Malware Families page 17 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Ep918
- Ep918 is a piece of malware for which specific details remain undisclosed.
- Epic backdoorrat
- Also known as Tavdig, Wipbot, WorldCupSec. Epic is a sophisticated backdoor used by the Turla group for cyber-espionage operations.
- EpicSplit RAT ratscreen-capture
- EpicSplit RAT is a multiplatform Java RAT that is capable of running shell commands, downloading, uploading, and executing files…
- Epoblockl ransomware
- Epoblockl is a type of ransomware primarily focused on encrypting data on infected systems, demanding a ransom for decryption.
- Epsilon ransomware
- Epsilon is a ransomware family known for encrypting files on infected systems and demanding a ransom for their decryption.
- Epsilon Red ransomware
- Also known as BlackCocaine. According to PCrisk, Epsilon is a ransomware-type program.
- Epsilon Stealer credential-stealerspyware
- Epsilon Stealer is an information stealer sold as Malware as a Service by a new french actor called "Epsilon".
- EquationDrug rootkitbackdoor
- EquationDrug is a sophisticated malware family associated with high-profile espionage campaigns.
- Equationgroup (Sorting) exploit-kitspywarerootkit
- Equationgroup refers to a sophisticated and highly advanced threat actor suspected of ties with national intelligence agencies.
- Eraleign ransomware
- Also known as Apt73. A new ransomware group is said to have emerged in mid-April 2024, under the name "APT73." It's worth noting that the group reportedly…
- Erbium Stealer credential-stealerspyware
- Erbium is an information stealer advertised and sold as a Malware-as-a-Service on cybercrime forums and Telegram since at least July 2022.
- Erebus ransomware
- Erebus is a ransomware family known to target South Korean entities, specifically within the government and financial services industries.
- Erebus (ELF) ransomware
- Erebus is a ransomware that targets Linux systems, exploiting vulnerabilities to gain access and encrypt critical files.
- Erebus (Windows) ransomware
- Erebus is a ransomware strain that first gained attention in June 2017 after targeting systems in South Korea.
- Erebus 2017 Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Erebus Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Eredel credential-stealerspyware
- Eredel Stealer is a low price malware that allows for extracting passwords, cookies, screen desktop from browsers and programs.
- Erica Ransomware ransomware
- Erica Ransomware is a malware family that encrypts victims' data, demanding ransom payments for decryption keys.
- Erica2020 ransomware
- Erica2020 is a ransomware strain that targets sensitive sectors such as government, financial services, and healthcare.
- Eris ransomware
- Eris is a type of ransomware known for encrypting victims' files and demanding a ransom for decryption.
- ErrorFather trojandroppercredential-stealer
- ErrorFather is an Android banking trojan with a multi-stage dropper.
- Escobar trojancredential-stealer
- Escobar is an Android banking trojan, first detected in March 2021, believed to be a new variant of AbereBot.
- Esmeralda Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Estemani ransomware
- Estemani is a sophisticated type of ransomware known for targeting multiple industries, including financial services and healthcare sectors.
- Eternal ransomware
- Eternal is a ransomware threat that encrypts files on infected systems, demanding a ransom for decryption.
- EternalRocks wormbotnet
- Also known as MicroBotMassiveNet. EternalRocks is a network worm that leverages seven SMB exploits discovered by the NSA, as well as the DoublePulsar backdoor.
- Eternity ransomware
- Eternity is a ransomware that encrypts files on the victim's machine and demands a ransom for decryption.
- Eternity Clipper credential-stealertrojan
- This malware is part of the Eternity Malware "Framework".
- Eternity Ransomware ransomware
- Eternity Ransomware is part of the Eternity Framework ransomware-as-a-service offering, targeting various sectors with data encryption and…
- Eternity Stealer credential-stealer
- This Stealer is part of the eternity malware project.
- Eternity Worm worm
- This malware is part of the Eternity Malware "Framework".
- EtherRAT rat
- According to sysdig, EtherRAT uses Ethereum smart contracts for C2 URL resolution.
- EtumBot botnetloader
- Also known as HighTide. EtumBot, also known as HighTide, is a malware family associated with espionage activities primarily targeting government and technology…
- Euclid ransomware
- Euclid is a ransomware family designed to encrypt files of its victims, demanding a ransom for decryption.
- EugenLoader loader
- Also known as FakeBat, NUMOZYLOD, PaykLoader. A loader written in Powershell, usually delivered packaged in MSI/MSIX files.
- Evasive HT ransomware
- Evasive HT is a ransomware variant known for its capability to evade detection mechanisms while encrypting victim files.
- EventBot trojancredential-stealerspyware
- EventBot is an Android banking trojan and information stealer that abuses Android’s accessibility service to steal data from various…
- Everbe Ransomware ransomware
- Everbe Ransomware is a type of malware that encrypts victims' files and demands a ransom for the decryption key.
- Everest ransomware
- Everest is a ransomware family known for targeting financial and governmental institutions.
- Evil Ant ransomware
- Evil Ant is a type of ransomware written in Python.
- Evil Ransomware ransomware
- Also known as File0Locked KZ Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- EvilBunny trojan
- EvilBunny is a C++ malware sample observed since 2011 that was designed to be a execution platform for Lua scripts.
- EvilConwi rattrojan
- EvilConwi is a malicious variant of the legitimate ScreenConnect software by ConnectWise.
- EvilExtractor keyloggerransomwarespyware
- EvilExtractor is a piece of malware known for its versatility, combining aspects of both ransomware and spyware.
- EvilGnome spywaretrojan
- According to Infosec Institute, EvilGnome presents itself to unwitting Linux users as a legitimate GNOME extension.
- EvilGrab ratscreen-capturetrojan
- Also known as Vidgrab. EvilGrab is a malware family with common reconnaissance capabilities.
- EvilOSX rat
- EvilOSX is a RAT primarily targeting macOS systems, providing attackers with control over infected machines.
- EvilPlayout wiper
- A wiper used against in an attack against Iran’s state broadcaster.
- EvilPony credential-stealertrojan
- Also known as CREstealer. EvilPony, also known as CREstealer, is a privately modified version of the Pony stealer malware.
- Evilginx credential-stealer
- According to the author, Evilginx is a standalone man-in-the-middle attack framework used for phishing login credentials along with…
- Evolution ransomware
- Evolution is a ransomware family known for encrypting files and demanding ransom payments.
- Evrial credential-stealer
- Evrial is a credential-stealer malware known for its clipboard hijacking capabilities.
- EwDoor backdoor
- EwDoor is a backdoor targeting telecommunications providers, exploiting vulnerabilities to gain unauthorized access and control over…
- ExMatter ransomware
- Exfiltration tool written in .NET, used by at least one BlackMatter ransomware operator.
- Exaramel (ELF) backdoor
- Exaramel is a backdoor malware identified in both Windows and Linux environments, used by the APT group TeleBots.
- Exaramel (Windows) backdoorrat
- Exaramel is a sophisticated backdoor malware linked to the APT group TeleBots.
- Exaramel for Linux backdoor
- Exaramel for Linux is a backdoor written in the Go Programming Language and compiled as a 64-bit ELF binary.
- Exaramel for Windows backdoor
- Exaramel for Windows is a backdoor used for targeting Windows systems.
- Exbyte
- Exbyte is an exfiltration tool written in Go that is uniquely associated with BlackByte operations.
- Excalibur ratspyware
- Also known as Saber, Sabresac. Excalibur is a remote access tool (RAT) known to target government and defense sectors.
- Executioner ransomware
- Executioner is a ransomware that encrypts files and demands a ransom for decryption.
- ExecutionerPlus ransomware
- ExecutionerPlus is a sophisticated ransomware targeting multiple industries, known for encrypting data and demanding ransoms for…
- Exerwa CTF ransomware
- Exerwa CTF is a ransomware variant known for encrypting files and demanding a ransom in cryptocurrency.
- Exile RAT rat
- ExileRAT is a simple RAT platform capable of getting information on the system (computer name, username, listing drives, network adapter…
- ExoLock ransomware
- ExoLock is a ransomware that encrypts files on infected systems and demands a ransom for decryption keys.
- Exobot trojan
- Exobot is Android banking malware, primarily targeting financial institutions in Germany, Austria, and France.
- Exocrypt XTC ransomware
- Exocrypt XTC is a ransomware that encrypts victim files and demands payment for decryption keys.
- Exodus spywaredropper
- Also known as Exodus One, Exodus Two. Exodus is Android spyware deployed in two distinct stages named Exodus One (dropper) and Exodus Two (payload).
- Exorcist ransomware
- Exorcist is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
- Exotic Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- ExpBoot ransomware
- ExpBoot is a ransomware family that encrypts files on infected systems, demanding a ransom in exchange for the decryption key.
- Expand loader
- Expand is a Windows utility used to expand one or more compressed CAB files.
- Expiro credential-stealervirus
- Also known as Xpiro. Expiro malware has been around for more than a decade, and the malware authors sill continue their work and update it with more features.
- Explorer ransomware
- Explorer is a ransomware that encrypts files on infected systems, demanding a ransom for decryption keys.
- Explosive rat
- Explosive is a custom-made remote access tool used by the group Volatile Cedar.
- ExplosiveRAT rat
- ExplosiveRAT is a remote access tool primarily used for cyber espionage targeting governmental and technology sectors.
- Extortion Scam ransomware
- Also known as Sextortion Scam. Extortion Scam, also known as Sextortion Scam, involves deceiving victims into paying a ransom by threatening to release compromising…
- Extractor ransomware
- Extractor is a ransomware variant that encrypts files on compromised systems, demanding a ransom payment for decryption.
- EyLamo ransomware
- EyLamo is a ransomware known for encrypting files on the victim's system and demanding a ransom for decryption.
- Eye Pyramid spywarekeylogger
- Eye Pyramid is a spyware malware used primarily for espionage activities targeting Italian government officials and financial sectors.
- Eyecry ransomware
- Eyecry is a type of ransomware known for encrypting user data and demanding a ransom for decryption.
- FALLCHILL rat
- FALLCHILL is a RAT that has been used by Lazarus Group since at least 2016 to target the aerospace, telecommunications, and finance…
- FBLocker ransomware
- FBLocker is a ransomware variant that encrypts files on infected systems and demands a ransom payment for file decryption.
- FBot botnetddoscryptominer
- FBot is a malware known for leveraging botnet infrastructures to conduct DDoS attacks and cryptomining operations.
- FCP ransomware
- FCP is a ransomware strain that encrypts data and demands ransom for decryption.
- FCT ransomware
- FCT is a type of ransomware malware, which encrypts files on the infected system and demands a ransom for decryption.
- FCrypt ransomware
- FCrypt is a type of ransomware that encrypts files on a victim's system, demanding a ransom for the decryption key.
- FDMTP downloader
- FDMTP is a newly discovered hacking tool developed in .NET, used by Earth Preta.
- FELIXROOT backdoor
- Also known as GreyEnergy mini. FELIXROOT is a backdoor that has been used to target Ukrainian victims.
- FEimea RAT rat
- FEimea RAT is a remote access trojan used for various cyber-espionage activities.
- FFDroider credential-stealer
- According to PCrisk, FFDroider is a malicious program classified as a stealer.
- FILE FROZR ransomware
- Also known as FileFrozr. FILE FROZR, also known as FileFrozr, is a Ransomware as a Service (RaaS) leveraging file encryption to extort victims.
- FINALDRAFT (ELF) rat
- FINALDRAFT is a sophisticated Linux-based remote access tool (RAT) that primarily targets government and technology sectors.
- FINALDRAFT (Windows) trojan
- FINALDRAFT is a sophisticated trojan primarily targeting government and defense sectors.
- FINSPY spywarerat
- Though we have not identified the targets, FINSPY is sold by Gamma Group to multiple nation-state clients, and we assess with moderate…
- FINTEAM rat
- Also known as TeamBot. Recently, Check Point researchers spotted a targeted attack against officials within government finance authorities and representatives in…
- FIVEHANDS ransomware
- Also known as Thieflock. FIVEHANDS is a customized version of DEATHRANSOM ransomware written in C++.
- FK_Undead trojanrootkit
- Also known as Undead. This malware family is mainly spread through various private server clients in bundles, and mainly tamper with user system network data…
- FLASHFLOOD wormspyware
- FLASHFLOOD is malware developed by APT30 that allows propagation and exfiltration of data over removable devices.
- FLIPSIDE backdoor
- FLIPSIDE is a simple tool similar to Plink that is used by FIN5 to maintain access to victims.