Malware Families page 16 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

DustyHammock backdoordownloader
According to Proofpoint, DustyHammock is a minimalist backdoor that can run commands via cmd.exe, as well as download and execute…
DustySky spywareworm
Also known as NeD Worm. DustySky is multi-stage malware written in .NET that has been used by Molerats since May 2015.
Duuzer rat
Also known as Escad. Duuzer, also known as Escad, is a Remote Access Trojan (RAT) primarily targeting South Korean entities.
Dviide ransomware
Dviide is a ransomware family known for encrypting files on infected systems and demanding payment for decryption.
Dvmap rootkit
Dvmap is rooting malware that injects malicious code into system runtime libraries.
DynA-Crypt Ransomware ransomware
Also known as DynA CryptoLocker Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
DynamicRAT ratddos
Also known as DYNARAT. DynamicRAT is a malware that is spread via email attachments and compromises the security of computer systems.
DynamicStealer credential-stealer
Dynamic Stealer is a Github Project C# written code by L1ghtN4n.
DynoWiper wiper
DynoWiper is a destructive malware associated with the 2025 Poland Wiper Attacks in December of 2025.
Dyre trojancredential-stealer
Also known as Dyzap, Dyreza. Dyre is a banking Trojan that has been used for financial gain.
EASYNIGHT loader
FireEye describes EASYNIGHT is a loader observed used with several malware families, including HIGHNOON and HIGHNOON.LITE.
ECCENTRICBANDWAGON ratkeyloggerscreen-capture
ECCENTRICBANDWAGON is a remote access Trojan (RAT) used by North Korean cyber actors that was first identified in August 2020.
ECLR ransomware
ECLR is a type of ransomware that encrypts files on a victim's computer, demanding a ransom for decryption.
EDA2 ransomware
EDA2 is a successor of HiddenTear. Just like HiddenTear it was developed as an open-source project by a security researcher and published…
EDDIESTEALER credential-stealer
According to Elastic Security Labs, this is a newly discovered Rust infostealer targeting Windows hosts, which receives a task list from…
EDRSilencer trojanspyware
Trend Micro describes EDRSilencer as a red team tool originally designed to interfere with endpoint detection and response solutions via…
EHDevel rat
EHDevel is a remote access trojan (RAT) utilized by threat actors, primarily targeting government and telecommunications sectors.
EKANS
Also known as SNAKEHOSE. EKANS is ransomware that was first seen December 2019 and later reported to have impacted operations at Honda automotive production…
EKANS ransomware
Also known as SNAKEHOSE. EKANS is ransomware variant written in Golang that first appeared in mid-December 2019 and has been used against multiple sectors…
ELECTRICFISH trojan
The application is a command-line utility and its primary purpose is to tunnel traffic between two IP addresses.
ELMER backdoor
Also known as Elmost. ELMER is a non-persistent, proxy-aware HTTP backdoor written in Delphi that has been used by APT16.
EOEO ransomware
Ransomware
EPICALLY ransomware
EPICALLY is a type of ransomware known for encrypting user files and demanding a ransom for decryption.
EQ Ransomware ransomware
GrujaRS discovered the EQ Ransomware that drops a ransom note named README_BACK_FILES.htm and uses .f**k (censored) as its extension for…
ERMAC trojancredential-stealer
According to Intel471, ERMAC, an Android banking trojan enables bad actors to determine when certain apps are launched and then overwrites…
ESPecter rootkit
ESPecter is a rootkit malware utilized by threat actors to carry out covert surveillance and data exfiltration operations.
ESXiArgs ransomware
ESXiArgs is ransomware specifically designed to target ESXi servers.
EVILNUM backdoorrat
EVILNUM is fully capable backdoor that was first identified in 2018.
EVILNUM (Javascript) backdoordownloader
According proofpoint, EvilNum is a backdoor that can be used for data theft or to load additional payloads.
EVILNUM (Windows) trojancredential-stealerspyware
EVILNUM is a malware family that primarily targets the financial services sector, often aiming to steal credentials and financial data.
EYService backdoor
EYService is the main part of the backdoor used by Nazar APT.
EZDZ ransomware
Ezdz is a ransomware strain known for its encryption tactics and targeting multiple industries, particularly those dealing with sensitive…
EagerBee loaderbackdoor
Also known as Thumtais. According to Elastic, EagerBee loads additional capabilities using remotely-downloaded PE files, hosted in C2.
EagleMonitorRAT rat
This RAT written in C# was derived from HorusEyesRat.
EagleMsgSpy spywarescreen-capture
According to Lookout, EagleMsgSpy is a lawful intercept surveillance tool developed by a Chinese software development company with use by…
Earthworm webshell
According to Cisco Talos, Earthworm is network tunneling tool that has extensively been used by Chinese-speaking threat actors in…
Easy Stealer credential-stealertrojan
Easy Stealer is a new information stealer written in Golang that is under active development.
EbolaRnsmwr ransomware
EbolaRnsmwr is a ransomware targeting multiple sectors, predominantly impacting healthcare, financial services, and government entities.
Ebury backdoorbotnetcredential-stealer
Ebury is an OpenSSH backdoor and credential stealer targeting Linux servers and container hosts developed by Windigo.
Echelon credential-stealer
Also known as Echelon-Stealer. Echelon is a credential-stealer malware family known to target financial and technology sectors, stealing sensitive information such as…
EchoGather spyware
According to Intezer, the malware gathers system information and transmits this via (proxy-aware) HTTP requests.
Echobot botnetworm
The latest in this long line of Mirai scourges is a new variant named Echobot.
Ecipekac loader
Also known as HEAVYHAND, SigLoader, DESLoader. Ecipekac is a multi-layer loader that has been used by menuPass since at least 2019 including use as a loader for P8RAT, SodaMaster, and…
Edam dropperdownloader
Also known as SECONDBEST. According to Orange Cyberdefense, Edam is written in C++ and its PDB path indicates it is called "droper_dll".
EdgeLocker ransomwaretrojan
It’s directed to English speaking users, therefore is able to infect worldwide.
EdgeStepper downloader
According to ESET Research, EdgeStepper is an adversary-in-the-middle tool, which forwards DNS traffic from machines in a targeted network…
EduCrypt ransomware
Also known as EduCrypter. EduCrypt is a form of ransomware based on the Hidden Tear project.
EduRansom ransomware
EduRansom is a ransomware primarily targeting educational institutions.
Egalyty ransomware
Egalyty is a ransomware strain known for targeting critical sectors such as healthcare and financial services.
EggLocker ransomware
EggLocker is a ransomware that encrypts files on infected systems, demanding a ransom payment for decryption.
EggShell RAT ratkeyloggerscreen-capture
EggShell RAT is a remote access tool primarily targeting macOS systems, but also capable of running on Linux and Windows.
Egregor ransomware
Egregor is a Ransomware-as-a-Service (RaaS) tool that was first observed in September 2020.
EiTest downloaderransomware
EiTest is a malware campaign known for distributing different types of malware, primarily through exploit kits and malvertising.
Ekati demo tool ransomware
Ekati demo tool is a type of ransomware used in cyber attacks to encrypt victim's files and demand a ransom for decryption.
Ekipa RAT rat
Ekipa RAT is a sophisticated Remote Access Trojan used for cyberespionage.
El Machete APT Backdoor Dropper dropperbackdoor
This dropper masquerades itself as Adobe software, titled as Adobe.msi.
El-Polocker ransomware
Also known as Los Pollos Hermanos. El-Polocker, also known as Los Pollos Hermanos, is a ransomware strain featuring a graphical user interface, used predominantly to target…
Eleanor ratwebshell
Eleanor comes as a drag-and-drop file utility called EasyDoc Converter.
ElectricPowder backdoor
ElectricPowder is a sophisticated piece of malware primarily used for espionage.
ElectroRAT rat
According to PCrisk, ElectroRAT is a Remote Access Trojan (RAT) written in the Go programming language and designed to target Windows…
Elevator backdoor
Elevator is a sophisticated backdoor utilized primarily by advanced persistent threat groups for cyber espionage activities.
Elibomi trojan
Also known as Drinik. Elibomi, also known as Drinik, is a banking trojan primarily targeting users in India.
Elirks backdoortrojan
Elirks is a basic backdoor Trojan, first discovered in 2010, that is primarily used to steal information from compromised systems.
Elise backdoortrojan
Also known as BKDR_ESILE, Page, EVILNEST. Elise is a custom backdoor Trojan that appears to be used exclusively by Lotus Blossom.
ElizaRAT rat
ElizaRAT is a remote access trojan designed to facilitate unauthorized access and control over compromised systems.
Embargo ransomwareloader
Embargo is a ransomware variant written in Rust that has been active since at least May 2024.
Emdivi rat
Emdivi is a remote access trojan primarily targeting Japanese organizations.
Emissary trojan
Emissary is a Trojan that has been used by Lotus Blossom.
Emmenhtal loaderdropperrat
Also known as IDATDropper, PEAKLIGHT. Emmenhtal is a malicious loader likely distributed since early 2024, and publicly detailed by Orange Cyberdefense CERT in August 2024.
Emotet botnetdownloadertrojan
Also known as Geodo, Heodo. Emotet is a modular malware variant which is primarily used as a downloader for other malware variants such as TrickBot and IcedID.
Empire ratbackdoor
Also known as EmPyre, PowerShell Empire. Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub.
Empire Downloader downloader
Empire Downloader is a PowerShell-based malware primarily used to download and execute additional payloads.
Empyrean credential-stealer
Discord Stealer written in Python with Javascript-based inject files.
Emudbot worm
Supposedly a worm that was active around 2012-2013.
EnCrypt ransomware
EnCrypt is a type of ransomware designed to encrypt files on a victim's computer, demanding a ransom to restore access.
Enc1 ransomware
Enc1 is a ransomware that encrypts user files and demands a ransom for decryption.
Encoder.xxxx ransomware
Also known as Trojan.Encoder.6491. Encoder.xxxx is a ransomware coded in Go, also known as Trojan.Encoder.6491.
EncoderCSL ransomware
EncoderCSL is a type of ransomware that encrypts victim files and demands a ransom for decryption keys.
EncrypTile Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
EncryptServer2018 ransomware
EncryptServer2018 is a ransomware family known for targeting various sectors, encrypting files, and demanding a ransom for decryption.
EncryptedBatch ransomware
EncryptedBatch is a ransomware family known for encrypting files on infected systems and demanding a ransom from victims.
Encryptss77 Ransomware ransomware
Also known as SFX Monster Ransomware. This is most likely to affect English speaking users, since the note is written in English.
Endurance wiperransomware
Endurance is a destructive ransomware variant first observed in 2023, developed and operated by the threat actor known as IntelBroker…
EnemyBot botnetddos
According to the Infosec Institute, EnemyBot is a dangerous IoT botnet that has made headlines in the last few weeks.
Enigma ransomware
Enigma is a ransomware that encrypts files on the victim's system, demanding a ransom to restore access.
Enigma 2 Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Enigma Loader downloaderloader
According to Trend Micro, this is a downloader, dedicated to stage execution of a second stage malware called Enigma Stealer.
Enjey ransomware
Enjey is a ransomware based on the RemindMe ransomware.
EnjeyCrypter Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
EnkripsiPC Ransomware ransomware
Also known as IDRANSOMv3, Manifestus. It’s directed to English speaking users, therefore is able to infect worldwide.
Enrume ransomware
Also known as Ransom32. Enrume, also known as Ransom32, is a JavaScript-based ransomware that operates cross-platform.
Ensiko webshellransomware
Ensiko is a ransomware variant often delivered as a webshell, used to encrypt files and demand a ransom.
Ensikology webshellcryptominer
Also known as Ensiko. Ensikology, also known as Ensiko, is a PHP web shell that possesses sophisticated capabilities including cryptocurrency mining and serving…
Entropy ransomware
Entropy is a ransomware first seen in 1st quarter of 2022, is being used in conjunction of Dridex infection.
EntryShell backdoor
Fileless malware 'EntryShell', a variant of the KeyBoy malware, due to similarities in backdoor command IDs and debug messages with old…
Enviserv backdoor
According to Microsoft, Enviserv is a malicious program that is unable to spread of its own accord.
EnvyScout dropper
Also known as ROOTSAW. EnvyScout is a dropper that has been used by APT29 since at least 2021.
EnyBeny Nuclear Ransomware ransomware
@GrujaRS discovered a new in-dev ransomware called EnyBeny Nuclear Ransomware that meant to append the extension .PERSONAL_ID:.Nuclear to…
EnyBenyHorsuke Ransomware ransomware
GrujaRS discovered a new ransomware called EnyBenyHorsuke Ransomware that appends the .Horsuke extension to encrypted files.
EnybenyCrypt ransomware
EnybenyCrypt is a type of ransomware that encrypts a victim's files and demands a ransom in return for the decryption key.