Malware Families page 18 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- FLKR Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- FONIX ransomware
- FONIX is a ransomware family known for encrypting victims' files and demanding a ransom for decryption.
- FPSpy spywarebackdoor
- FPSpy is a sophisticated spyware used for cyber-espionage, primarily targeting government, telecommunication, and financial sectors.
- FRAMESTING webshell
- FRAMESTING is a Python web shell that was used during Cutting Edge to embed into an Ivanti Connect Secure Python package for command…
- FROZENHILL loaderdropper
- FROZENHILL is a launcher written in C++ that is configured to utilize existing files for execution and also infects newly attached storage…
- FRP backdoor
- FRP, which stands for Fast Reverse Proxy, is an openly available tool that is capable of exposing a server located behind a firewall or…
- FRS ransomware
- FRS is a ransomware that encrypts files on infected systems, demanding a ransom for their release.
- FRat rat
- A RAT employing Node.js, Sails, and Socket.IO to collect information on a target
- FRat Loader loader
- Loader used to deliver FRat (see family windows.frat)
- FScrypt ransomware
- FScrypt is a ransomware that encrypts files on the victim's system and demands a ransom for decryption.
- FSociety ransomware
- FSociety is a ransomware strain derived from EDA2 and RemindMe.
- FTCode ransomwareloader
- A targeted email campaign has been spotted distributing the JasperLoader to victims.
- FULLHOUSE backdoor
- Fullhouse (AKA FULLHOUSE.DOORED) is a custom backdoor used by subsets of the North Korean Lazarus Group.
- FULLMETAL trojanbackdoor
- FULLMETAL is a sophisticated malware family used for cyber-espionage, particularly targeting the defense and aerospace sectors in the…
- FYAnti loader
- Also known as DILLJUICE stage2. FYAnti is a loader that has been used by menuPass since at least 2020, including to deploy QuasarRAT.
- FabSysCrypto Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Fabiansomware ransomware
- Fabiansomware is a type of ransomware that encrypts files on infected systems and demands a ransom payment for decryption keys.
- Fabookie credential-stealer
- Fabookie malware is designed to steal Facebook account information, targeting individuals and organizations involved with social media…
- FaceStealer credential-stealer
- FaceStealer is a credential-stealing malware that primarily targets Facebook credentials.
- Facebook HT ransomware
- Facebook HT is a ransomware that encrypts files on infected systems, demanding a ransom for decryption keys.
- Facefish backdoortrojan
- Facefish is a Linux-based malware that acts as a backdoor and trojan to steal sensitive information from targeted systems.
- Fadesoft Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- FailyTale rat
- FailyTale is a Remote Access Trojan (RAT) used for espionage, primarily targeting government and technology sectors.
- Fairware ransomware
- Fairware is a ransomware targeting Linux operating systems.
- Faizal ransomware
- Faizal is a ransomware that encrypts files and demands a ransom payment for decryption keys.
- Fakben ransomware
- Fakben is a ransomware variant based on the Hidden Tear project, aimed at encrypting files and demanding ransom for decryption keys.
- Fake Cerber ransomware
- Fake Cerber is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
- Fake DMA ransomware
- Fake DMA is a ransomware variant that targets various industries, impacting financial, healthcare, and technology sectors.
- Fake Globe Ransomware ransomware
- Also known as Globe Imposter, GlobeImposter. It’s directed to English speaking users, therefore is able to infect worldwide.
- Fake Locky Ransomware ransomware
- Also known as Locky Impersonator Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- Fake Pornhub trojan
- Fake Pornhub is a trojan that masquerades as a legitimate adult application to lure victims into installing it.
- FakeAdBlocker trojan
- FakeAdBlocker is a malicious software masquerading as a legitimate ad-blocking tool.
- FakeCry ransomware
- Malware written in .NET that mimics WannaCry.
- FakeCryptoLocker ransomware
- FakeCryptoLocker is a type of ransomware that encrypts files on an infected system and demands a ransom payment for decryption.
- FakeDefend ransomware
- FakeDefend is a type of ransomware that specifically targets Android mobile devices.
- FakeGram trojancredential-stealer
- Also known as FakeTGram. FakeGram is a trojan that mimics legitimate messaging applications to steal user credentials.
- FakeM backdoor
- FakeM is a shellcode-based Windows backdoor that has been used by Scarlet Mimic.
- FakeRean trojan
- Also known as Braviax. FakeRean, also known as Braviax, is a trojan that masquerades as legitimate security software.
- FakeSpy spyware
- FakeSpy is Android spyware that has been operated by the Chinese threat actor behind the Roaming Mantis campaigns.
- FakeTC
- FakeTC is a type of malware with limited information publicly available.
- FakeUpdateRU downloader
- FakeUpdateRU is a malicious JavaScript code injected into compromised websites to deliver further malware using the drive-by download…
- FakeWord trojancredential-stealer
- FakeWord is a trojan malware often used in phishing attacks to steal credentials.
- Fakecalls trojanspyware
- Fakecalls is an Android trojan, first detected in January 2021, that masquerades as South Korean banking apps.
- Fanny wormexploit-kit
- Also known as DEMENTIAWHEEL. Fanny is a USB-propagated worm discovered in 2008, used primarily for reconnaissance and weapon delivery in the Middle East and South Asia.
- Fantom ransomware
- Also known as Comrad Circle. Fantom is a ransomware based on EDA2 that pretends to be a legitimate Windows update.
- FantomCrypt ransomware
- According to PCrisk, Fantom is a ransomware-type virus that imitates the Windows update procedure while encrypting files.
- Farseer rat
- Farseer is a Windows-based Remote Access Trojan (RAT) known for targeting government and public sector organizations, particularly in…
- FartPlz ransomware
- FartPlz is a ransomware known for encrypting victim files and demanding a ransom for decryption.
- FastCash trojan
- FastCash is a trojan primarily used for ATM cash-out operations.
- FastFire downloaderbotnet
- FastFire is a malware family known for its capability to quickly infiltrate networks and propagate through systems.
- FastLoader downloaderscreen-capture
- FastLoader is a small .NET downloader, which name comes from PDB strings seen in samples.
- FastPOS credential-stealer
- FastPOS is a malware family designed to target point-of-sale systems by stealing payment card data.
- FastSpy spywarerat
- FastSpy is a remote access tool designed for cyber espionage, primarily targeting government, tech, and defense industries.
- Fastwind ransomware
- Fastwind is a ransomware that encrypts files on the victim's system and demands a ransom for decryption.
- FatDuke backdoor
- FatDuke is a backdoor used by APT29 since at least 2016.
- FatalRat ratkeylogger
- Also known as Sainbox RAT. FatalRAT is a most-likely chinese remote access tool distributed through forums and Telegram channels.
- Fauppod trojan
- Fauppod is a type of trojan malware. It is part of a broader malware family used for unauthorized access or damage to systems.
- FeedLoad downloadertrojan
- FeedLoad is a sophisticated downloader trojan used primarily to deliver other malicious payloads onto compromised systems.
- Felipe trojancredential-stealer
- The Zscaler ThreatLabZ team came across a new strain of infostealer Trojan called Felipe, which silently installs itself onto a user’s…
- Felismus backdoor
- Felismus is a modular backdoor that has been used by Sowbug.
- Felismus RAT rat
- Felismus RAT is a remote access trojan used by the cyber espionage group Sowbug.
- Fenix rat
- Fenix is a remote access trojan (RAT) family used in various cyber espionage operations.
- FenixLocker ransomware
- FenixLocker is a type of ransomware that encrypts victim files and demands a ransom for decryption.
- Fenrir ransomware
- Fenrir is a type of ransomware that encrypts the victim's files and demands a ransom for the decryption key.
- Feodo credential-stealertrojanbotnet
- Also known as Bugat, Cridex. Feodo (also known as Cridex or Bugat) is a Trojan used to commit e-banking fraud and to steal sensitive information from the victims…
- Ferocious downloader
- Ferocious is a first stage implant composed of VBS and PowerShell scripts that has been used by WIRTE since at least 2021.
- Fgdump credential-stealer
- Fgdump is a tool specifically designed to dump Windows password hashes, often used by attackers to crack or abuse credentials.
- Ficker Stealer credential-stealerdownloaderspyware
- According to CyberArk, this malware is used to steal sensitive information, including login credentials, credit card information…
- Fickle Stealer credential-stealer
- Fickle Stealer is a credential-stealing malware designed to pilfer sensitive information like user credentials and financial data.
- File Ripper ransomware
- File Ripper is a type of ransomware designed to encrypt files on a victim's system, demanding a ransom for the decryption key.
- File Spider ransomware
- Also known as Spider. A new ransomware called File Spider is being distributed through spam that targets victims in Bosnia and Herzegovina, Serbia, and Croatia.
- File-Locker ransomware
- The File-Locker Ransomware is a Hidden Tear variant that is targeting victims in Korea.
- FileCoder ransomware
- Also known as FindZip, Patcher. A barely functional piece of macOS ransomware, written in Swift.
- FileEngineering ransomware
- FileEngineering is a ransomware that encrypts files on infected systems, demanding a ransom for decryption keys.
- FileFuck ransomware
- FileFuck is a ransomware family known for targeting various sectors, including financial services and healthcare.
- FileIce credential-stealer
- FileIce is malware associated with credential theft, designed to harvest user credentials from the victim's system.
- FileLocker ransomware
- FileLocker is a type of ransomware that encrypts files on the victim's system and demands a ransom in exchange for the decryption key.
- Fileice Ransomware Survey Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Filerase wiper
- Filerase is a .net API-based utility capable of propagating and recursively deleting files.
- FilesL0cker ransomware
- FilesL0cker is a ransomware known for encrypting files and demanding a ransom from victims to restore access.
- FinFisher spywarerat
- Also known as FinSpy. FinFisher is a government-grade commercial surveillance spyware reportedly sold exclusively to government agencies for use in targeted and…
- FinFisher (Android) spywaretrojan
- FinFisher, also known as FinSpy, is a sophisticated surveillance malware often associated with government surveillance operations.
- FinFisher (ELF) spywarerattrojan
- FinFisher is a sophisticated spyware suite designed for targeted surveillance.
- FinFisher (OS X) spywaretrojan
- FinFisher (OS X) is a commercial spyware tool developed by the Gamma Group, used by entities for surveillance purposes.
- FinFisher RAT ratspyware
- Also known as FinSpy. FinFisher is a commercial software used to steal information and spy on affected victims.
- Final ransomware
- Final is a ransomware that encrypts files on the victim's machine, demanding a ransom for decryption.
- Final1stspy dropper
- Final1stspy is a dropper family that has been used to deliver DOGCALL.
- FindPOS keyloggercredential-stealer
- Also known as Poseidon. FindPOS, also known as Poseidon, is a point-of-sale malware family designed to steal credit card information.
- FindZip ransomware
- FindZip is a ransomware that targets macOS systems.
- Fire Chili rootkit
- The purpose of this rootkit/driver is hiding and protecting malicious artifacts from user-mode components(e.g.
- FireBird RAT rat
- FireBird RAT is a remote access trojan often used in cyber-espionage activities targeting critical sectors like government and healthcare.
- FireCrypt ransomware
- FireCrypt is a ransomware known for encrypting files and demanding ransom payments from victims.
- FireMalv trojanspyware
- FireMalv is a trojan known for targeting financial services and government sectors in various countries, including the US, UK, and Russia.
- FireWood trojanbackdoor
- FireWood is a sophisticated malware family primarily used for cyber espionage.
- Fireball
- Fireball is a type of adware that takes over browsers, turning them into zombies to generate ad revenue for the attacker.
- First ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- FirstRansom ransomware
- FirstRansom is a ransomware family known for targeting financial services, healthcare, and government sectors.
- FishMaster loader
- Also known as JollyJellyfish. FishMaster, also known as JollyJellyfish, is a custom loader designed for deploying CobaltStrike beacons.
- FjordPhantom trojanspyware
- FjordPhantom is a malicious Android application first discovered in September 2024 with targets in Southeast Asia, specifically Indonesia…
- Flagpro downloader
- Also known as BUSYICE. Flagpro is a Windows-based, first-stage downloader that has been used by BlackTech since at least October 2020.