Malware Families page 18 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

FLKR Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
FONIX ransomware
FONIX is a ransomware family known for encrypting victims' files and demanding a ransom for decryption.
FPSpy spywarebackdoor
FPSpy is a sophisticated spyware used for cyber-espionage, primarily targeting government, telecommunication, and financial sectors.
FRAMESTING webshell
FRAMESTING is a Python web shell that was used during Cutting Edge to embed into an Ivanti Connect Secure Python package for command…
FROZENHILL loaderdropper
FROZENHILL is a launcher written in C++ that is configured to utilize existing files for execution and also infects newly attached storage…
FRP backdoor
FRP, which stands for Fast Reverse Proxy, is an openly available tool that is capable of exposing a server located behind a firewall or…
FRS ransomware
FRS is a ransomware that encrypts files on infected systems, demanding a ransom for their release.
FRat rat
A RAT employing Node.js, Sails, and Socket.IO to collect information on a target
FRat Loader loader
Loader used to deliver FRat (see family windows.frat)
FScrypt ransomware
FScrypt is a ransomware that encrypts files on the victim's system and demands a ransom for decryption.
FSociety ransomware
FSociety is a ransomware strain derived from EDA2 and RemindMe.
FTCode ransomwareloader
A targeted email campaign has been spotted distributing the JasperLoader to victims.
FULLHOUSE backdoor
Fullhouse (AKA FULLHOUSE.DOORED) is a custom backdoor used by subsets of the North Korean Lazarus Group.
FULLMETAL trojanbackdoor
FULLMETAL is a sophisticated malware family used for cyber-espionage, particularly targeting the defense and aerospace sectors in the…
FYAnti loader
Also known as DILLJUICE stage2. FYAnti is a loader that has been used by menuPass since at least 2020, including to deploy QuasarRAT.
FabSysCrypto Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Fabiansomware ransomware
Fabiansomware is a type of ransomware that encrypts files on infected systems and demands a ransom payment for decryption keys.
Fabookie credential-stealer
Fabookie malware is designed to steal Facebook account information, targeting individuals and organizations involved with social media…
FaceStealer credential-stealer
FaceStealer is a credential-stealing malware that primarily targets Facebook credentials.
Facebook HT ransomware
Facebook HT is a ransomware that encrypts files on infected systems, demanding a ransom for decryption keys.
Facefish backdoortrojan
Facefish is a Linux-based malware that acts as a backdoor and trojan to steal sensitive information from targeted systems.
Fadesoft Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
FailyTale rat
FailyTale is a Remote Access Trojan (RAT) used for espionage, primarily targeting government and technology sectors.
Fairware ransomware
Fairware is a ransomware targeting Linux operating systems.
Faizal ransomware
Faizal is a ransomware that encrypts files and demands a ransom payment for decryption keys.
Fakben ransomware
Fakben is a ransomware variant based on the Hidden Tear project, aimed at encrypting files and demanding ransom for decryption keys.
Fake Cerber ransomware
Fake Cerber is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
Fake DMA ransomware
Fake DMA is a ransomware variant that targets various industries, impacting financial, healthcare, and technology sectors.
Fake Globe Ransomware ransomware
Also known as Globe Imposter, GlobeImposter. It’s directed to English speaking users, therefore is able to infect worldwide.
Fake Locky Ransomware ransomware
Also known as Locky Impersonator Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
Fake Pornhub trojan
Fake Pornhub is a trojan that masquerades as a legitimate adult application to lure victims into installing it.
FakeAdBlocker trojan
FakeAdBlocker is a malicious software masquerading as a legitimate ad-blocking tool.
FakeCry ransomware
Malware written in .NET that mimics WannaCry.
FakeCryptoLocker ransomware
FakeCryptoLocker is a type of ransomware that encrypts files on an infected system and demands a ransom payment for decryption.
FakeDefend ransomware
FakeDefend is a type of ransomware that specifically targets Android mobile devices.
FakeGram trojancredential-stealer
Also known as FakeTGram. FakeGram is a trojan that mimics legitimate messaging applications to steal user credentials.
FakeM backdoor
FakeM is a shellcode-based Windows backdoor that has been used by Scarlet Mimic.
FakeRean trojan
Also known as Braviax. FakeRean, also known as Braviax, is a trojan that masquerades as legitimate security software.
FakeSpy spyware
FakeSpy is Android spyware that has been operated by the Chinese threat actor behind the Roaming Mantis campaigns.
FakeTC
FakeTC is a type of malware with limited information publicly available.
FakeUpdateRU downloader
FakeUpdateRU is a malicious JavaScript code injected into compromised websites to deliver further malware using the drive-by download…
FakeWord trojancredential-stealer
FakeWord is a trojan malware often used in phishing attacks to steal credentials.
Fakecalls trojanspyware
Fakecalls is an Android trojan, first detected in January 2021, that masquerades as South Korean banking apps.
Fanny wormexploit-kit
Also known as DEMENTIAWHEEL. Fanny is a USB-propagated worm discovered in 2008, used primarily for reconnaissance and weapon delivery in the Middle East and South Asia.
Fantom ransomware
Also known as Comrad Circle. Fantom is a ransomware based on EDA2 that pretends to be a legitimate Windows update.
FantomCrypt ransomware
According to PCrisk, Fantom is a ransomware-type virus that imitates the Windows update procedure while encrypting files.
Farseer rat
Farseer is a Windows-based Remote Access Trojan (RAT) known for targeting government and public sector organizations, particularly in…
FartPlz ransomware
FartPlz is a ransomware known for encrypting victim files and demanding a ransom for decryption.
FastCash trojan
FastCash is a trojan primarily used for ATM cash-out operations.
FastFire downloaderbotnet
FastFire is a malware family known for its capability to quickly infiltrate networks and propagate through systems.
FastLoader downloaderscreen-capture
FastLoader is a small .NET downloader, which name comes from PDB strings seen in samples.
FastPOS credential-stealer
FastPOS is a malware family designed to target point-of-sale systems by stealing payment card data.
FastSpy spywarerat
FastSpy is a remote access tool designed for cyber espionage, primarily targeting government, tech, and defense industries.
Fastwind ransomware
Fastwind is a ransomware that encrypts files on the victim's system and demands a ransom for decryption.
FatDuke backdoor
FatDuke is a backdoor used by APT29 since at least 2016.
FatalRat ratkeylogger
Also known as Sainbox RAT. FatalRAT is a most-likely chinese remote access tool distributed through forums and Telegram channels.
Fauppod trojan
Fauppod is a type of trojan malware. It is part of a broader malware family used for unauthorized access or damage to systems.
FeedLoad downloadertrojan
FeedLoad is a sophisticated downloader trojan used primarily to deliver other malicious payloads onto compromised systems.
Felipe trojancredential-stealer
The Zscaler ThreatLabZ team came across a new strain of infostealer Trojan called Felipe, which silently installs itself onto a user’s…
Felismus backdoor
Felismus is a modular backdoor that has been used by Sowbug.
Felismus RAT rat
Felismus RAT is a remote access trojan used by the cyber espionage group Sowbug.
Fenix rat
Fenix is a remote access trojan (RAT) family used in various cyber espionage operations.
FenixLocker ransomware
FenixLocker is a type of ransomware that encrypts victim files and demands a ransom for decryption.
Fenrir ransomware
Fenrir is a type of ransomware that encrypts the victim's files and demands a ransom for the decryption key.
Feodo credential-stealertrojanbotnet
Also known as Bugat, Cridex. Feodo (also known as Cridex or Bugat) is a Trojan used to commit e-banking fraud and to steal sensitive information from the victims…
Ferocious downloader
Ferocious is a first stage implant composed of VBS and PowerShell scripts that has been used by WIRTE since at least 2021.
Fgdump credential-stealer
Fgdump is a tool specifically designed to dump Windows password hashes, often used by attackers to crack or abuse credentials.
Ficker Stealer credential-stealerdownloaderspyware
According to CyberArk, this malware is used to steal sensitive information, including login credentials, credit card information…
Fickle Stealer credential-stealer
Fickle Stealer is a credential-stealing malware designed to pilfer sensitive information like user credentials and financial data.
File Ripper ransomware
File Ripper is a type of ransomware designed to encrypt files on a victim's system, demanding a ransom for the decryption key.
File Spider ransomware
Also known as Spider. A new ransomware called File Spider is being distributed through spam that targets victims in Bosnia and Herzegovina, Serbia, and Croatia.
File-Locker ransomware
The File-Locker Ransomware is a Hidden Tear variant that is targeting victims in Korea.
FileCoder ransomware
Also known as FindZip, Patcher. A barely functional piece of macOS ransomware, written in Swift.
FileEngineering ransomware
FileEngineering is a ransomware that encrypts files on infected systems, demanding a ransom for decryption keys.
FileFuck ransomware
FileFuck is a ransomware family known for targeting various sectors, including financial services and healthcare.
FileIce credential-stealer
FileIce is malware associated with credential theft, designed to harvest user credentials from the victim's system.
FileLocker ransomware
FileLocker is a type of ransomware that encrypts files on the victim's system and demands a ransom in exchange for the decryption key.
Fileice Ransomware Survey Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Filerase wiper
Filerase is a .net API-based utility capable of propagating and recursively deleting files.
FilesL0cker ransomware
FilesL0cker is a ransomware known for encrypting files and demanding a ransom from victims to restore access.
FinFisher spywarerat
Also known as FinSpy. FinFisher is a government-grade commercial surveillance spyware reportedly sold exclusively to government agencies for use in targeted and…
FinFisher (Android) spywaretrojan
FinFisher, also known as FinSpy, is a sophisticated surveillance malware often associated with government surveillance operations.
FinFisher (ELF) spywarerattrojan
FinFisher is a sophisticated spyware suite designed for targeted surveillance.
FinFisher (OS X) spywaretrojan
FinFisher (OS X) is a commercial spyware tool developed by the Gamma Group, used by entities for surveillance purposes.
FinFisher RAT ratspyware
Also known as FinSpy. FinFisher is a commercial software used to steal information and spy on affected victims.
Final ransomware
Final is a ransomware that encrypts files on the victim's machine, demanding a ransom for decryption.
Final1stspy dropper
Final1stspy is a dropper family that has been used to deliver DOGCALL.
FindPOS keyloggercredential-stealer
Also known as Poseidon. FindPOS, also known as Poseidon, is a point-of-sale malware family designed to steal credit card information.
FindZip ransomware
FindZip is a ransomware that targets macOS systems.
Fire Chili rootkit
The purpose of this rootkit/driver is hiding and protecting malicious artifacts from user-mode components(e.g.
FireBird RAT rat
FireBird RAT is a remote access trojan often used in cyber-espionage activities targeting critical sectors like government and healthcare.
FireCrypt ransomware
FireCrypt is a ransomware known for encrypting files and demanding ransom payments from victims.
FireMalv trojanspyware
FireMalv is a trojan known for targeting financial services and government sectors in various countries, including the US, UK, and Russia.
FireWood trojanbackdoor
FireWood is a sophisticated malware family primarily used for cyber espionage.
Fireball
Fireball is a type of adware that takes over browsers, turning them into zombies to generate ad revenue for the attacker.
First ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
FirstRansom ransomware
FirstRansom is a ransomware family known for targeting financial services, healthcare, and government sectors.
FishMaster loader
Also known as JollyJellyfish. FishMaster, also known as JollyJellyfish, is a custom loader designed for deploying CobaltStrike beacons.
FjordPhantom trojanspyware
FjordPhantom is a malicious Android application first discovered in September 2024 with targets in Southeast Asia, specifically Indonesia…
Flagpro downloader
Also known as BUSYICE. Flagpro is a Windows-based, first-stage downloader that has been used by BlackTech since at least October 2020.