Malware Families page 17 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Ep918
Ep918 is a piece of malware for which specific details remain undisclosed.
Epic backdoorrat
Also known as Tavdig, Wipbot, WorldCupSec. Epic is a sophisticated backdoor used by the Turla group for cyber-espionage operations.
EpicSplit RAT ratscreen-capture
EpicSplit RAT is a multiplatform Java RAT that is capable of running shell commands, downloading, uploading, and executing files…
Epoblockl ransomware
Epoblockl is a type of ransomware primarily focused on encrypting data on infected systems, demanding a ransom for decryption.
Epsilon ransomware
Epsilon is a ransomware family known for encrypting files on infected systems and demanding a ransom for their decryption.
Epsilon Red ransomware
Also known as BlackCocaine. According to PCrisk, Epsilon is a ransomware-type program.
Epsilon Stealer credential-stealerspyware
Epsilon Stealer is an information stealer sold as Malware as a Service by a new french actor called "Epsilon".
EquationDrug rootkitbackdoor
EquationDrug is a sophisticated malware family associated with high-profile espionage campaigns.
Equationgroup (Sorting) exploit-kitspywarerootkit
Equationgroup refers to a sophisticated and highly advanced threat actor suspected of ties with national intelligence agencies.
Eraleign ransomware
Also known as Apt73. A new ransomware group is said to have emerged in mid-April 2024, under the name "APT73." It's worth noting that the group reportedly…
Erbium Stealer credential-stealerspyware
Erbium is an information stealer advertised and sold as a Malware-as-a-Service on cybercrime forums and Telegram since at least July 2022.
Erebus ransomware
Erebus is a ransomware family known to target South Korean entities, specifically within the government and financial services industries.
Erebus (ELF) ransomware
Erebus is a ransomware that targets Linux systems, exploiting vulnerabilities to gain access and encrypt critical files.
Erebus (Windows) ransomware
Erebus is a ransomware strain that first gained attention in June 2017 after targeting systems in South Korea.
Erebus 2017 Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Erebus Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Eredel credential-stealerspyware
Eredel Stealer is a low price malware that allows for extracting passwords, cookies, screen desktop from browsers and programs.
Erica Ransomware ransomware
Erica Ransomware is a malware family that encrypts victims' data, demanding ransom payments for decryption keys.
Erica2020 ransomware
Erica2020 is a ransomware strain that targets sensitive sectors such as government, financial services, and healthcare.
Eris ransomware
Eris is a type of ransomware known for encrypting victims' files and demanding a ransom for decryption.
ErrorFather trojandroppercredential-stealer
ErrorFather is an Android banking trojan with a multi-stage dropper.
Escobar trojancredential-stealer
Escobar is an Android banking trojan, first detected in March 2021, believed to be a new variant of AbereBot.
Esmeralda Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Estemani ransomware
Estemani is a sophisticated type of ransomware known for targeting multiple industries, including financial services and healthcare sectors.
Eternal ransomware
Eternal is a ransomware threat that encrypts files on infected systems, demanding a ransom for decryption.
EternalRocks wormbotnet
Also known as MicroBotMassiveNet. EternalRocks is a network worm that leverages seven SMB exploits discovered by the NSA, as well as the DoublePulsar backdoor.
Eternity ransomware
Eternity is a ransomware that encrypts files on the victim's machine and demands a ransom for decryption.
Eternity Clipper credential-stealertrojan
This malware is part of the Eternity Malware "Framework".
Eternity Ransomware ransomware
Eternity Ransomware is part of the Eternity Framework ransomware-as-a-service offering, targeting various sectors with data encryption and…
Eternity Stealer credential-stealer
This Stealer is part of the eternity malware project.
Eternity Worm worm
This malware is part of the Eternity Malware "Framework".
EtherRAT rat
According to sysdig, EtherRAT uses Ethereum smart contracts for C2 URL resolution.
EtumBot botnetloader
Also known as HighTide. EtumBot, also known as HighTide, is a malware family associated with espionage activities primarily targeting government and technology…
Euclid ransomware
Euclid is a ransomware family designed to encrypt files of its victims, demanding a ransom for decryption.
EugenLoader loader
Also known as FakeBat, NUMOZYLOD, PaykLoader. A loader written in Powershell, usually delivered packaged in MSI/MSIX files.
Evasive HT ransomware
Evasive HT is a ransomware variant known for its capability to evade detection mechanisms while encrypting victim files.
EventBot trojancredential-stealerspyware
EventBot is an Android banking trojan and information stealer that abuses Android’s accessibility service to steal data from various…
Everbe Ransomware ransomware
Everbe Ransomware is a type of malware that encrypts victims' files and demands a ransom for the decryption key.
Everest ransomware
Everest is a ransomware family known for targeting financial and governmental institutions.
Evil Ant ransomware
Evil Ant is a type of ransomware written in Python.
Evil Ransomware ransomware
Also known as File0Locked KZ Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
EvilBunny trojan
EvilBunny is a C++ malware sample observed since 2011 that was designed to be a execution platform for Lua scripts.
EvilConwi rattrojan
EvilConwi is a malicious variant of the legitimate ScreenConnect software by ConnectWise.
EvilExtractor keyloggerransomwarespyware
EvilExtractor is a piece of malware known for its versatility, combining aspects of both ransomware and spyware.
EvilGnome spywaretrojan
According to Infosec Institute, EvilGnome presents itself to unwitting Linux users as a legitimate GNOME extension.
EvilGrab ratscreen-capturetrojan
Also known as Vidgrab. EvilGrab is a malware family with common reconnaissance capabilities.
EvilOSX rat
EvilOSX is a RAT primarily targeting macOS systems, providing attackers with control over infected machines.
EvilPlayout wiper
A wiper used against in an attack against Iran’s state broadcaster.
EvilPony credential-stealertrojan
Also known as CREstealer. EvilPony, also known as CREstealer, is a privately modified version of the Pony stealer malware.
Evilginx credential-stealer
According to the author, Evilginx is a standalone man-in-the-middle attack framework used for phishing login credentials along with…
Evolution ransomware
Evolution is a ransomware family known for encrypting files and demanding ransom payments.
Evrial credential-stealer
Evrial is a credential-stealer malware known for its clipboard hijacking capabilities.
EwDoor backdoor
EwDoor is a backdoor targeting telecommunications providers, exploiting vulnerabilities to gain unauthorized access and control over…
ExMatter ransomware
Exfiltration tool written in .NET, used by at least one BlackMatter ransomware operator.
Exaramel (ELF) backdoor
Exaramel is a backdoor malware identified in both Windows and Linux environments, used by the APT group TeleBots.
Exaramel (Windows) backdoorrat
Exaramel is a sophisticated backdoor malware linked to the APT group TeleBots.
Exaramel for Linux backdoor
Exaramel for Linux is a backdoor written in the Go Programming Language and compiled as a 64-bit ELF binary.
Exaramel for Windows backdoor
Exaramel for Windows is a backdoor used for targeting Windows systems.
Exbyte
Exbyte is an exfiltration tool written in Go that is uniquely associated with BlackByte operations.
Excalibur ratspyware
Also known as Saber, Sabresac. Excalibur is a remote access tool (RAT) known to target government and defense sectors.
Executioner ransomware
Executioner is a ransomware that encrypts files and demands a ransom for decryption.
ExecutionerPlus ransomware
ExecutionerPlus is a sophisticated ransomware targeting multiple industries, known for encrypting data and demanding ransoms for…
Exerwa CTF ransomware
Exerwa CTF is a ransomware variant known for encrypting files and demanding a ransom in cryptocurrency.
Exile RAT rat
ExileRAT is a simple RAT platform capable of getting information on the system (computer name, username, listing drives, network adapter…
ExoLock ransomware
ExoLock is a ransomware that encrypts files on infected systems and demands a ransom for decryption keys.
Exobot trojan
Exobot is Android banking malware, primarily targeting financial institutions in Germany, Austria, and France.
Exocrypt XTC ransomware
Exocrypt XTC is a ransomware that encrypts victim files and demands payment for decryption keys.
Exodus spywaredropper
Also known as Exodus One, Exodus Two. Exodus is Android spyware deployed in two distinct stages named Exodus One (dropper) and Exodus Two (payload).
Exorcist ransomware
Exorcist is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
Exotic Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
ExpBoot ransomware
ExpBoot is a ransomware family that encrypts files on infected systems, demanding a ransom in exchange for the decryption key.
Expand loader
Expand is a Windows utility used to expand one or more compressed CAB files.
Expiro credential-stealervirus
Also known as Xpiro. Expiro malware has been around for more than a decade, and the malware authors sill continue their work and update it with more features.
Explorer ransomware
Explorer is a ransomware that encrypts files on infected systems, demanding a ransom for decryption keys.
Explosive rat
Explosive is a custom-made remote access tool used by the group Volatile Cedar.
ExplosiveRAT rat
ExplosiveRAT is a remote access tool primarily used for cyber espionage targeting governmental and technology sectors.
Extortion Scam ransomware
Also known as Sextortion Scam. Extortion Scam, also known as Sextortion Scam, involves deceiving victims into paying a ransom by threatening to release compromising…
Extractor ransomware
Extractor is a ransomware variant that encrypts files on compromised systems, demanding a ransom payment for decryption.
EyLamo ransomware
EyLamo is a ransomware known for encrypting files on the victim's system and demanding a ransom for decryption.
Eye Pyramid spywarekeylogger
Eye Pyramid is a spyware malware used primarily for espionage activities targeting Italian government officials and financial sectors.
Eyecry ransomware
Eyecry is a type of ransomware known for encrypting user data and demanding a ransom for decryption.
FALLCHILL rat
FALLCHILL is a RAT that has been used by Lazarus Group since at least 2016 to target the aerospace, telecommunications, and finance…
FBLocker ransomware
FBLocker is a ransomware variant that encrypts files on infected systems and demands a ransom payment for file decryption.
FBot botnetddoscryptominer
FBot is a malware known for leveraging botnet infrastructures to conduct DDoS attacks and cryptomining operations.
FCP ransomware
FCP is a ransomware strain that encrypts data and demands ransom for decryption.
FCT ransomware
FCT is a type of ransomware malware, which encrypts files on the infected system and demands a ransom for decryption.
FCrypt ransomware
FCrypt is a type of ransomware that encrypts files on a victim's system, demanding a ransom for the decryption key.
FDMTP downloader
FDMTP is a newly discovered hacking tool developed in .NET, used by Earth Preta.
FELIXROOT backdoor
Also known as GreyEnergy mini. FELIXROOT is a backdoor that has been used to target Ukrainian victims.
FEimea RAT rat
FEimea RAT is a remote access trojan used for various cyber-espionage activities.
FFDroider credential-stealer
According to PCrisk, FFDroider is a malicious program classified as a stealer.
FILE FROZR ransomware
Also known as FileFrozr. FILE FROZR, also known as FileFrozr, is a Ransomware as a Service (RaaS) leveraging file encryption to extort victims.
FINALDRAFT (ELF) rat
FINALDRAFT is a sophisticated Linux-based remote access tool (RAT) that primarily targets government and technology sectors.
FINALDRAFT (Windows) trojan
FINALDRAFT is a sophisticated trojan primarily targeting government and defense sectors.
FINSPY spywarerat
Though we have not identified the targets, FINSPY is sold by Gamma Group to multiple nation-state clients, and we assess with moderate…
FINTEAM rat
Also known as TeamBot. Recently, Check Point researchers spotted a targeted attack against officials within government finance authorities and representatives in…
FIVEHANDS ransomware
Also known as Thieflock. FIVEHANDS is a customized version of DEATHRANSOM ransomware written in C++.
FK_Undead trojanrootkit
Also known as Undead. This malware family is mainly spread through various private server clients in bundles, and mainly tamper with user system network data…
FLASHFLOOD wormspyware
FLASHFLOOD is malware developed by APT30 that allows propagation and exfiltration of data over removable devices.
FLIPSIDE backdoor
FLIPSIDE is a simple tool similar to Plink that is used by FIN5 to maintain access to victims.