Malware Families page 15 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- DilongTrash downloader
- DilongTrash is a downloader malware primarily used to retrieve and execute additional malicious payloads onto compromised systems.
- Dimnie ratdownloaderkeylogger
- Dimnie is a piece of malware that has been active since 2014, primarily used in targeted attacks.
- DinoTrain downloader
- The DinoTrain malware acts primarily as a downloader, used to fetch and execute additional payloads on infected systems.
- Dipsind backdoor
- Dipsind is a malware family of backdoors that appear to be used exclusively by PLATINUM.
- DirCrypt ransomware
- DirCrypt is a ransomware family known for encrypting files on compromised systems and demanding a ransom payment in exchange for a…
- DirtyDecrypt ransomware
- DirtyDecrypt is a ransomware known for encrypting users' files and demanding payment for the decryption key.
- DirtyMoe botnetcryptominer
- DirtyMoe is a malware family known for its botnet and cryptomining capabilities.
- Disco rat
- Disco is a custom implant that has been used by MoustachedBouncer since at least 2020 including in campaigns using targeted malicious…
- Dishwasher ransomware
- Dishwasher is a ransomware strain known for encrypting users' files and demanding a ransom payment for the decryption key.
- Disk Knight wiper
- Disk Knight is a wiper malware family known for its destructive capabilities, primarily targeting critical infrastructure sectors such as…
- DiskDoctor ransomware
- Also known as Scarab-DiskDoctor. new Scarab Ransomware variant called DiskDoctor that appends the .DiskDoctor extension and drops a ransom note named HOW TO RECOVER…
- Diskpart wiper
- Diskpart is a Windows command-line utility that is used to manage the computer’s drives, which includes disks, partitions, volumes and…
- DispCashBR trojan
- DispCashBR is a malware family targeting ATMs, primarily affecting financial institutions in Brazil.
- DispenserXFS trojanransomware
- DispenserXFS is a malware family known for its trojan and ransomware capabilities, targeting primarily financial and healthcare sectors.
- District ransomware
- District is a ransomware that encrypts files and demands a ransom payment for decryption.
- Divergent botnetloader
- Also known as Novter. Divergent, also known as Novter, is a malware family often utilized to establish botnets.
- Diztakun spywaretrojan
- Diztakun is a malware family known for conducting cyber-espionage activities, primarily targeting government and financial sectors.
- Dizzyvoid backdoorrat
- Also known as Errorroot. Dizzyvoid, also known as Errorroot, is a sophisticated malware family known for its backdoor and remote access Trojan (RAT) capabilities.
- Django ransomware
- Django is a ransomware variant that encrypts files on infected systems and demands a ransom for their decryption.
- Djvu ransomware
- Djvu is a ransomware family that encrypts files on infected systems and demands a ransom payment for decryption.
- DneSpy backdoorspywarescreen-capture
- DneSpy collects information, takes screenshots, and downloads and executes the latest version of other malicious components in the…
- DnsSystem backdoor
- DnsSystem is a .NET based DNS backdoor, which is a customized version of the open source tool DIG.net, that has been used by HEXANE since…
- DoNotChange ransomware
- DoNotChange is a ransomware variant that encrypts user data and demands a ransom for decryption.
- DocSwap trojanspyware
- DocSwap is an Android malware first identified in 2025, and attributed to Kimsuky.
- Dockster backdoor
- Dockster is a backdoor malware known for its use in targeted attacks against organizations, primarily those in the government sector.
- Dodger ransomware
- Dodger is a type of ransomware designed to encrypt files on infected systems and demand a ransom for their decryption.
- Dofloo botnetddoscryptominer
- Also known as AESDDoS. Dofloo (aka AESDDoS) is a popular malware used to create large scale botnets that can launch DDoS attacks and load cryptocurrency miners…
- DogHousePower ransomwaredownloader
- Also known as Shelma. DogHousePower is a PyInstaller-based ransomware targeting web and database servers.
- DogeCrypt ransomware
- DogeCrypt is a ransomware family known for encrypting files and demanding payments in cryptocurrency.
- Dok trojancredential-stealer
- Also known as Retefe. Dok is a Trojan application disguised as a .zip file that is able to collect user credentials and install a malicious proxy server to…
- Dok trojandropper
- Also known as Retefe. Dok a.k.a. Retefe is the macOS version of the banking trojan Retefe. It consists of a codesigned Mach-O dropper usually malspammed in an…
- Doki backdoor
- Doki is a backdoor that uses a unique Dogecoin-based Domain Generation Algorithm and was first observed in July 2020.
- DollyWay downloaderbotnet
- PHP/JavaScript malware for WordPress that injects multi-stage scripts, turning compromised sites into distributed TDS/C2 nodes.
- DolphinTear ransomware
- DolphinTear is a ransomware family known for encrypting victim files and demanding a ransom payment in cryptocurrency.
- Domino ransomware
- Domino is a ransomware variant derived from the open-source project Hidden Tear.
- Donald Trump ransomware
- Donald Trump is a ransomware malware which encrypts files on affected systems, often demanding a ransom for decryption keys.
- Donald Trump 2 Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Donation1 ransomware
- Donation1 is a type of ransomware that encrypts a victim's files and demands a payment for the decryption key.
- Done ransomware
- Done is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
- Dont_Worry ransomware
- Ransomware
- Donut loader
- Donut is an open source framework used to generate position-independent shellcode.
- Donutleaks ransomware
- TOX: D3404141459BC7206CC4AFEC16A3403F262C0937A732C12644E7CA97F0615201A519F7EAB2E2
- DoorMe ratwebshell
- DoorMe is a remote access tool and webshell utilized primarily for cyber espionage activities.
- DoppelDridex credential-stealertrojan
- DoppelDridex is a fork of Indrik Spider's Dridex malware.
- DoppelPaymer ransomware
- Also known as Pay OR Grief. Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files.
- Dorshel trojan
- Dorshel is a trojan malware family that primarily targets financial institutions and technology companies.
- Dosia ddosbotnet
- Also known as DDOSIA. Infrastructure and programs used for, as its name suggests, DDoSing.
- Dot Ransomware ransomware
- Also known as MZP Ransomware. Dot Ransomware, also known as MZP Ransomware, is a type of malicious software designed to encrypt files on a victim's computer, demanding…
- DotNoData ransomware
- DotNoData is a ransomware that encrypts files and demands a ransom for decryption.
- DotRansomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- DotZeroCMD ransomware
- DotZeroCMD is a ransomware that encrypts files on infected machines, demanding a ransom payment for decryption.
- DoubleAgent rat
- DoubleAgent is a family of RAT malware dating back to 2013, known to target groups with contentious relationships with the Chinese…
- DoubleFantasy (ELF) backdoor
- DoubleFantasy is an early-stage implant used for reconnaissance and information gathering by advanced persistent threats, specifically…
- DoubleFantasy (Windows) backdoor
- Also known as VALIDATOR. DoubleFantasy, also known as VALIDATOR, is a backdoor used primarily for initial reconnaissance and validation of targets.
- DoubleFinger loader
- DoubleFinger is a malware loader known for its stealthy distribution methods and modular architecture.
- DoubleLocker ransomware
- DoubleLocker is an Android ransomware that encrypts user data and changes the device's PIN, effectively locking the user out.
- DoublePulsar backdoorrootkit
- DoublePulsar is a backdoor tool used in conjunction with the EternalBlue exploit to enable remote code execution on targeted systems.
- DoubleZero wiper
- Also known as FiberLake. A wiper identified by CERT-UA on March 17th, written in C#.
- DownEx spyware
- According to Bitdefender, this is an exfiltration tool, scanning local and network drives for sensitive files, like documents, archives…
- DownPaper backdoordownloader
- DownPaper is a backdoor Trojan; its main functionality is to download and run second stage malware.
- Downdelph downloader
- Also known as Delphacy, DELPHACY. Downdelph is a first-stage downloader written in Delphi that has been used by APT28 in rare instances between 2013 and 2015.
- Downeks downloaderdropper
- Downeks is a malware family used by threat actors for downloading and dropping additional malicious payloads.
- Dr. Fucker ransomware
- Dr. Fucker is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption. It typically…
- Dr. Jimbo ransomware
- Dr. Jimbo is a sophisticated ransomware family that targets various industries, encrypting files to demand ransoms. It has been known to…
- Dracarys trojanspyware
- Android malware that impersonates genuine applications such as Signal, Telegram, WhatsApp, YouTube, and other chat applications and…
- DracuLoader loader
- Cyber Defense Institute stated that this shellcode PE loader was observed staging win.hemigate.
- DragonBreath backdoorrat
- DragonBreath is a sophisticated malware family often used in cyber-espionage campaigns.
- DragonEgg spywaretrojan
- Also known as LightSpy. DragonEgg is the Android variant of the LightSpy malware family, known for its espionage capabilities.
- Dragoncyber ransomware
- Dragoncyber is a notorious ransomware strain known for targeting a variety of industries, including healthcare and finance, to encrypt…
- Drakos ransomware
- Drakos is a type of ransomware that encrypts files on the victim's system and demands a ransom for decryption.
- DramNudge spywarebackdoor
- DramNudge is a stealthy spyware and backdoor malware known for its use in espionage campaigns targeting government and financial sectors.
- DreamBot credential-stealertrojanbotnet
- 2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) 2014 Dreambot (Gozi ISFB variant) In 2014, a variant of Gozi ISFB was developed.
- DreamBus botnetcryptominer
- DreamBus is a malware family known for its use in crypto-mining and large-scale botnet operations.
- DressCode botnet
- DressCode is an Android malware family known for turning infected devices into nodes of a botnet.
- Dridex trojancredential-stealerbotnet
- Also known as Bugat v5. Dridex is a prolific banking Trojan that first appeared in 2014.
- DriedSister ransomware
- DriedSister is a ransomware family known for targeting various industries including financial services, healthcare, and retail sectors.
- Drinik trojancredential-stealerspyware
- Drinik is an evolving Android banking trojan that was observed targeting customers of around 27 banks in India in August 2021.
- Dripion rat
- Also known as Masson. Dripion, also known as Masson, is a Remote Access Trojan (RAT) primarily used in cyber-espionage campaigns.
- DriveOcean rat
- Also known as Google Drive RAT. DriveOcean, also known as Google Drive RAT, is a remote access trojan that communicates via Google Drive.
- DriveSwitch loader
- According to Cisco Talos, DriveSwitch is a launcher for SilentRaid.
- DroidBot ratkeyloggerspyware
- According to Cleafy, DroidBot is a modern RAT that combines hidden VNC and overlay attack techniques with spyware-like capabilities, such…
- DroidJack rat
- DroidJack is an Android remote access tool that has been observed posing as legitimate applications including the Super Mario Run and…
- DroidLock ransomwareratcredential-stealer
- According to Zimperium, DroidLock has the ability to lock device screens with a ransomware-like overlay and illegally acquire app lock…
- DroidWatcher spywaretrojan
- DroidWatcher is a type of spyware and trojan designed to target Android devices.
- Drokbk backdoor
- Drokbk stands out for its use of the GitHub platform as part of its C&C infrastructure.
- DropBook backdoor
- DropBook is a Python-based backdoor compiled with PyInstaller.
- DropboxC2C rat
- DropboxC2C is a Remote Access Tool (RAT) that utilizes Dropbox for command and control communication, enabling unauthorized access and…
- Drovorub rootkitbackdoor
- Drovorub is a Linux malware toolset comprised of an agent, client, server, and kernel modules, that has been used by APT28.
- Dtrack spywarerat
- Also known as Preft, TroyRAT. Dtrack is spyware that was discovered in 2019 and has been used against Indian financial institutions, research facilities, and the…
- DualShot ransomware
- DualShot is a sophisticated ransomware strain that targets several industries including healthcare, financial services, and the public…
- DualToy trojandropper
- DualToy is Windows malware that installs malicious applications onto Android and iOS devices connected over USB.
- DualToy (Android) trojandownloader
- DualToy is a Trojan primarily targeting Android devices, known for downloading and installing apps from unauthorized sources.
- DualToy (Windows) trojandownloader
- DualToy is a cross-platform malware family that primarily targets Windows systems and has capabilities to infect Android devices.
- DualToy (iOS) downloaderdropper
- DualToy is a family of malware primarily targeting Android and iOS devices.
- Dumador botnet
- Dumador is a malware family known for its botnet capabilities, used to control and exploit infected systems.
- Dummy
- Dummy is a placeholder or example malware name often used in documentation or testing.
- DummyEncrypter Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- DummyLocker ransomware
- DummyLocker is a ransomware variant that encrypts files on the victim's machine, demanding a ransom for decryption.
- Duqu backdoorspyware
- Duqu is a malware platform that uses a modular approach to extend functionality after deployment within a target network.
- Dusk ransomware
- Dusk is a type of ransomware known for encrypting user data and demanding payment for decryption.