Malware Families page 2 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Abyss Locker ransomware
- Also known as elf.hellokitty. Family based on HelloKitty Ransomware. Encryption algorithm changed from AES to ChaCha. Sample seems to be unpacked.
- AcidBox exploit-kitrootkit
- Also known as MagicScroll. Unit42 found AcidBox in February 2019 and describes it as a malware family used by an unknown threat actor in 2017 against Russian…
- AcidPour wiper
- AcidPour is a variant of AcidRain designed to impact a wider range of x86 architecture Linux devices.
- AcidRain wiper
- AcidRain is an ELF binary targeting modems and routers using MIPS architecture.
- AcridRain credential-stealer
- AcridRain is a password stealer written in C/C++.
- Acronym ratspyware
- Acronym is a sophisticated remote access tool (RAT) used primarily for cyber espionage.
- Acroware Cryptolocker Ransomware ransomware
- Also known as Acroware Screenlocker. Leo discovered a screenlocker that calls itself Acroware Cryptolocker Ransomware.
- Action RAT rat
- Action RAT is a remote access tool written in Delphi that has been used by SideCopy since at least December 2021 against Indian and…
- ActionSpy spywarerat
- Also known as AxeSpy. ActionSpy, also known as AxeSpy, is an Android malware family primarily used for espionage.
- AdFind
- AdFind is a free command-line query tool that can be used for gathering information from Active Directory.
- AdKoob trojanspyware
- AdKoob is a Trojan and spyware primarily distributed through social media platforms.
- AdamLocker ransomware
- Adam Locker (detected as RANSOM_ADAMLOCK.A) is a ransomware that encrypts targeted files on a victim’s system but offers them a free…
- AdamLocker Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Adamantium Thief credential-stealertrojan
- Adamantium Thief is a credential-stealing trojan primarily targeting entities in the financial services and government sectors.
- AdaptixC2 rat
- AdaptixC2 is a open-source post-exploitation and adversarial emulation framework that lets penetration testers control compromised hosts…
- Adhubllka ransomware
- Adhubllka is a type of ransomware associated with TA547, primarily detected in Australia.
- AdoBot botnetrat
- AdoBot is a mobile malware primarily targeting Android devices.
- Adonis ransomware
- Adonis is a ransomware family known for encrypting victim files and demanding cryptocurrency payments.
- AdultSwine trojanspyware
- AdultSwine is a piece of Android malware that was discovered in over 60 apps on the Google Play Store, primarily targeting children.
- Adups spyware
- Adups is software that was pre-installed onto Android devices, including those made by BLU Products.
- AdvisorsBot downloader
- AdvisorsBot is a downloader named after early command and control domains that all contained the word "advisors".
- Adylkuzz cryptominer
- Adylkuzz is a malware family known for its cryptomining activities, primarily focusing on the mining of Monero cryptocurrency.
- Adzok trojan
- Adzok is a trojan malware family known for targeting sensitive industries such as financial services, government, and healthcare sectors.
- AepCrypt ransomware
- AepCrypt is a type of ransomware that encrypts files on the infected system and demands a ransom for decryption.
- AeroAdmin rat
- AeroAdmin is probably the easiest program to use for free remote access.
- Afrodita ransomware
- Afrodita is a ransomware family known for encrypting files on infected systems and demanding a ransom payment for recovery.
- AgeLocker ransomware
- AgeLocker is a ransomware family known for encrypting victim files using the Age encryption tool.
- Agenda Ransomware ransomware
- Agenda Ransomware is a type of ransomware known for targeting various industries worldwide.
- Agent Racoon backdoor
- Agent Racoon is a .NET-based backdoor malware that leverages DNS for covert C2 communication, employing randomized subdomains and Punycode…
- Agent Smith trojan
- Agent Smith is mobile malware that generates financial gain by replacing legitimate applications on devices with malicious versions that…
- Agent Tesla spywaretrojancredential-stealer
- Also known as AgenTesla, AgentTesla, Negasteal. Agent Tesla is a spyware Trojan written for the .NET framework that has been observed since at least 2014.
- Agent.btz wormrootkit
- Also known as ComRAT, Minit, Sun rootkit. Agent.btz is a worm that primarily spreads itself via removable devices such as USB drives.
- AgfSpy backdoor
- The agfSpy backdoor retrieves configuration and commands from its C&C server.
- AhMyth ratcredential-stealerscreen-capture
- According to PCrisk, Ahmyth is a Remote Access Trojan (RAT) targeting Android users.
- AhNyth Android rat
- AhNyth Android is an Android Remote Administration Tool designed to give attackers control over infected devices.
- AhRat rat
- AhRat is an Android remote access tool based on the open-source AhMyth remote access tool.
- Ahtapod backdoorrat
- Ahtapod is a backdoor malware associated with cyber espionage activities, targeting government and telecommunications sectors.
- Ahtapot botnetrat
- Ahtapot is a modular botnet and remote access trojan (RAT) primarily targeting financial institutions and government agencies in Turkey.
- AirDropBot botnetwormbackdoor
- Also known as CloudBot. AirDropBot is used to create a DDoS botnet.
- AiraCrop ransomware
- AiraCrop is a ransomware associated with the TeamXRat group.
- AiraCrop Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Airstalk spyware
- According to Unit 42, this malware steals information from browsers and uses a covert channel through the AirWatch API.
- Aisuru botnetddos
- Aisuru is a honeypot-aware variant of Mirai that primarily targets IoT devices.
- AkdoorTea rattrojan
- AkdoorTea is a simple TCP RAT. In August 2025, it was contained in a trojanized Nvidia CUDA toolkit package, delivered probably via the…
- Akemi credential-stealerkeyloggerscreen-capture
- According to VMRay, this malware family uses in interesting obfuscation technique: a trailing slash in its archive to confuse analysis…
- Akira ransomware
- Also known as Megazord. Akira ransomware, written in C++, is most prominently (but not exclusively) associated with the ransomware-as-a-service entity Akira.
- Akira (ELF) ransomware
- Also known as REDBIKE. Akira is a ransomware strain designed to attack various industries by encrypting data on Linux (ELF) systems.
- Akira (Windows) ransomware
- Also known as REDBIKE. Akira is a ransomware family known for encrypting files and demanding ransom payments primarily targeting organizations in financial…
- Akira Stealer credential-stealer
- Akira Stealer is a credential-stealing malware specializing in harvesting sensitive information such as login credentials from infected…
- Akira _v2 ransomware
- Akira _v2 is a Rust-based variant of Akira ransomware that has been in use since at least 2024.
- Ako ransomwareworm
- Also known as MedusaReborn. Once installed, Ako will attempt to delete Volume Shadow Copies and disable recovery services.
- Al-Namrood ransomware
- Al-Namrood is a ransomware strain known for encrypting files and demanding a ransom.
- Albaniiutas trojan
- Also known as BlueTraveller. Albaniiutas, also known as BlueTraveller, is a malware family primarily targeting governmental entities.
- Albertino Advanced RAT rat
- Albertino Advanced RAT is a sophisticated remote access trojan used primarily for cyber espionage.
- Album Stealer credential-stealerdropper
- The Zscaler ThreatLabz research team has spotted a new information stealer named Album.
- Alcatraz Locker Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Alco ransomware
- Alco is a ransomware family that encrypts victims' files and demands a ransom payment for decryption.
- Aldibot botnetcredential-stealerddos
- According to Trend Micro Encyclopia: ALDIBOT first appeared in late August 2012 in relevant forums.
- Alfonso Stealer credential-stealer
- Alfonso Stealer is a credential-stealing malware targeting sensitive information from various industries.
- Alien trojanratbotnet
- Also known as AlienBot. According to ThreatFabric, this is a fork of Cerberus v1 (active January 2020+).
- Alina POS trojan
- Also known as alina_eagle, alina_spark, katrina. Alina POS is a point-of-sale malware family primarily used to steal payment card data from infected systems.
- AllCry ransomware
- AllCry is a type of ransomware known for encrypting files on the victim's machine and demanding a ransom for decryption.
- All_Your_Documents Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- AllaKore rat
- AllaKore is a simple Remote Access Tool written in Delphi, first observed in 2015 but still in early stages of development.
- AllaSenha credential-stealerrat
- According to HarfangLabs, AllaSenha is specifically aimed at stealing credentials that are required to access Brazilian bank accounts…
- Allaple worm
- Also known as Starman. Allaple is a computer worm known for spreading through network shares and vulnerable systems.
- AllcomeClipper trojan
- Allcome is classified as a clipper malware.
- AlldataLocker ransomware
- AlldataLocker is a ransomware family that encrypts victim data and demands payment for file restoration.
- Allwinner backdoor
- Allwinner is a company that supplies processors used in Android tablets and other devices.
- Alma Communicator rat
- Alma Communicator is a remote access tool designed for espionage purposes, primarily targeting government, financial, and energy sectors…
- Alma Ransomware ransomware
- Also known as Alma Locker. Alma Ransomware, also known as Alma Locker, is a type of malware that encrypts a user's data and demands a ransom for the decryption key.
- AlmaLocker ransomware
- AlmaLocker is a ransomware family that emerged in 2016.
- Almanahe rat
- Almanahe is a remote access trojan (RAT) used primarily for cyber-espionage purposes.
- AlmondRAT (Windows) rat
- According to Threatray, AlmondRAT is a .NET Remote Access Trojan deployed by the Bitter APT group.
- Alpha Ransomware ransomware
- Also known as AlphaLocker. Alpha Ransomware, also known as AlphaLocker, is a type of ransomware that encrypts victims' files and demands a ransom for decryption.
- AlphaLocker ransomware
- A new form of ransomware named AlphaLocker that is built by cybercriminals for cybercriminals.
- AlphaNC ransomware
- AlphaNC is a ransomware family known for encrypting files and demanding ransom payments from victims.
- AlphaSeed trojanbackdoor
- AlphaSeed is a sophisticated trojan and backdoor malware family known for targeting financial services, government entities, and…
- Alphabet Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Alreay rat
- Alreay is a remote access trojan that uses HTTP(S) or TCP for communication with its C&C server.
- Alureon rootkit
- Also known as Olmarik, Pihar, TDL. Alureon, also known as Olmarik or TDSS, is a malware family primarily recognized for its rootkit capabilities.
- Amadey botnettrojandownloader
- Amadey is a Trojan bot that has been used since at least October 2018.
- Amatera credential-stealer
- Amatera is a stealer written in C++. It conducts anti-sandbox analysis before enumerating browsers, exfiltrating found cryptocurrency…
- Amavaldo Banking Trojan trojanbackdoor
- Amavaldo is banking trojan writen in Delphi and known to targeting Spanish or Portuguese speaking countries.
- AmexTroll trojan
- AmexTroll is a malware family primarily targeting financial services and government sectors.
- Amjixius ransomware
- Also known as Ancrypted. Amjixius, also known as Ancrypted, is a ransomware family that encrypts the victim's files and demands a ransom for their decryption.
- Ammyy Admin rat
- Also known as Ammyy. Ammyy Admin is a completely portable remote access program that's extremely simple to setup.
- Amnesia ransomware
- Amnesia is a ransomware that encrypts files on infected systems, demanding a ransom for the decryption key.
- Amnesia RAT ratcredential-stealerscreen-capture
- According to Fortinet, Amnesia RAT is written in Python and designed for broad, multi-category data theft combined with real-time…
- Amnesia-2 ransomware
- Amnesia-2 is a ransomware targeting IoT devices, particularly focusing on surveillance systems.
- AmpleBot credential-stealertrojan
- Also known as BlackRock. This malware was initially named BlackRock and later renamed to AmpleBot.
- AnDROid ransomware
- AnDROid is a ransomware variant targeting Android devices.
- Anatova ransomware
- Anatova is a family of ransomware known for its advanced obfuscation techniques and ability to spread through various infected applications.
- Anatova Ransomware ransomware
- Anatova is a ransomware family with the goal of ciphering all the files that it can and then requesting payment from the victim.
- Anatsa trojancredential-stealer
- Also known as ReBot, TeaBot, Toddler. Anatsa, also known as ReBot, TeaBot, and Toddler, is a banking Trojan targeting Android devices in multiple European countries.
- Anchor backdoorrat
- Also known as Anchor_DNS. Anchor is one of a family of backdoor malware that has been used in conjunction with TrickBot on selected high profile targets since at…
- AnchorDNS backdoor
- Backdoor deployed by the TrickBot actors.
- AnchorMTea loaderbackdoor
- Recon/Loader malware attributed to Lazarus, disguised as Notepad++ shell extension.
- AnchorMail backdoortrojan
- Also known as ANCHOR.MAIL, Delegatz. AnchorMail is a sophisticated backdoor, part of the Anchor family, often associated with TrickBot group operations.
- Andardoor backdoor
- Also known as ROCKHATCH. Andardoor, also known as ROCKHATCH, is a backdoor malware associated with cyber espionage activities, particularly targeting government…