Malware Families page 16 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- DustyHammock backdoordownloader
- According to Proofpoint, DustyHammock is a minimalist backdoor that can run commands via cmd.exe, as well as download and execute…
- DustySky spywareworm
- Also known as NeD Worm. DustySky is multi-stage malware written in .NET that has been used by Molerats since May 2015.
- Duuzer rat
- Also known as Escad. Duuzer, also known as Escad, is a Remote Access Trojan (RAT) primarily targeting South Korean entities.
- Dviide ransomware
- Dviide is a ransomware family known for encrypting files on infected systems and demanding payment for decryption.
- Dvmap rootkit
- Dvmap is rooting malware that injects malicious code into system runtime libraries.
- DynA-Crypt Ransomware ransomware
- Also known as DynA CryptoLocker Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- DynamicRAT ratddos
- Also known as DYNARAT. DynamicRAT is a malware that is spread via email attachments and compromises the security of computer systems.
- DynamicStealer credential-stealer
- Dynamic Stealer is a Github Project C# written code by L1ghtN4n.
- DynoWiper wiper
- DynoWiper is a destructive malware associated with the 2025 Poland Wiper Attacks in December of 2025.
- Dyre trojancredential-stealer
- Also known as Dyzap, Dyreza. Dyre is a banking Trojan that has been used for financial gain.
- EASYNIGHT loader
- FireEye describes EASYNIGHT is a loader observed used with several malware families, including HIGHNOON and HIGHNOON.LITE.
- ECCENTRICBANDWAGON ratkeyloggerscreen-capture
- ECCENTRICBANDWAGON is a remote access Trojan (RAT) used by North Korean cyber actors that was first identified in August 2020.
- ECLR ransomware
- ECLR is a type of ransomware that encrypts files on a victim's computer, demanding a ransom for decryption.
- EDA2 ransomware
- EDA2 is a successor of HiddenTear. Just like HiddenTear it was developed as an open-source project by a security researcher and published…
- EDDIESTEALER credential-stealer
- According to Elastic Security Labs, this is a newly discovered Rust infostealer targeting Windows hosts, which receives a task list from…
- EDRSilencer trojanspyware
- Trend Micro describes EDRSilencer as a red team tool originally designed to interfere with endpoint detection and response solutions via…
- EHDevel rat
- EHDevel is a remote access trojan (RAT) utilized by threat actors, primarily targeting government and telecommunications sectors.
- EKANS
- Also known as SNAKEHOSE. EKANS is ransomware that was first seen December 2019 and later reported to have impacted operations at Honda automotive production…
- EKANS ransomware
- Also known as SNAKEHOSE. EKANS is ransomware variant written in Golang that first appeared in mid-December 2019 and has been used against multiple sectors…
- ELECTRICFISH trojan
- The application is a command-line utility and its primary purpose is to tunnel traffic between two IP addresses.
- ELMER backdoor
- Also known as Elmost. ELMER is a non-persistent, proxy-aware HTTP backdoor written in Delphi that has been used by APT16.
- EOEO ransomware
- Ransomware
- EPICALLY ransomware
- EPICALLY is a type of ransomware known for encrypting user files and demanding a ransom for decryption.
- EQ Ransomware ransomware
- GrujaRS discovered the EQ Ransomware that drops a ransom note named README_BACK_FILES.htm and uses .f**k (censored) as its extension for…
- ERMAC trojancredential-stealer
- According to Intel471, ERMAC, an Android banking trojan enables bad actors to determine when certain apps are launched and then overwrites…
- ESPecter rootkit
- ESPecter is a rootkit malware utilized by threat actors to carry out covert surveillance and data exfiltration operations.
- ESXiArgs ransomware
- ESXiArgs is ransomware specifically designed to target ESXi servers.
- EVILNUM backdoorrat
- EVILNUM is fully capable backdoor that was first identified in 2018.
- EVILNUM (Javascript) backdoordownloader
- According proofpoint, EvilNum is a backdoor that can be used for data theft or to load additional payloads.
- EVILNUM (Windows) trojancredential-stealerspyware
- EVILNUM is a malware family that primarily targets the financial services sector, often aiming to steal credentials and financial data.
- EYService backdoor
- EYService is the main part of the backdoor used by Nazar APT.
- EZDZ ransomware
- Ezdz is a ransomware strain known for its encryption tactics and targeting multiple industries, particularly those dealing with sensitive…
- EagerBee loaderbackdoor
- Also known as Thumtais. According to Elastic, EagerBee loads additional capabilities using remotely-downloaded PE files, hosted in C2.
- EagleMonitorRAT rat
- This RAT written in C# was derived from HorusEyesRat.
- EagleMsgSpy spywarescreen-capture
- According to Lookout, EagleMsgSpy is a lawful intercept surveillance tool developed by a Chinese software development company with use by…
- Earthworm webshell
- According to Cisco Talos, Earthworm is network tunneling tool that has extensively been used by Chinese-speaking threat actors in…
- Easy Stealer credential-stealertrojan
- Easy Stealer is a new information stealer written in Golang that is under active development.
- EbolaRnsmwr ransomware
- EbolaRnsmwr is a ransomware targeting multiple sectors, predominantly impacting healthcare, financial services, and government entities.
- Ebury backdoorbotnetcredential-stealer
- Ebury is an OpenSSH backdoor and credential stealer targeting Linux servers and container hosts developed by Windigo.
- Echelon credential-stealer
- Also known as Echelon-Stealer. Echelon is a credential-stealer malware family known to target financial and technology sectors, stealing sensitive information such as…
- EchoGather spyware
- According to Intezer, the malware gathers system information and transmits this via (proxy-aware) HTTP requests.
- Echobot botnetworm
- The latest in this long line of Mirai scourges is a new variant named Echobot.
- Ecipekac loader
- Also known as HEAVYHAND, SigLoader, DESLoader. Ecipekac is a multi-layer loader that has been used by menuPass since at least 2019 including use as a loader for P8RAT, SodaMaster, and…
- Edam dropperdownloader
- Also known as SECONDBEST. According to Orange Cyberdefense, Edam is written in C++ and its PDB path indicates it is called "droper_dll".
- EdgeLocker ransomwaretrojan
- It’s directed to English speaking users, therefore is able to infect worldwide.
- EdgeStepper downloader
- According to ESET Research, EdgeStepper is an adversary-in-the-middle tool, which forwards DNS traffic from machines in a targeted network…
- EduCrypt ransomware
- Also known as EduCrypter. EduCrypt is a form of ransomware based on the Hidden Tear project.
- EduRansom ransomware
- EduRansom is a ransomware primarily targeting educational institutions.
- Egalyty ransomware
- Egalyty is a ransomware strain known for targeting critical sectors such as healthcare and financial services.
- EggLocker ransomware
- EggLocker is a ransomware that encrypts files on infected systems, demanding a ransom payment for decryption.
- EggShell RAT ratkeyloggerscreen-capture
- EggShell RAT is a remote access tool primarily targeting macOS systems, but also capable of running on Linux and Windows.
- Egregor ransomware
- Egregor is a Ransomware-as-a-Service (RaaS) tool that was first observed in September 2020.
- EiTest downloaderransomware
- EiTest is a malware campaign known for distributing different types of malware, primarily through exploit kits and malvertising.
- Ekati demo tool ransomware
- Ekati demo tool is a type of ransomware used in cyber attacks to encrypt victim's files and demand a ransom for decryption.
- Ekipa RAT rat
- Ekipa RAT is a sophisticated Remote Access Trojan used for cyberespionage.
- El Machete APT Backdoor Dropper dropperbackdoor
- This dropper masquerades itself as Adobe software, titled as Adobe.msi.
- El-Polocker ransomware
- Also known as Los Pollos Hermanos. El-Polocker, also known as Los Pollos Hermanos, is a ransomware strain featuring a graphical user interface, used predominantly to target…
- Eleanor ratwebshell
- Eleanor comes as a drag-and-drop file utility called EasyDoc Converter.
- ElectricPowder backdoor
- ElectricPowder is a sophisticated piece of malware primarily used for espionage.
- ElectroRAT rat
- According to PCrisk, ElectroRAT is a Remote Access Trojan (RAT) written in the Go programming language and designed to target Windows…
- Elevator backdoor
- Elevator is a sophisticated backdoor utilized primarily by advanced persistent threat groups for cyber espionage activities.
- Elibomi trojan
- Also known as Drinik. Elibomi, also known as Drinik, is a banking trojan primarily targeting users in India.
- Elirks backdoortrojan
- Elirks is a basic backdoor Trojan, first discovered in 2010, that is primarily used to steal information from compromised systems.
- Elise backdoortrojan
- Also known as BKDR_ESILE, Page, EVILNEST. Elise is a custom backdoor Trojan that appears to be used exclusively by Lotus Blossom.
- ElizaRAT rat
- ElizaRAT is a remote access trojan designed to facilitate unauthorized access and control over compromised systems.
- Embargo ransomwareloader
- Embargo is a ransomware variant written in Rust that has been active since at least May 2024.
- Emdivi rat
- Emdivi is a remote access trojan primarily targeting Japanese organizations.
- Emissary trojan
- Emissary is a Trojan that has been used by Lotus Blossom.
- Emmenhtal loaderdropperrat
- Also known as IDATDropper, PEAKLIGHT. Emmenhtal is a malicious loader likely distributed since early 2024, and publicly detailed by Orange Cyberdefense CERT in August 2024.
- Emotet botnetdownloadertrojan
- Also known as Geodo, Heodo. Emotet is a modular malware variant which is primarily used as a downloader for other malware variants such as TrickBot and IcedID.
- Empire ratbackdoor
- Also known as EmPyre, PowerShell Empire. Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub.
- Empire Downloader downloader
- Empire Downloader is a PowerShell-based malware primarily used to download and execute additional payloads.
- Empyrean credential-stealer
- Discord Stealer written in Python with Javascript-based inject files.
- Emudbot worm
- Supposedly a worm that was active around 2012-2013.
- EnCrypt ransomware
- EnCrypt is a type of ransomware designed to encrypt files on a victim's computer, demanding a ransom to restore access.
- Enc1 ransomware
- Enc1 is a ransomware that encrypts user files and demands a ransom for decryption.
- Encoder.xxxx ransomware
- Also known as Trojan.Encoder.6491. Encoder.xxxx is a ransomware coded in Go, also known as Trojan.Encoder.6491.
- EncoderCSL ransomware
- EncoderCSL is a type of ransomware that encrypts victim files and demands a ransom for decryption keys.
- EncrypTile Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- EncryptServer2018 ransomware
- EncryptServer2018 is a ransomware family known for targeting various sectors, encrypting files, and demanding a ransom for decryption.
- EncryptedBatch ransomware
- EncryptedBatch is a ransomware family known for encrypting files on infected systems and demanding a ransom from victims.
- Encryptss77 Ransomware ransomware
- Also known as SFX Monster Ransomware. This is most likely to affect English speaking users, since the note is written in English.
- Endurance wiperransomware
- Endurance is a destructive ransomware variant first observed in 2023, developed and operated by the threat actor known as IntelBroker…
- EnemyBot botnetddos
- According to the Infosec Institute, EnemyBot is a dangerous IoT botnet that has made headlines in the last few weeks.
- Enigma ransomware
- Enigma is a ransomware that encrypts files on the victim's system, demanding a ransom to restore access.
- Enigma 2 Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Enigma Loader downloaderloader
- According to Trend Micro, this is a downloader, dedicated to stage execution of a second stage malware called Enigma Stealer.
- Enjey ransomware
- Enjey is a ransomware based on the RemindMe ransomware.
- EnjeyCrypter Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- EnkripsiPC Ransomware ransomware
- Also known as IDRANSOMv3, Manifestus. It’s directed to English speaking users, therefore is able to infect worldwide.
- Enrume ransomware
- Also known as Ransom32. Enrume, also known as Ransom32, is a JavaScript-based ransomware that operates cross-platform.
- Ensiko webshellransomware
- Ensiko is a ransomware variant often delivered as a webshell, used to encrypt files and demand a ransom.
- Ensikology webshellcryptominer
- Also known as Ensiko. Ensikology, also known as Ensiko, is a PHP web shell that possesses sophisticated capabilities including cryptocurrency mining and serving…
- Entropy ransomware
- Entropy is a ransomware first seen in 1st quarter of 2022, is being used in conjunction of Dridex infection.
- EntryShell backdoor
- Fileless malware 'EntryShell', a variant of the KeyBoy malware, due to similarities in backdoor command IDs and debug messages with old…
- Enviserv backdoor
- According to Microsoft, Enviserv is a malicious program that is unable to spread of its own accord.
- EnvyScout dropper
- Also known as ROOTSAW. EnvyScout is a dropper that has been used by APT29 since at least 2021.
- EnyBeny Nuclear Ransomware ransomware
- @GrujaRS discovered a new in-dev ransomware called EnyBeny Nuclear Ransomware that meant to append the extension .PERSONAL_ID:.Nuclear to…
- EnyBenyHorsuke Ransomware ransomware
- GrujaRS discovered a new ransomware called EnyBenyHorsuke Ransomware that appends the .Horsuke extension to encrypted files.
- EnybenyCrypt ransomware
- EnybenyCrypt is a type of ransomware that encrypts a victim's files and demands a ransom in return for the decryption key.