Malware Families page 2 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Abyss Locker ransomware
Also known as elf.hellokitty. Family based on HelloKitty Ransomware. Encryption algorithm changed from AES to ChaCha. Sample seems to be unpacked.
AcidBox exploit-kitrootkit
Also known as MagicScroll. Unit42 found AcidBox in February 2019 and describes it as a malware family used by an unknown threat actor in 2017 against Russian…
AcidPour wiper
AcidPour is a variant of AcidRain designed to impact a wider range of x86 architecture Linux devices.
AcidRain wiper
AcidRain is an ELF binary targeting modems and routers using MIPS architecture.
AcridRain credential-stealer
AcridRain is a password stealer written in C/C++.
Acronym ratspyware
Acronym is a sophisticated remote access tool (RAT) used primarily for cyber espionage.
Acroware Cryptolocker Ransomware ransomware
Also known as Acroware Screenlocker. Leo discovered a screenlocker that calls itself Acroware Cryptolocker Ransomware.
Action RAT rat
Action RAT is a remote access tool written in Delphi that has been used by SideCopy since at least December 2021 against Indian and…
ActionSpy spywarerat
Also known as AxeSpy. ActionSpy, also known as AxeSpy, is an Android malware family primarily used for espionage.
AdFind
AdFind is a free command-line query tool that can be used for gathering information from Active Directory.
AdKoob trojanspyware
AdKoob is a Trojan and spyware primarily distributed through social media platforms.
AdamLocker ransomware
Adam Locker (detected as RANSOM_ADAMLOCK.A) is a ransomware that encrypts targeted files on a victim’s system but offers them a free…
AdamLocker Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Adamantium Thief credential-stealertrojan
Adamantium Thief is a credential-stealing trojan primarily targeting entities in the financial services and government sectors.
AdaptixC2 rat
AdaptixC2 is a open-source post-exploitation and adversarial emulation framework that lets penetration testers control compromised hosts…
Adhubllka ransomware
Adhubllka is a type of ransomware associated with TA547, primarily detected in Australia.
AdoBot botnetrat
AdoBot is a mobile malware primarily targeting Android devices.
Adonis ransomware
Adonis is a ransomware family known for encrypting victim files and demanding cryptocurrency payments.
AdultSwine trojanspyware
AdultSwine is a piece of Android malware that was discovered in over 60 apps on the Google Play Store, primarily targeting children.
Adups spyware
Adups is software that was pre-installed onto Android devices, including those made by BLU Products.
AdvisorsBot downloader
AdvisorsBot is a downloader named after early command and control domains that all contained the word "advisors".
Adylkuzz cryptominer
Adylkuzz is a malware family known for its cryptomining activities, primarily focusing on the mining of Monero cryptocurrency.
Adzok trojan
Adzok is a trojan malware family known for targeting sensitive industries such as financial services, government, and healthcare sectors.
AepCrypt ransomware
AepCrypt is a type of ransomware that encrypts files on the infected system and demands a ransom for decryption.
AeroAdmin rat
AeroAdmin is probably the easiest program to use for free remote access.
Afrodita ransomware
Afrodita is a ransomware family known for encrypting files on infected systems and demanding a ransom payment for recovery.
AgeLocker ransomware
AgeLocker is a ransomware family known for encrypting victim files using the Age encryption tool.
Agenda Ransomware ransomware
Agenda Ransomware is a type of ransomware known for targeting various industries worldwide.
Agent Racoon backdoor
Agent Racoon is a .NET-based backdoor malware that leverages DNS for covert C2 communication, employing randomized subdomains and Punycode…
Agent Smith trojan
Agent Smith is mobile malware that generates financial gain by replacing legitimate applications on devices with malicious versions that…
Agent Tesla spywaretrojancredential-stealer
Also known as AgenTesla, AgentTesla, Negasteal. Agent Tesla is a spyware Trojan written for the .NET framework that has been observed since at least 2014.
Agent.btz wormrootkit
Also known as ComRAT, Minit, Sun rootkit. Agent.btz is a worm that primarily spreads itself via removable devices such as USB drives.
AgfSpy backdoor
The agfSpy backdoor retrieves configuration and commands from its C&C server.
AhMyth ratcredential-stealerscreen-capture
According to PCrisk, Ahmyth is a Remote Access Trojan (RAT) targeting Android users.
AhNyth Android rat
AhNyth Android is an Android Remote Administration Tool designed to give attackers control over infected devices.
AhRat rat
AhRat is an Android remote access tool based on the open-source AhMyth remote access tool.
Ahtapod backdoorrat
Ahtapod is a backdoor malware associated with cyber espionage activities, targeting government and telecommunications sectors.
Ahtapot botnetrat
Ahtapot is a modular botnet and remote access trojan (RAT) primarily targeting financial institutions and government agencies in Turkey.
AirDropBot botnetwormbackdoor
Also known as CloudBot. AirDropBot is used to create a DDoS botnet.
AiraCrop ransomware
AiraCrop is a ransomware associated with the TeamXRat group.
AiraCrop Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Airstalk spyware
According to Unit 42, this malware steals information from browsers and uses a covert channel through the AirWatch API.
Aisuru botnetddos
Aisuru is a honeypot-aware variant of Mirai that primarily targets IoT devices.
AkdoorTea rattrojan
AkdoorTea is a simple TCP RAT. In August 2025, it was contained in a trojanized Nvidia CUDA toolkit package, delivered probably via the…
Akemi credential-stealerkeyloggerscreen-capture
According to VMRay, this malware family uses in interesting obfuscation technique: a trailing slash in its archive to confuse analysis…
Akira ransomware
Also known as Megazord. Akira ransomware, written in C++, is most prominently (but not exclusively) associated with the ransomware-as-a-service entity Akira.
Akira (ELF) ransomware
Also known as REDBIKE. Akira is a ransomware strain designed to attack various industries by encrypting data on Linux (ELF) systems.
Akira (Windows) ransomware
Also known as REDBIKE. Akira is a ransomware family known for encrypting files and demanding ransom payments primarily targeting organizations in financial…
Akira Stealer credential-stealer
Akira Stealer is a credential-stealing malware specializing in harvesting sensitive information such as login credentials from infected…
Akira _v2 ransomware
Akira _v2 is a Rust-based variant of Akira ransomware that has been in use since at least 2024.
Ako ransomwareworm
Also known as MedusaReborn. Once installed, Ako will attempt to delete Volume Shadow Copies and disable recovery services.
Al-Namrood ransomware
Al-Namrood is a ransomware strain known for encrypting files and demanding a ransom.
Albaniiutas trojan
Also known as BlueTraveller. Albaniiutas, also known as BlueTraveller, is a malware family primarily targeting governmental entities.
Albertino Advanced RAT rat
Albertino Advanced RAT is a sophisticated remote access trojan used primarily for cyber espionage.
Album Stealer credential-stealerdropper
The Zscaler ThreatLabz research team has spotted a new information stealer named Album.
Alcatraz Locker Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Alco ransomware
Alco is a ransomware family that encrypts victims' files and demands a ransom payment for decryption.
Aldibot botnetcredential-stealerddos
According to Trend Micro Encyclopia: ALDIBOT first appeared in late August 2012 in relevant forums.
Alfonso Stealer credential-stealer
Alfonso Stealer is a credential-stealing malware targeting sensitive information from various industries.
Alien trojanratbotnet
Also known as AlienBot. According to ThreatFabric, this is a fork of Cerberus v1 (active January 2020+).
Alina POS trojan
Also known as alina_eagle, alina_spark, katrina. Alina POS is a point-of-sale malware family primarily used to steal payment card data from infected systems.
AllCry ransomware
AllCry is a type of ransomware known for encrypting files on the victim's machine and demanding a ransom for decryption.
All_Your_Documents Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
AllaKore rat
AllaKore is a simple Remote Access Tool written in Delphi, first observed in 2015 but still in early stages of development.
AllaSenha credential-stealerrat
According to HarfangLabs, AllaSenha is specifically aimed at stealing credentials that are required to access Brazilian bank accounts…
Allaple worm
Also known as Starman. Allaple is a computer worm known for spreading through network shares and vulnerable systems.
AllcomeClipper trojan
Allcome is classified as a clipper malware.
AlldataLocker ransomware
AlldataLocker is a ransomware family that encrypts victim data and demands payment for file restoration.
Allwinner backdoor
Allwinner is a company that supplies processors used in Android tablets and other devices.
Alma Communicator rat
Alma Communicator is a remote access tool designed for espionage purposes, primarily targeting government, financial, and energy sectors…
Alma Ransomware ransomware
Also known as Alma Locker. Alma Ransomware, also known as Alma Locker, is a type of malware that encrypts a user's data and demands a ransom for the decryption key.
AlmaLocker ransomware
AlmaLocker is a ransomware family that emerged in 2016.
Almanahe rat
Almanahe is a remote access trojan (RAT) used primarily for cyber-espionage purposes.
AlmondRAT (Windows) rat
According to Threatray, AlmondRAT is a .NET Remote Access Trojan deployed by the Bitter APT group.
Alpha Ransomware ransomware
Also known as AlphaLocker. Alpha Ransomware, also known as AlphaLocker, is a type of ransomware that encrypts victims' files and demands a ransom for decryption.
AlphaLocker ransomware
A new form of ransomware named AlphaLocker that is built by cybercriminals for cybercriminals.
AlphaNC ransomware
AlphaNC is a ransomware family known for encrypting files and demanding ransom payments from victims.
AlphaSeed trojanbackdoor
AlphaSeed is a sophisticated trojan and backdoor malware family known for targeting financial services, government entities, and…
Alphabet Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Alreay rat
Alreay is a remote access trojan that uses HTTP(S) or TCP for communication with its C&C server.
Alureon rootkit
Also known as Olmarik, Pihar, TDL. Alureon, also known as Olmarik or TDSS, is a malware family primarily recognized for its rootkit capabilities.
Amadey botnettrojandownloader
Amadey is a Trojan bot that has been used since at least October 2018.
Amatera credential-stealer
Amatera is a stealer written in C++. It conducts anti-sandbox analysis before enumerating browsers, exfiltrating found cryptocurrency…
Amavaldo Banking Trojan trojanbackdoor
Amavaldo is banking trojan writen in Delphi and known to targeting Spanish or Portuguese speaking countries.
AmexTroll trojan
AmexTroll is a malware family primarily targeting financial services and government sectors.
Amjixius ransomware
Also known as Ancrypted. Amjixius, also known as Ancrypted, is a ransomware family that encrypts the victim's files and demands a ransom for their decryption.
Ammyy Admin rat
Also known as Ammyy. Ammyy Admin is a completely portable remote access program that's extremely simple to setup.
Amnesia ransomware
Amnesia is a ransomware that encrypts files on infected systems, demanding a ransom for the decryption key.
Amnesia RAT ratcredential-stealerscreen-capture
According to Fortinet, Amnesia RAT is written in Python and designed for broad, multi-category data theft combined with real-time…
Amnesia-2 ransomware
Amnesia-2 is a ransomware targeting IoT devices, particularly focusing on surveillance systems.
AmpleBot credential-stealertrojan
Also known as BlackRock. This malware was initially named BlackRock and later renamed to AmpleBot.
AnDROid ransomware
AnDROid is a ransomware variant targeting Android devices.
Anatova ransomware
Anatova is a family of ransomware known for its advanced obfuscation techniques and ability to spread through various infected applications.
Anatova Ransomware ransomware
Anatova is a ransomware family with the goal of ciphering all the files that it can and then requesting payment from the victim.
Anatsa trojancredential-stealer
Also known as ReBot, TeaBot, Toddler. Anatsa, also known as ReBot, TeaBot, and Toddler, is a banking Trojan targeting Android devices in multiple European countries.
Anchor backdoorrat
Also known as Anchor_DNS. Anchor is one of a family of backdoor malware that has been used in conjunction with TrickBot on selected high profile targets since at…
AnchorDNS backdoor
Backdoor deployed by the TrickBot actors.
AnchorMTea loaderbackdoor
Recon/Loader malware attributed to Lazarus, disguised as Notepad++ shell extension.
AnchorMail backdoortrojan
Also known as ANCHOR.MAIL, Delegatz. AnchorMail is a sophisticated backdoor, part of the Anchor family, often associated with TrickBot group operations.
Andardoor backdoor
Also known as ROCKHATCH. Andardoor, also known as ROCKHATCH, is a backdoor malware associated with cyber espionage activities, particularly targeting government…