijacking.
- Delta(Alfa,Bravo, ...)
- Malware known as Delta typically refers to a sample with undefined established characteristics.
- DeltaStealer credential-stealerspyware
- DeltaStealer is a Rust-based infostealer malware designed to exfiltrate sensitive information such as login credentials and potentially…
- Demo ransomware
- Also known as CryptoDemo. Demo, also known as CryptoDemo, is a ransomware that specifically targets and encrypts .jpg files, posing a unique threat to personal and…
- Dendroid rat
- Dendroid is an Android remote access tool (RAT) primarily targeting Western countries.
- Denis backdoortrojan
- Denis is a Windows backdoor and Trojan used by APT32.
- Denonia cryptominer
- Cado discovered this malware, written in Go and targeting AWS Lambda environments.
- Dented botnetcredential-stealertrojan
- Dented is a banking bot written in C. It supports IE, Firefox, Chrome, Opera and Edge and comes with a simple POS grabber. Due to its…
- Deos ransomware
- Deos is a ransomware malware specifically designed to destroy data on infected machines.
- Deprimon downloader
- According to ESET Research, DePriMon is a malicious downloader, with several stages and using many non-traditional techniques.
- Deputy loader
- According to IBM X-Force, this is a loader component for Sheriff.
- DeputyDog backdoor
- DeputyDog is a backdoor linked to a Chinese APT group, primarily used for cyber-espionage targeting government and technology sectors.
- DeriaLock ransomware
- DeriaLock is a ransomware malware that encrypts user files and demands a ransom for decryption.
- DeriaLock Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- DeroHE ransomware
- DeroHE is a ransomware family known for encrypting files and demanding a cryptocurrency ransom.
- Derusbi backdoorrat
- Also known as PHOTO. Derusbi is malware used by multiple Chinese APT groups.
- Derusbi (ELF) backdoorrat
- Derusbi is a backdoor often used by Chinese advanced persistent threat (APT) groups.
- Derusbi (Windows) backdoorkeyloggerscreen-capture
- Also known as PHOTO. A DLL backdoor also reported publicly as “Derusbi”, capable of obtaining directory, file, and drive listing; creating a reverse shell…
- Desert Scorpion spyware
- Desert Scorpion is surveillanceware that has targeted the Middle East, specifically individuals located in Palestine.
- DesertBlade wiper
- According to Microsoft, this was used in a limited destructive malware attack in early March 2022 impacting a single Ukrainian entity.
- Desktop ransomware
- Desktop is a ransomware family known for encrypting files on infected machines and demanding a ransom for decryption.
- DesktopNow
- DesktopNow is a free remote access program from NCH Software.
- Desync ransomware
- This crypto ransomware encrypts enterprise LAN data with AES (ECB mode), and then requires a ransom in # BTC to return the files.
- DetoxCrypto ransomware
- Ransomware - Based on Detox: Calipso, We are all Pokemons, Nullbyte
- DevOpt
- DevOpt is a malware with no currently available description in the database.
- Devil's Rat rat
- Devil's Rat is a remote access Trojan used for espionage, allowing attackers to gain unauthorized access and control over infected systems.
- DevilsTongue spywarerootkit
- According to Microsoft, DevilsTongue is a complex modular multi-threaded piece of malware written in C and C++ with several novel…
- Devos ransomware
- Devos is a ransomware family that targets a variety of industries including education, healthcare, retail, and government.
- Dexbia rat
- Also known as CONIME. Dexbia, also known as CONIME, is a remote access trojan (RAT) used primarily for cyber espionage activities.
- Dexphot cryptominer
- Dexphot is a cryptominer Malware attacking windows machines to gain profit from their resources.
- Dexter credential-stealervirus
- Also known as LusyPOS. Dexter is a computer virus or point of sale malware which infects computers running Microsoft Windows and was discovered by IT security…
- Dharma Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Diamond ransomware
- Diamond is a notorious ransomware family known for targeting multiple industries through phishing campaigns.
- DiamondFox botnetcredential-stealerddos
- Also known as Crystal, Gorynch, Gorynych. According to PCrisk, DiamondFox is highly modular malware offered as malware-as-a-service, and is for sale on various hacker forums.
- Diavol ransomware
- Diavol is a ransomware variant first observed in June 2021 that is capable of prioritizing file types to encrypt based on a pre-configured…
- Digisom ransomware
- Digisom is a ransomware family targeting sectors such as financial services, healthcare, and technology.
- DilmaLocker ransomware
- DilmaLocker is a type of ransomware designed to encrypt files on a victim's system and demand a ransom payment for decryption.