Malware Families page 20 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

GNL Locker ransomware
Ransomware Only encrypts DE or NL country.
GOG Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
GOLDBACKDOOR backdoor
GOLDBACKDOOR is a backdoor malware designed to provide unauthorized access to compromised systems.
GONEPOSTAL backdoordropper
Also known as Cordyceps, NOTDOOR. The malware consists of a dropper DLL and an obfuscated, password protected VbaProject.OTM file, which houses macros written for Microsoft…
GOREVERSE backdoor
GOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH).
GOREshell webshell
GOREshell is a type of web shell used for cyber espionage purposes, often deployed on compromised web servers to provide remote access to…
GOSH
GOSH is a malware with limited details publicly available.
GOTROJ trojan
GOTROJ is a sophisticated trojan typically used in targeted attacks to infiltrate systems and exfiltrate sensitive data.
GOlden Phoenix
GPAA ransomware
GPAA is a ransomware strain designed to encrypt files on infected systems, demanding payment to restore access.
GPCode ransomware
GPCode is a family of ransomware known for encrypting user files and demanding a ransom for decryption.
GPGQwerty ransomware
GPGQwerty is a ransomware that encrypts files on an infected system and demands a ransom for decryption.
GPlayed trojan
GPlayed is an Android trojan with a broad range of capabilities.
GRAPELOADER loader
According to Checkpoint Research, GRAPELOADER is a newly observed initial-stage tool used for fingerprinting, persistence, and payload…
GRAYRABBIT backdoor
According to Mandiant, GRAYRABBIT is a lightweight and simple backdoor that supports simple file operation, system information collection…
GREASE backdoor
GREASE is a backdoor malware family used primarily for espionage purposes, targeting critical infrastructure sectors.
GRIFFON backdoor
Also known as Harpy. GRIFFON is a JavaScript backdoor utilized by the cybercriminal group FIN7, known for targeting financial services and hospitality sectors.
GRILLMARK backdoor
Also known as Hellsing Backdoor. This is a proxy-aware HTTP backdoor that is implemented as a service and uses the compromised system's proxy settings to access the…
GRIMBOLT backdoorrat
According to Mandiant, GRIMBOLT is a C#-written foothold backdoor compiled using native ahead-of-time (AOT) compilation and packed with UPX.
GROK ransomware
GROK is a ransomware variant known for encrypting files and demanding a ransom in Bitcoin for decryption keys.
GRUNT rat
Also known as Covenant. GRUNT, also known as Covenant, is a post-exploitation command and control tool primarily used in red team operations.
GSpy spyware
GSpy is a malware family known for utilizing a domain generation algorithm (DGA) to enhance its command and control capabilities.
GTPDOOR backdoor
According to haxrob, GTPDOOR is the name of Linux based malware that is intended to be deployed on systems in telco networks adjacent to…
GUIDLOADER loader
GUIDLOADER is a sophisticated loader malware used by threat actors to deploy additional malicious payloads on compromised systems.
GUP Proxy Tool
The GUP Proxy Tool is a malware tool used to create a proxy network for obfuscating traffic.
GX40 ransomware
GX40 is a type of ransomware that encrypts files on a victim's device, demanding a ransom for the decryption key.
GaboonGrabber droppercredential-stealerkeylogger
According to ANY.RUN, the GaboonGrabber is a malware developed in .NET that grabs its embedded resources to prepare multiple fileless…
Gacrux trojanbackdoor
Gacrux is a trojan malware family known for its backdoor capabilities, often used in cyberespionage campaigns targeting government and…
Gaganode (Android) cryptominer
According to Synthient, Gaganode is a decentralized bandwidth monetization service that enables both users and publishers to earn crypto…
Gaganode (ELF) botnetcryptominer
According to Synthient, Gaganode is a decentralized bandwidth monetization service that enables both users and publishers to earn crypto…
Gaganode (Windows) botnetcryptominer
According to Synthient, Gaganode is a decentralized bandwidth monetization service that enables both users and publishers to earn crypto…
Galacti-Crypter ransomware
Galacti-Crypter is a ransomware variant known for encrypting files on infected machines and demanding a ransom for decryption.
GalaxyLoader loader
GalaxyLoader is a simple .NET loader. Its name stems from the .pdb and the function naming. It seems to make use of iplogger.com for…
GamaWiper wiper
According to ClearSky, this is a VBS-based wiper, deployed via exploitation of a vulnerable WinRAR version (CVE-2025-80880).
GameOver ransomwarebotnet
GameOver is a sophisticated ransomware that funds its operators by extorting payments from its victims.
GamePlayerFramework rat
GamePlayerFramework is a sophisticated remote access trojan primarily used for cyber espionage.
Gameover DGA botnetcredential-stealertrojan
Gameover DGA is a variant of the Gameover Zeus malware family, known for its use of a Domain Generation Algorithm to create command and…
Gameover P2P botnetcredential-stealerransomware
Also known as GOZ, Gameover ZeuS, Mapp. Gameover ZeuS is a peer-to-peer botnet based on components from the earlier ZeuS trojan.
GammA ransomware
GammA is a type of ransomware designed to encrypt the victim's files and demand a ransom for decryption.
Gamotrol trojanspyware
Gamotrol is a relatively new malware family known for targeting critical sectors such as financial services and government institutions.
GandCrab ransomwareexploit-kit
Also known as GrandCrab. A new ransomware called GandCrab was released towards the end of last week that is currently being distributed via exploit kits.
GarryWeber Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Gasket backdoorransomware
A backdoor used by Mespinoza ransomware gang to maintain access to a compromised network.
Gaudox loaderrootkit
Gaudox is a http loader, written in C/C++.
Gauss credential-stealerspyware
Gauss is an advanced espionage toolkit discovered in 2012, designed for cyber-espionage activities in the Middle East, with a focus on…
Gazavat backdoorddostrojan
Gazavat (which is often tagged as Expiro by AV vendors) is a multi-functional backdoor that has code overlaps with the POS malware DMSniff.
Gazer backdoor
Also known as WhiteBear. Gazer is a backdoor used by Turla since at least 2016.
Gdrive downloaderspyware
Also known as DoomDrive, GoogleDriveSucks. According to Unit 42, this is a .NET X64 malware that is capable of interaction with GoogleDrive, allowing an attacker to have victim…
GearInformer spyware
GearInformer is a type of spyware designed to extract sensitive information from targeted systems.
Gelsemium dropperloaderbackdoor
Also known as Gelsevirine, Gelsenicine, Gelsemine. Gelsemium is a modular malware comprised of a dropper (Gelsemine), a loader (Gelsenicine), and main (Gelsevirine) plug-ins written using…
GeminiDuke rat
GeminiDuke is malware that was used by APT29 from 2009 to 2012.
Geminis3 ransomware
Geminis3 is a ransomware family that encrypts files on infected systems, demanding a ransom for decryption.
Gendarmerie ransomware
Gendarmerie is a type of ransomware that encrypts files on infected devices and demands a ransom for decryption.
Geneve ransomware
Geneve is a ransomware that encrypts files on infected systems, demanding a ransom for decryption.
Genobot ransomware
Genobot is a ransomware family that encrypts the victim's files and demands a ransom for decryption keys.
Geost trojan
Geost is an Android banking trojan that primarily targets financial institutions in Russia, stealing credentials and intercepting SMS…
Gerber Ransomware 1.0 ransomware
Gerber Ransomware 1.0 is a file-encrypting malware that aims to extort victims by demanding a ransom in exchange for decryption keys.
Gerber Ransomware 3.0 ransomware
Gerber Ransomware 3.0 is a file-encrypting malware that demands ransom payments in cryptocurrency.
GermanWiper ransomwarewiper
GermanWiper is a ransomware that masquerades as a traditional file-encrypting malware but instead irreversibly wipes files.
Get2 downloader
Also known as FRIENDSPEAK, GetandGo. Get2 is a downloader written in C++ that has been used by TA505 to deliver FlawedGrace, FlawedAmmyy, Snatch and SDBbot.
GetCrypt ransomwareexploit-kit
A new ransomware is in the dark market which encrypts all the files on the device and redirects victims to the RIG exploit kit.
GetMail credential-stealer
GetMail is a credential-stealing malware primarily used to harvest email information.
GetMyPass credential-stealer
Also known as getmypos. GetMyPass is a credential-stealing malware primarily targeting payment card data from point-of-sale systems.
Gh0stBins rat
Also known as Gh0stBins RAT. Gh0stBins is a Remote Access Trojan (RAT) used for cyber espionage, allowing attackers to remotely control infected systems.
Gh0stTimes rat
Custom RAT developed by the BlackTech actor, based on the Gh0st RAT.
Gh0stnet rat
Also known as Remosh. Gh0stnet, also known as Remosh, is a remote access tool (RAT) commonly used in cyber-espionage campaigns.
Ghimob trojan
Ghimob is a trojan primarily targeting financial services in Latin American countries.
Ghole trojanbackdoor
Also known as CoreImpact (Modified), Gholee. Ghole, also known as Gholee, is a sophisticated malware family associated with cyber-espionage campaigns.
GhosTEncryptor ransomware
GhosTEncryptor is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
Ghost RAT ratkeyloggerscreen-capture
Also known as Farfli, Gh0st RAT, PCRat. According to Security Ninja, Gh0st RAT (Remote Access Terminal) is a trojan “Remote Access Tool” used on Windows platforms, and has been…
GhostAdmin ratscreen-capture
Also known as Ghost iBot. GhostAdmin is a Remote Access Trojan (RAT) known for its capabilities in screen capturing and data exfiltration, often used in…
GhostChat trojanspyware
According to ESET Research, GhostChat is a malicious Android app (package name com.datingbatch.chatapp) disguised to appear a legitimate…
GhostCrypt ransomware
GhostCrypt is a type of ransomware based on the Hidden Tear source code.
GhostCtrl rattrojan
GhostCtrl is a remote access trojan (RAT) that targets Android devices.
GhostEmperor backdoorrootkit
GhostEmperor is a sophisticated malware used by a likely APT group, targeting government and tech sectors in Asia.
GhostHammer ransomware
GhostHammer is a type of ransomware designed to encrypt files on infected systems and demand ransom for decryption keys.
GhostLocker ransomware
GhostLocker is a ransomware family known for encrypting files on infected systems and demanding a ransom for decryption.
GhostMiner cryptominer
GhostMiner is a sophisticated cryptocurrency mining malware that employs fileless techniques to evade detection.
GhostPenguin backdoorrat
GhostPenguin is a highly sophisticated remote access tool used primarily in cyber-espionage campaigns targeting government and technology…
GhostSecret rattrojan
GhostSecret is a sophisticated malware family associated with cyber espionage.
GhostSocks botnet
GhostSocks, a Golang-based proxy malware, was first advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in…
GhostWeaver backdoorcredential-stealer
According to TRAC Labs, the GhostWeaver backdoor not only maintains continuous, authenticated communication with its command-and-control…
Gibberish ransomware
Gibberish is a type of ransomware that encrypts files on the affected system, demanding a ransom for decryption.
Gibon ransomware
Gibon is a type of ransomware that encrypts files on the victim's machine and demands a ransom payment for their decryption.
Giffy trojan
Giffy is a trojan malware family that primarily targets financial services, healthcare, and government sectors.
Gigabud ratcredential-stealerscreen-capture
Gigabud is the name of an Android Remote Access Trojan (RAT) Android that can record the victim's screen and steal banking credentials by…
Gingerbread ransomware
Gingerbread is a ransomware family known for encrypting files on the victim's machine and demanding a ransom for decryption.
Ginp trojancredential-stealer
Ginp is an Android banking trojan that has been used to target Spanish banks.
Ginwui rat
Ginwui is a remote access trojan (RAT) that targets government and public sector organizations.
Ginzo Stealer credential-stealer
Ginzo Stealer is an information-stealing malware developed in the .NET framework.
Gitpaste-12 botnetcryptominerworm
Gitpaste-12 is a modular malware first observed in October 2020 targeting Linux based x86 servers, as well as Linux ARM and MIPS based IoT…
Giyotin ransomware
Giyotin is a ransomware identified as engaging in encrypting victims' files and demanding a ransom payment.
Gladius ransomware
Gladius is a formidable ransomware known for encrypting victims' files and demanding a cryptocurrency ransom for their release.
GlanceLove trojanratkeylogger
GlanceLove is an advanced remote access trojan (RAT) used for cyber espionage.
GlassRAT rat
GlassRAT is a remote access Trojan typically used for cyber espionage.
GlassWorm worm
GlassWorm is a worm that propagated through supply chain attacks by compromising repository credentials from victim environments and…
Glasses credential-stealer
Also known as Wordpress Bruteforcer. Glasses, also known as Wordpress Bruteforcer, is a malware family used for brute-forcing Wordpress sites.
GlitchPOS credential-stealer
GlitchPOS is a malware family designed to target point-of-sale (POS) systems.
Globe v1 ransomware
Also known as Purge. Globe v1, also known as Purge, is a ransomware family that encrypts files on infected systems and demands a ransom for decryption.
Globe2 Ransomware ransomware
Also known as Purge Ransomware. This is most likely to affect English speaking users, since the note is written in English.