Malware Families page 19 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Flame spywareworm
Also known as Flamer, sKyWIper. Flame is a sophisticated toolkit that has been used to collect information since at least 2010, largely targeting Middle East countries.
Flamingo ransomware
Flamingo is a type of ransomware designed to encrypt files on a victim's system and demand a ransom for decryption.
FlashBack trojan
Also known as FakeFlash. FlashBack is a family of Mac OS X malware that masquerades as a legitimate Adobe Flash Player installer.
FlashDevelop loader
FlashDevelop is identified as a shellcode loader according to Intezer, designed to load and execute shellcode in a target environment.
FlatChestWare ransomware
FlatChestWare is a variant of the HiddenTear ransomware that remains decryptable, meaning victims can recover their files without paying a…
Flatcher3 ransomware
Flatcher3 is a ransomware variant known for encrypting victims' files and demanding payment in cryptocurrency for the decryption key.
FlawedAmmy ratscreen-capturecredential-stealer
During the month of October, Check Point researchers discovered a widespread malware campaign spreading a remote access trojan (dubbed…
FlawedAmmyy rat
FlawedAmmyy is a remote access tool (RAT) that was first seen in early 2016.
FlawedGrace rat
Also known as GraceWire. FlawedGrace is a fully featured remote access tool (RAT) written in C++ that was first observed in late 2017.
Flesh Stealer credential-stealerspywaretrojan
According to M4lcode, FleshStealer is a sophisticated, modular, and obfuscated .NET-based information-stealing malware designed for…
FlexNet trojan
Also known as gugi. FlexNet, also known as Gugi, is a mobile banking trojan targeting Android devices.
FlexiSpy spyware
FlexiSpy is sophisticated surveillanceware for iOS and Android.
FlexiSpy (Android) spyware
FlexiSpy is a powerful Android spyware used for monitoring and surveillance.
FlexiSpy (Windows) spywarekeylogger
FlexiSpy is commercial spyware known for its capability to monitor and harvest information from the infected devices.
FlexiSpy (symbian) spyware
FlexiSpy is a commercial spyware application that targets the Symbian operating system to perform surveillance activities on mobile devices.
FlexibleFerret rat
FlexibleFerret is a remote access tool (RAT) known for its adaptable features that allow operators to control compromised systems.
FlixOnline trojanspyware
FlixOnline is an Android malware, first detected in early 2021, believed to target users of WhatsApp.
Flodrix credential-stealertrojan
Flodrix is a credential-stealing trojan that targets financial services and technology sectors, primarily in the United States and United…
FlokiBot trojancredential-stealer
FlokiBot is a banking Trojan that targets financial institutions and retail sectors by stealing sensitive information such as credentials.
Flotera Ransomware ransomware
Flotera Ransomware is a malicious software strain known for encrypting files on compromised systems and demanding payment for their release.
FlowCloud rat
FlowCloud is a remote access trojan with capabilities to exfiltrate data and control infected systems remotely.
FlowEncrypt ransomware
FlowEncrypt is a ransomware variant that encrypts files on an infected system and demands a ransom payment for decryption.
FlowerPower credential-stealertrojan
Also known as BoBoStealer. FlowerPower, also known as BoBoStealer, is a credential-stealing malware primarily targeting financial institutions and government entities.
FlowerShop backdoorrat
FlowerShop is a sophisticated cyber espionage malware family used primarily for targeted attacks against government and financial sectors.
Floxif downloaderdropper
Floxif is a malware primarily known for being involved in supply chain attacks, where it was used to download additional malicious payloads.
FluBot trojancredential-stealerbotnet
Also known as Cabassous, FakeChat. FluBot is a multi-purpose mobile banking malware that was first observed in Spain in late 2020.
FluHorse credential-stealertrojan
According to Check Point, this malware features several malicious Android applications that mimic legitimate applications, most of which…
Fluffy-TAR ransomware
Fluffy-TAR is a ransomware strain that encrypts files and demands a ransom for decryption keys.
Flusihoc botnetddos
Available since 2015, Flusihoc is a versatile C++ malware capable of a variety of DDoS attacks as directed by a Command and Control server.
FlyStudio trojanspyware
FlyStudio is a malware family primarily used for espionage activities.
FlyTrap trojancredential-stealer
FlyTrap is an Android trojan, first detected in March 2021, that uses social engineering tactics to compromise Facebook accounts.
FlyingDutchman ransomwaredropper
FlyingDutchman is a ransomware known for targeting financial services and transportation industries.
Flyper ransomware
Flyper is a ransomware based on the open-source projects EDA2 and HiddenTear.
FoalShell webshell
According to BI.ZONE, FoalShell is a simple reverse shell used by Cavalry Werewolf, written in Go, C++, and C#.
Fobber trojan
Fobber is a trojan-type malware known for its ability to steal sensitive information.
Fodcha botnetddos
Fodcha is a malware used to operate a DDoS botnet, launching distributed denial-of-service attacks against targeted entities.
Fog ransomware
According to SentinelOne, Fog Ransomware emerged in April of 2024 with operations targeting both Windows and Linux endpoints.
FoggyWeb backdoor
FoggyWeb is a passive and highly-targeted backdoor capable of remotely exfiltrating sensitive information from a compromised Active…
Fonco ransomware
Ransomware contact email [email protected] also as prefix in encrypted file contents
FonixCrypter ransomware
FonixCrypter is a type of ransomware that encrypts victim files and demands a ransom for decryption.
FontOnLake ratrootkitcredential-stealer
This family utilizes custom modules allowing for remote access, credential harvesting (e.g.
Fooder loaderrat
Fooder is a custom 64-bit C/C++ loader used by MuddyWater that can decrypt and reflectively load embedded payloads such as a go-socks5…
ForestTiger ratspyware
Also known as ScoringMathTea. ForestTiger is an advanced persistent threat group known for using remote access trojans and spyware in their campaigns.
Forfiles
Forfiles is a Windows utility commonly used in batch jobs to execute commands on one or more selected files or directories (ex: list all…
Forma Ransomware ransomware
Also known as FORMA. Forma Ransomware is a family of malicious software designed to encrypt data on compromised systems and demand a ransom from victims for…
Formbook credential-stealerkeyloggertrojan
Also known as win.xloader. FormBook contains a unique crypter RunPE that has unique behavioral patterns subject to detection.
FormerFirstRAT rat
Also known as ffrat. FormerFirstRAT is a remote access tool often associated with cyber espionage activities targeting government, technology, and defense…
FortuneCookie ransomware
FortuneCookie is a type of ransomware known for encrypting files and demanding ransom from its victims.
FortuneCrypt ransomware
FortuneCrypt is a ransomware family known for encrypting victims' files and demanding a ransom for decryption.
FoxSocket ransomware
FoxSocket is a ransomware family known for encrypting files and demanding payment in cryptocurrency for decryption.
Foxy ransomware
Foxy is a ransomware known for encrypting files on infected systems and demanding payment for decryption keys.
FrameworkPOS trojan
Also known as Trinity, SCRAPMINT, trinity. FrameworkPOS is a point of sale (POS) malware used by FIN6 to steal payment card data from sytems that run physical POS devices.
Free-Freedom ransomware
Also known as Roga. Free-Freedom, also known as Roga, is a ransomware that demands an unlock code provided to victims.
Freecivilian rat
Freecivilian is a Remote Access Trojan (RAT) used primarily for cyber espionage.
Freeme ransomware
Also known as Freezing. Freezing crypto ransomware encrypts user data using AES, and then requires a ransom in # BTC to return the files.
Freenki Loader loader
Also known as SHUTTERSPEED. Freenki Loader, also known as SHUTTERSPEED, is a malware loader used to deliver additional malicious payloads.
Freshdesk ransomware
Freshdesk is a ransomware that encrypts victims' files and demands a ransom for decryption.
FriendlyFerret spyware
FriendlyFerret is a form of spyware designed to infiltrate networks, often targeting educational institutions and tech companies.
FrigidStealer credential-stealerspyware
According to Proofpoint, FrigidStealer FrigidStealer uses Apple script files and osascript to prompt the user to enter their password, and…
FritzFrog botnetworm
Guardicore has discovered FritzFrog, a sophisticated peer-to-peer (P2P) botnet which has been actively breaching SSH servers since January…
Frog ransomware
Frog is a ransomware strain that encrypts files on the infected systems, demanding a ransom payment for decryption.
FrostyFerret rat
FrostyFerret is a remote access tool (RAT) that has been primarily used for cyber espionage activities.
FrostyGoop trojan
Also known as BUSTLEBERM. FrostyGoop is a Windows-based binary written in Golang that allows for interaction with industrial control system (ICS) equipment via…
FrozenCell spywarerat
FrozenCell is the mobile component of a family of surveillanceware, with a corresponding desktop component known as KasperAgent and…
FrozrLock ransomware
FrozrLock is a ransomware that encrypts files on affected systems and demands a ransom for file decryption.
FruitFly spyware
Also known as Quimitchin. FruitFly is a piece of spyware designed to target macOS systems, employing methods to capture screenshots and log keystrokes.
Fs0ciety trojanrat
Fs0ciety is a remote access trojan used by advanced persistent threat groups.
Fs0ciety Locker Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Fsteam
FuckSociety Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
FuckTheSystem ransomware
FuckTheSystem is a type of ransomware that encrypts files on the victim's system and demands a ransom for decryption.
FudModule rootkittrojan
Also known as LIGHTSHOW. FudModule is a user-mode DLL that gets the ability to read and write arbitrary kernel memory via the BYOVD technique.
FunFact Ransomware ransomware
Funfact uses an open code for GNU Privacy Guard (GnuPG), then asks to email them to find out the amout of bitcoin to send (to receive a…
FunkyBot botnet
FunkyBot is a malware family known for operating as a botnet.
FunnyDream backdoor
FunnyDream is a backdoor with multiple components that was used during the FunnyDream campaign since at least 2019, primarily for…
FunnySwitch backdoorrat
Also known as RouterGod. FunnySwitch, also known as RouterGod, is a remote access tool that targets network devices, primarily in the telecommunications and…
FurBall spyware
According to Check Point, they uncovered an operation dubbed "Domestic Kitten", which uses malicious Android applications to steal…
Furtim rootkit
Furtim is a stealthy rootkit primarily targeting industrial control systems within energy and utilities sectors.
Fury ransomware
Fury is a ransomware known for encrypting files on victim machines to demand a ransom payment for decryption keys.
FusionDrive trojanransomware
FusionDrive is a sophisticated malware family primarily targeting the technology and financial sectors.
Fusob ransomware
Fusob is one of the major mobile ransomware families.
FuwuqiDrama rat
FuwuqiDrama is a server-side RAT. It manages client connections by utilizing I/O completion ports, which are usually used in…
FuxSocy ransomware
FuxSocy has some similarities to win.cerber but is tracked as its own family for now.
FuxSocy Encryptor ransomware
FuxSocy Encryptor is a ransomware strain known for encrypting victims' files and demanding a ransom for decryption.
Fuxnet trojanwiper
Fuxnet is malware designed to impact the industrial network infrastructure managing control system sensors for utility operations in Moscow.
Fysbis backdoor
Fysbis is a Linux-based backdoor used by APT28 that dates back to at least 2014.
GAMYBEAR rat
GAMYBEAR A software tool developed using the Go programming language.
GC47 Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
GCleaner trojan
GCleaner is a trojan known for disguising itself as a legitimate system utility to conduct malicious activities on infected systems.
GEARSHIFT dropperkeylogger
According to FireEye, GEARSHIFT is a memory-only dropper for two keylogger DLLs.
GEMCUTTER downloader
According to FireEye, GEMCUTTER is used in a similar capacity as BACKBEND (downloader), but maintains persistence by creating a Windows…
GG Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
GGLdr loader
GGLdr is a malware loader often used for delivering various payloads to compromised systems.
GHAMBAR ratkeyloggerscreen-capture
According to Mandiant, GHAMBAR is a remote administration tool (RAT) that communicates with its C2 server using SOAP requests over HTTP.
GHOSTBLADE spyware
According to Google, GHOSTBLADE is delivered via the DarkSword exploit chain.
GIFTEDCROOK credential-stealer
According to CERT-UA, this stealer used by UAC-0226 is written in C/C++, targeting browser databases and using telegram for data…
GIMMICK (OS X) backdoor
This multi-platform malware is a ObjectiveC written macOS variant dubbed GIMMICK by Volexity.
GIMMICK (Windows) rat
GIMMICK is a Windows remote access trojan associated with cyber-espionage activities.
GLASSTOKEN webshell
GLASSTOKEN is a custom web shell used by threat actors during Cutting Edge to execute commands on compromised Ivanti Secure Connect VPNs.
GLOOXMAIL trojan
Also known as Trojan.GTALK. GLOOXMAIL is malware used by APT1 that mimics legitimate Jabber/XMPP traffic.