Malware Families page 14 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

DarkMe rattrojan
DarkMe is a remote access trojan (RAT) known for targeting government and financial institutions in Eastern Europe and Russia.
DarkMegi wiper
DarkMegi is a wiper malware known for destroying data on infected systems.
DarkPulsar backdoor
DarkPulsar is a backdoor malware believed to be associated with Russian Advanced Persistent Threat (APT) actors.
DarkRadiation ransomware
DarkRadiation is a ransomware family that targets Linux systems.
DarkRat rat
DarkRat is a remote access trojan (RAT) known for its ability to stealthily control compromised systems.
DarkShell botnetddos
DarkShell is a DDoS bot seemingly of Chinese origin, discovered in 2011.
DarkSide (ELF) ransomware
DarkSide is a notorious ransomware that targets large organizations, encrypting their data and demanding a ransom for decryption.
DarkSide (Windows) ransomware
Also known as BlackMatter. FireEye describes DARKSIDE as a ransomware written in C and configurable to target files whether on fixed, removable disks, or network…
DarkStRat rat
DarkStRat is a remote access trojan (RAT) known for its stealthy deployment and extensive control capabilities.
DarkTequila credential-stealerkeyloggerspyware
Dark Tequila is a complex malicious campaign targeting Mexican users, with the primary purpose of stealing financial information, as well…
DarkTortilla loadertrojan
DarkTortilla is a highly configurable .NET-based crypter that has been possibly active since at least August 2015.
DarkTrack rat
DarkTrack is a Remote Access Trojan (RAT) capable of compromising target systems for espionage and data theft.
DarkVNC rattrojan
According to Enigmasoft, DarkVNC malware is a hacking tool that is available for purchase online.
DarkVision RAT ratkeyloggerscreen-capture
DarkVision_RAT is a highly customizable Remote Access Trojan (RAT) first identified in 2020.
DarkWatchman ratkeylogger
DarkWatchman is a lightweight JavaScript-based remote access tool (RAT) that avoids file operations; it was first observed in November 2021.
DarkWisp backdoorspyware
According to Trend Micro, DarkWisp is a PowerShell-based backdoor and reconnaissance utility designed for unauthorized system access and…
Darkangel ransomware
Dark Angels is a highly targeted ransomware and data-extortion group that emerged in spring 2022.
Darkbit01
TOX: AB33BC51AFAC64D98226826E70B483593C81CB22E6A3B504F7A75348C38C862F00042F5245AC
Darkmoon
Also known as Chymine, Dark Moon.
Darknet RAT rat
Also known as Dark NET RAT. Darknet RAT is a remote access tool primarily used for cyber espionage.
DarkoderCryptor ransomware
DarkoderCryptor is a ransomware known for encrypting files and demanding a ransom for decryption.
Darkside ransomware
Also known as BlackMatter. Darkside, the latest ransomware operation to emerge has been attacking organizations beginning earlier this month.
Darksky botnetddosdownloader
DarkSky is a botnet that is capable of downloading malware, conducting a number of network and application-layer distributed…
Darktrack RAT rat
According to PCrisk, DarkTrack is a malicious program classified as a Remote Access Trojan (RAT).
DarthMiner cryptominer
DarthMiner is a known cryptomining malware primarily targeting macOS systems.
Daserf backdoorspyware
Also known as Muirim, Nioupale. Daserf is a backdoor that has been used to spy on and steal from Japanese, South Korean, Russian, Singaporean, and Chinese victims.
DataExfiltrator
Also known as FileSender. DataExfiltrator is a malware family used to exfiltrate sensitive data from infected systems.
DataKeeper ransomware
DataKeeper is a ransomware family known for encrypting victims' files and demanding a ransom payment for decryption.
Datacloud ransomware
Datacloud is a type of ransomware that encrypts files on infected systems, demanding payment in exchange for the decryption key.
Dataleak credential-stealerspyware
Dataleak is a spyware and credential-stealing malware family known for targeting government and financial sectors to exfiltrate sensitive…
Datebatut ransomware
Datebatut is a ransomware family known for encrypting files on victim machines and demanding payment for decryption keys.
Datper rat
Datper is a remote access trojan (RAT) primarily used in cyber espionage campaigns.
DawDropper dropper
DawDropper is a malware family used as a dropper for banking trojans on Android devices.
Daxin backdoor
Also known as DELIMEAT. Symantec describes this as a malware written as Windows kernel driver, used by China-linked threat actors.
DazzleSpy spywarebackdoor
DazzleSpy is a sophisticated malware targeting macOS systems primarily in Hong Kong and Macau.
DcDcrypt ransomware
Ransomware written in .NET.
DeCrypt Protect ransomware
DeCrypt Protect is a ransomware known for encrypting victims' files and demanding payment for decryption keys.
DeLpHiMoRix trojan
Also known as DelphiMorix!. DeLpHiMoRix is a trojan known for its use of Delphi programming language.
DeadSec-Crypto ransomware
DeadSec-Crypto is a ransomware strain known for encrypting files on victims' systems and demanding cryptocurrency payments for decryption…
Deadly Ransomware ransomware
Also known as Deadly for a Good Purpose Ransomware. This is most likely to affect English speaking users, since the note is written in English.
DealPly
DealPly is an adware program that primarily manifests as a browser extension.
DealersChoice exploit-kit
DealersChoice is a Flash exploitation framework used by APT28.
DearCry ransomware
Also known as DoejoCrypt. DearCry, also known as DoejoCrypt, is a ransomware variant observed exploiting vulnerabilities in Microsoft Exchange servers.
Death Bitches ransomware
Death Bitches is a ransomware strain that encrypts files on the victim's device, demanding a ransom for decryption.
DeathHiddenTear (Large&Small HT) > ransomware
DeathHiddenTear, also known as Large&Small HT, is a ransomware strain derived from the open-source Hidden Tear project.
DeathNote ransomware
DeathNote is a ransomware family known for encrypting files on infected systems and demanding a ransom for the decryption key.
DeathOfShadow ransomware
DeathOfShadow is a ransomware that encrypts files on infected machines, demanding a ransom for decryption keys.
DecService ransomware
DecService is a ransomware that encrypts files on infected systems and demands a ransom for decryption.
DecYourData ransomware
DecYourData is a ransomware strain known for encrypting files on victim computers and demanding a ransom for decryption.
Decebal rat
Decebal is a remote access tool (RAT) primarily used for espionage activities.
Decoy Dog RAT rat
Decoy Dog RAT is a remote access trojan used for covert data exfiltration and command-and-control operations.
DecryptFox Ransomware ransomware
Michael Gillespie found a new ransomware uploaded to ID Ransomware that appends the .encr extension and drops a ransom note named…
DecryptIomega ransomware
DecryptIomega is a ransomware family known for encrypting files on the victim's system and demanding a ransom for the decryption key.
Decryption Assistant ransomware
Decryption Assistant is a form of ransomware that encrypts files on the victim's computer and demands a ransom for decryption.
DeepCreep rat
DeepCreep is a sophisticated remote access tool often used by advanced persistent threat groups.
DeepRAT rat
DeepRAT is a sophisticated Remote Access Trojan (RAT) focusing on espionage activities.
Deeper RAT rat
Deeper RAT is a sophisticated remote access trojan used in cyber-espionage campaigns.
DeerStealer credential-stealerbotnetrat
According to Broadcom, DeerStealer is an information stealer written in Delphi and targeting devices running an windows operating system.
Defender ransomware
Defender is a ransomware family known for targeting critical industries such as financial services, healthcare, and the public sector.
Defray ransomware
Also known as Glushkov. Defray is ransomware that appeared in 2017, and is targeted ransomware, mainly on the healthcare vertical.
Defray (Glushkov) ransomware
Defray is a ransomware that targets multiple sectors including healthcare and education, often delivered via phishing emails with…
Deimos trojanloader
Described by Elastic as being associated with win.jupyter, and being used in the context of initial access, persistence, and C&C…
DeimosC2 rat
Trend Micro describes DeimosC2 as an open-source C&C framework that was released in June 2020.
DeliveryCheck trojanwebshell
Also known as CAPIBAR, GAMEDAY. According to CERT-UA, this malware makes use of XSLT (Extensible Stylesheet Language Transformations) and COM-hijacking.
Delta(Alfa,Bravo, ...)
Malware known as Delta typically refers to a sample with undefined established characteristics.
DeltaStealer credential-stealerspyware
DeltaStealer is a Rust-based infostealer malware designed to exfiltrate sensitive information such as login credentials and potentially…
Demo ransomware
Also known as CryptoDemo. Demo, also known as CryptoDemo, is a ransomware that specifically targets and encrypts .jpg files, posing a unique threat to personal and…
Dendroid rat
Dendroid is an Android remote access tool (RAT) primarily targeting Western countries.
Denis backdoortrojan
Denis is a Windows backdoor and Trojan used by APT32.
Denonia cryptominer
Cado discovered this malware, written in Go and targeting AWS Lambda environments.
Dented botnetcredential-stealertrojan
Dented is a banking bot written in C. It supports IE, Firefox, Chrome, Opera and Edge and comes with a simple POS grabber. Due to its…
Deos ransomware
Deos is a ransomware malware specifically designed to destroy data on infected machines.
Deprimon downloader
According to ESET Research, DePriMon is a malicious downloader, with several stages and using many non-traditional techniques.
Deputy loader
According to IBM X-Force, this is a loader component for Sheriff.
DeputyDog backdoor
DeputyDog is a backdoor linked to a Chinese APT group, primarily used for cyber-espionage targeting government and technology sectors.
DeriaLock ransomware
DeriaLock is a ransomware malware that encrypts user files and demands a ransom for decryption.
DeriaLock Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
DeroHE ransomware
DeroHE is a ransomware family known for encrypting files and demanding a cryptocurrency ransom.
Derusbi backdoorrat
Also known as PHOTO. Derusbi is malware used by multiple Chinese APT groups.
Derusbi (ELF) backdoorrat
Derusbi is a backdoor often used by Chinese advanced persistent threat (APT) groups.
Derusbi (Windows) backdoorkeyloggerscreen-capture
Also known as PHOTO. A DLL backdoor also reported publicly as “Derusbi”, capable of obtaining directory, file, and drive listing; creating a reverse shell…
Desert Scorpion spyware
Desert Scorpion is surveillanceware that has targeted the Middle East, specifically individuals located in Palestine.
DesertBlade wiper
According to Microsoft, this was used in a limited destructive malware attack in early March 2022 impacting a single Ukrainian entity.
Desktop ransomware
Desktop is a ransomware family known for encrypting files on infected machines and demanding a ransom for decryption.
DesktopNow
DesktopNow is a free remote access program from NCH Software.
Desync ransomware
This crypto ransomware encrypts enterprise LAN data with AES (ECB mode), and then requires a ransom in # BTC to return the files.
DetoxCrypto ransomware
Ransomware - Based on Detox: Calipso, We are all Pokemons, Nullbyte
DevOpt
DevOpt is a malware with no currently available description in the database.
Devil's Rat rat
Devil's Rat is a remote access Trojan used for espionage, allowing attackers to gain unauthorized access and control over infected systems.
DevilsTongue spywarerootkit
According to Microsoft, DevilsTongue is a complex modular multi-threaded piece of malware written in C and C++ with several novel…
Devos ransomware
Devos is a ransomware family that targets a variety of industries including education, healthcare, retail, and government.
Dexbia rat
Also known as CONIME. Dexbia, also known as CONIME, is a remote access trojan (RAT) used primarily for cyber espionage activities.
Dexphot cryptominer
Dexphot is a cryptominer Malware attacking windows machines to gain profit from their resources.
Dexter credential-stealervirus
Also known as LusyPOS. Dexter is a computer virus or point of sale malware which infects computers running Microsoft Windows and was discovered by IT security…
Dharma Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Diamond ransomware
Diamond is a notorious ransomware family known for targeting multiple industries through phishing campaigns.
DiamondFox botnetcredential-stealerddos
Also known as Crystal, Gorynch, Gorynych. According to PCrisk, DiamondFox is highly modular malware offered as malware-as-a-service, and is for sale on various hacker forums.
Diavol ransomware
Diavol is a ransomware variant first observed in June 2021 that is capable of prioritizing file types to encrypt based on a pre-configured…
Digisom ransomware
Digisom is a ransomware family targeting sectors such as financial services, healthcare, and technology.
DilmaLocker ransomware
DilmaLocker is a type of ransomware designed to encrypt files on a victim's system and demand a ransom payment for decryption.