Malware Families page 19 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Flame spywareworm
- Also known as Flamer, sKyWIper. Flame is a sophisticated toolkit that has been used to collect information since at least 2010, largely targeting Middle East countries.
- Flamingo ransomware
- Flamingo is a type of ransomware designed to encrypt files on a victim's system and demand a ransom for decryption.
- FlashBack trojan
- Also known as FakeFlash. FlashBack is a family of Mac OS X malware that masquerades as a legitimate Adobe Flash Player installer.
- FlashDevelop loader
- FlashDevelop is identified as a shellcode loader according to Intezer, designed to load and execute shellcode in a target environment.
- FlatChestWare ransomware
- FlatChestWare is a variant of the HiddenTear ransomware that remains decryptable, meaning victims can recover their files without paying a…
- Flatcher3 ransomware
- Flatcher3 is a ransomware variant known for encrypting victims' files and demanding payment in cryptocurrency for the decryption key.
- FlawedAmmy ratscreen-capturecredential-stealer
- During the month of October, Check Point researchers discovered a widespread malware campaign spreading a remote access trojan (dubbed…
- FlawedAmmyy rat
- FlawedAmmyy is a remote access tool (RAT) that was first seen in early 2016.
- FlawedGrace rat
- Also known as GraceWire. FlawedGrace is a fully featured remote access tool (RAT) written in C++ that was first observed in late 2017.
- Flesh Stealer credential-stealerspywaretrojan
- According to M4lcode, FleshStealer is a sophisticated, modular, and obfuscated .NET-based information-stealing malware designed for…
- FlexNet trojan
- Also known as gugi. FlexNet, also known as Gugi, is a mobile banking trojan targeting Android devices.
- FlexiSpy spyware
- FlexiSpy is sophisticated surveillanceware for iOS and Android.
- FlexiSpy (Android) spyware
- FlexiSpy is a powerful Android spyware used for monitoring and surveillance.
- FlexiSpy (Windows) spywarekeylogger
- FlexiSpy is commercial spyware known for its capability to monitor and harvest information from the infected devices.
- FlexiSpy (symbian) spyware
- FlexiSpy is a commercial spyware application that targets the Symbian operating system to perform surveillance activities on mobile devices.
- FlexibleFerret rat
- FlexibleFerret is a remote access tool (RAT) known for its adaptable features that allow operators to control compromised systems.
- FlixOnline trojanspyware
- FlixOnline is an Android malware, first detected in early 2021, believed to target users of WhatsApp.
- Flodrix credential-stealertrojan
- Flodrix is a credential-stealing trojan that targets financial services and technology sectors, primarily in the United States and United…
- FlokiBot trojancredential-stealer
- FlokiBot is a banking Trojan that targets financial institutions and retail sectors by stealing sensitive information such as credentials.
- Flotera Ransomware ransomware
- Flotera Ransomware is a malicious software strain known for encrypting files on compromised systems and demanding payment for their release.
- FlowCloud rat
- FlowCloud is a remote access trojan with capabilities to exfiltrate data and control infected systems remotely.
- FlowEncrypt ransomware
- FlowEncrypt is a ransomware variant that encrypts files on an infected system and demands a ransom payment for decryption.
- FlowerPower credential-stealertrojan
- Also known as BoBoStealer. FlowerPower, also known as BoBoStealer, is a credential-stealing malware primarily targeting financial institutions and government entities.
- FlowerShop backdoorrat
- FlowerShop is a sophisticated cyber espionage malware family used primarily for targeted attacks against government and financial sectors.
- Floxif downloaderdropper
- Floxif is a malware primarily known for being involved in supply chain attacks, where it was used to download additional malicious payloads.
- FluBot trojancredential-stealerbotnet
- Also known as Cabassous, FakeChat. FluBot is a multi-purpose mobile banking malware that was first observed in Spain in late 2020.
- FluHorse credential-stealertrojan
- According to Check Point, this malware features several malicious Android applications that mimic legitimate applications, most of which…
- Fluffy-TAR ransomware
- Fluffy-TAR is a ransomware strain that encrypts files and demands a ransom for decryption keys.
- Flusihoc botnetddos
- Available since 2015, Flusihoc is a versatile C++ malware capable of a variety of DDoS attacks as directed by a Command and Control server.
- FlyStudio trojanspyware
- FlyStudio is a malware family primarily used for espionage activities.
- FlyTrap trojancredential-stealer
- FlyTrap is an Android trojan, first detected in March 2021, that uses social engineering tactics to compromise Facebook accounts.
- FlyingDutchman ransomwaredropper
- FlyingDutchman is a ransomware known for targeting financial services and transportation industries.
- Flyper ransomware
- Flyper is a ransomware based on the open-source projects EDA2 and HiddenTear.
- FoalShell webshell
- According to BI.ZONE, FoalShell is a simple reverse shell used by Cavalry Werewolf, written in Go, C++, and C#.
- Fobber trojan
- Fobber is a trojan-type malware known for its ability to steal sensitive information.
- Fodcha botnetddos
- Fodcha is a malware used to operate a DDoS botnet, launching distributed denial-of-service attacks against targeted entities.
- Fog ransomware
- According to SentinelOne, Fog Ransomware emerged in April of 2024 with operations targeting both Windows and Linux endpoints.
- FoggyWeb backdoor
- FoggyWeb is a passive and highly-targeted backdoor capable of remotely exfiltrating sensitive information from a compromised Active…
- Fonco ransomware
- Ransomware contact email [email protected] also as prefix in encrypted file contents
- FonixCrypter ransomware
- FonixCrypter is a type of ransomware that encrypts victim files and demands a ransom for decryption.
- FontOnLake ratrootkitcredential-stealer
- This family utilizes custom modules allowing for remote access, credential harvesting (e.g.
- Fooder loaderrat
- Fooder is a custom 64-bit C/C++ loader used by MuddyWater that can decrypt and reflectively load embedded payloads such as a go-socks5…
- ForestTiger ratspyware
- Also known as ScoringMathTea. ForestTiger is an advanced persistent threat group known for using remote access trojans and spyware in their campaigns.
- Forfiles
- Forfiles is a Windows utility commonly used in batch jobs to execute commands on one or more selected files or directories (ex: list all…
- Forma Ransomware ransomware
- Also known as FORMA. Forma Ransomware is a family of malicious software designed to encrypt data on compromised systems and demand a ransom from victims for…
- Formbook credential-stealerkeyloggertrojan
- Also known as win.xloader. FormBook contains a unique crypter RunPE that has unique behavioral patterns subject to detection.
- FormerFirstRAT rat
- Also known as ffrat. FormerFirstRAT is a remote access tool often associated with cyber espionage activities targeting government, technology, and defense…
- FortuneCookie ransomware
- FortuneCookie is a type of ransomware known for encrypting files and demanding ransom from its victims.
- FortuneCrypt ransomware
- FortuneCrypt is a ransomware family known for encrypting victims' files and demanding a ransom for decryption.
- FoxSocket ransomware
- FoxSocket is a ransomware family known for encrypting files and demanding payment in cryptocurrency for decryption.
- Foxy ransomware
- Foxy is a ransomware known for encrypting files on infected systems and demanding payment for decryption keys.
- FrameworkPOS trojan
- Also known as Trinity, SCRAPMINT, trinity. FrameworkPOS is a point of sale (POS) malware used by FIN6 to steal payment card data from sytems that run physical POS devices.
- Free-Freedom ransomware
- Also known as Roga. Free-Freedom, also known as Roga, is a ransomware that demands an unlock code provided to victims.
- Freecivilian rat
- Freecivilian is a Remote Access Trojan (RAT) used primarily for cyber espionage.
- Freeme ransomware
- Also known as Freezing. Freezing crypto ransomware encrypts user data using AES, and then requires a ransom in # BTC to return the files.
- Freenki Loader loader
- Also known as SHUTTERSPEED. Freenki Loader, also known as SHUTTERSPEED, is a malware loader used to deliver additional malicious payloads.
- Freshdesk ransomware
- Freshdesk is a ransomware that encrypts victims' files and demands a ransom for decryption.
- FriendlyFerret spyware
- FriendlyFerret is a form of spyware designed to infiltrate networks, often targeting educational institutions and tech companies.
- FrigidStealer credential-stealerspyware
- According to Proofpoint, FrigidStealer FrigidStealer uses Apple script files and osascript to prompt the user to enter their password, and…
- FritzFrog botnetworm
- Guardicore has discovered FritzFrog, a sophisticated peer-to-peer (P2P) botnet which has been actively breaching SSH servers since January…
- Frog ransomware
- Frog is a ransomware strain that encrypts files on the infected systems, demanding a ransom payment for decryption.
- FrostyFerret rat
- FrostyFerret is a remote access tool (RAT) that has been primarily used for cyber espionage activities.
- FrostyGoop trojan
- Also known as BUSTLEBERM. FrostyGoop is a Windows-based binary written in Golang that allows for interaction with industrial control system (ICS) equipment via…
- FrozenCell spywarerat
- FrozenCell is the mobile component of a family of surveillanceware, with a corresponding desktop component known as KasperAgent and…
- FrozrLock ransomware
- FrozrLock is a ransomware that encrypts files on affected systems and demands a ransom for file decryption.
- FruitFly spyware
- Also known as Quimitchin. FruitFly is a piece of spyware designed to target macOS systems, employing methods to capture screenshots and log keystrokes.
- Fs0ciety trojanrat
- Fs0ciety is a remote access trojan used by advanced persistent threat groups.
- Fs0ciety Locker Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Fsteam
- FuckSociety Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- FuckTheSystem ransomware
- FuckTheSystem is a type of ransomware that encrypts files on the victim's system and demands a ransom for decryption.
- FudModule rootkittrojan
- Also known as LIGHTSHOW. FudModule is a user-mode DLL that gets the ability to read and write arbitrary kernel memory via the BYOVD technique.
- FunFact Ransomware ransomware
- Funfact uses an open code for GNU Privacy Guard (GnuPG), then asks to email them to find out the amout of bitcoin to send (to receive a…
- FunkyBot botnet
- FunkyBot is a malware family known for operating as a botnet.
- FunnyDream backdoor
- FunnyDream is a backdoor with multiple components that was used during the FunnyDream campaign since at least 2019, primarily for…
- FunnySwitch backdoorrat
- Also known as RouterGod. FunnySwitch, also known as RouterGod, is a remote access tool that targets network devices, primarily in the telecommunications and…
- FurBall spyware
- According to Check Point, they uncovered an operation dubbed "Domestic Kitten", which uses malicious Android applications to steal…
- Furtim rootkit
- Furtim is a stealthy rootkit primarily targeting industrial control systems within energy and utilities sectors.
- Fury ransomware
- Fury is a ransomware known for encrypting files on victim machines to demand a ransom payment for decryption keys.
- FusionDrive trojanransomware
- FusionDrive is a sophisticated malware family primarily targeting the technology and financial sectors.
- Fusob ransomware
- Fusob is one of the major mobile ransomware families.
- FuwuqiDrama rat
- FuwuqiDrama is a server-side RAT. It manages client connections by utilizing I/O completion ports, which are usually used in…
- FuxSocy ransomware
- FuxSocy has some similarities to win.cerber but is tracked as its own family for now.
- FuxSocy Encryptor ransomware
- FuxSocy Encryptor is a ransomware strain known for encrypting victims' files and demanding a ransom for decryption.
- Fuxnet trojanwiper
- Fuxnet is malware designed to impact the industrial network infrastructure managing control system sensors for utility operations in Moscow.
- Fysbis backdoor
- Fysbis is a Linux-based backdoor used by APT28 that dates back to at least 2014.
- GAMYBEAR rat
- GAMYBEAR A software tool developed using the Go programming language.
- GC47 Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- GCleaner trojan
- GCleaner is a trojan known for disguising itself as a legitimate system utility to conduct malicious activities on infected systems.
- GEARSHIFT dropperkeylogger
- According to FireEye, GEARSHIFT is a memory-only dropper for two keylogger DLLs.
- GEMCUTTER downloader
- According to FireEye, GEMCUTTER is used in a similar capacity as BACKBEND (downloader), but maintains persistence by creating a Windows…
- GG Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- GGLdr loader
- GGLdr is a malware loader often used for delivering various payloads to compromised systems.
- GHAMBAR ratkeyloggerscreen-capture
- According to Mandiant, GHAMBAR is a remote administration tool (RAT) that communicates with its C2 server using SOAP requests over HTTP.
- GHOSTBLADE spyware
- According to Google, GHOSTBLADE is delivered via the DarkSword exploit chain.
- GIFTEDCROOK credential-stealer
- According to CERT-UA, this stealer used by UAC-0226 is written in C/C++, targeting browser databases and using telegram for data…
- GIMMICK (OS X) backdoor
- This multi-platform malware is a ObjectiveC written macOS variant dubbed GIMMICK by Volexity.
- GIMMICK (Windows) rat
- GIMMICK is a Windows remote access trojan associated with cyber-espionage activities.
- GLASSTOKEN webshell
- GLASSTOKEN is a custom web shell used by threat actors during Cutting Edge to execute commands on compromised Ivanti Secure Connect VPNs.
- GLOOXMAIL trojan
- Also known as Trojan.GTALK. GLOOXMAIL is malware used by APT1 that mimics legitimate Jabber/XMPP traffic.