Malware Families page 20 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- GNL Locker ransomware
- Ransomware Only encrypts DE or NL country.
- GOG Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- GOLDBACKDOOR backdoor
- GOLDBACKDOOR is a backdoor malware designed to provide unauthorized access to compromised systems.
- GONEPOSTAL backdoordropper
- Also known as Cordyceps, NOTDOOR. The malware consists of a dropper DLL and an obfuscated, password protected VbaProject.OTM file, which houses macros written for Microsoft…
- GOREVERSE backdoor
- GOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH).
- GOREshell webshell
- GOREshell is a type of web shell used for cyber espionage purposes, often deployed on compromised web servers to provide remote access to…
- GOSH
- GOSH is a malware with limited details publicly available.
- GOTROJ trojan
- GOTROJ is a sophisticated trojan typically used in targeted attacks to infiltrate systems and exfiltrate sensitive data.
- GOlden Phoenix
- GPAA ransomware
- GPAA is a ransomware strain designed to encrypt files on infected systems, demanding payment to restore access.
- GPCode ransomware
- GPCode is a family of ransomware known for encrypting user files and demanding a ransom for decryption.
- GPGQwerty ransomware
- GPGQwerty is a ransomware that encrypts files on an infected system and demands a ransom for decryption.
- GPlayed trojan
- GPlayed is an Android trojan with a broad range of capabilities.
- GRAPELOADER loader
- According to Checkpoint Research, GRAPELOADER is a newly observed initial-stage tool used for fingerprinting, persistence, and payload…
- GRAYRABBIT backdoor
- According to Mandiant, GRAYRABBIT is a lightweight and simple backdoor that supports simple file operation, system information collection…
- GREASE backdoor
- GREASE is a backdoor malware family used primarily for espionage purposes, targeting critical infrastructure sectors.
- GRIFFON backdoor
- Also known as Harpy. GRIFFON is a JavaScript backdoor utilized by the cybercriminal group FIN7, known for targeting financial services and hospitality sectors.
- GRILLMARK backdoor
- Also known as Hellsing Backdoor. This is a proxy-aware HTTP backdoor that is implemented as a service and uses the compromised system's proxy settings to access the…
- GRIMBOLT backdoorrat
- According to Mandiant, GRIMBOLT is a C#-written foothold backdoor compiled using native ahead-of-time (AOT) compilation and packed with UPX.
- GROK ransomware
- GROK is a ransomware variant known for encrypting files and demanding a ransom in Bitcoin for decryption keys.
- GRUNT rat
- Also known as Covenant. GRUNT, also known as Covenant, is a post-exploitation command and control tool primarily used in red team operations.
- GSpy spyware
- GSpy is a malware family known for utilizing a domain generation algorithm (DGA) to enhance its command and control capabilities.
- GTPDOOR backdoor
- According to haxrob, GTPDOOR is the name of Linux based malware that is intended to be deployed on systems in telco networks adjacent to…
- GUIDLOADER loader
- GUIDLOADER is a sophisticated loader malware used by threat actors to deploy additional malicious payloads on compromised systems.
- GUP Proxy Tool
- The GUP Proxy Tool is a malware tool used to create a proxy network for obfuscating traffic.
- GX40 ransomware
- GX40 is a type of ransomware that encrypts files on a victim's device, demanding a ransom for the decryption key.
- GaboonGrabber droppercredential-stealerkeylogger
- According to ANY.RUN, the GaboonGrabber is a malware developed in .NET that grabs its embedded resources to prepare multiple fileless…
- Gacrux trojanbackdoor
- Gacrux is a trojan malware family known for its backdoor capabilities, often used in cyberespionage campaigns targeting government and…
- Gaganode (Android) cryptominer
- According to Synthient, Gaganode is a decentralized bandwidth monetization service that enables both users and publishers to earn crypto…
- Gaganode (ELF) botnetcryptominer
- According to Synthient, Gaganode is a decentralized bandwidth monetization service that enables both users and publishers to earn crypto…
- Gaganode (Windows) botnetcryptominer
- According to Synthient, Gaganode is a decentralized bandwidth monetization service that enables both users and publishers to earn crypto…
- Galacti-Crypter ransomware
- Galacti-Crypter is a ransomware variant known for encrypting files on infected machines and demanding a ransom for decryption.
- GalaxyLoader loader
- GalaxyLoader is a simple .NET loader. Its name stems from the .pdb and the function naming. It seems to make use of iplogger.com for…
- GamaWiper wiper
- According to ClearSky, this is a VBS-based wiper, deployed via exploitation of a vulnerable WinRAR version (CVE-2025-80880).
- GameOver ransomwarebotnet
- GameOver is a sophisticated ransomware that funds its operators by extorting payments from its victims.
- GamePlayerFramework rat
- GamePlayerFramework is a sophisticated remote access trojan primarily used for cyber espionage.
- Gameover DGA botnetcredential-stealertrojan
- Gameover DGA is a variant of the Gameover Zeus malware family, known for its use of a Domain Generation Algorithm to create command and…
- Gameover P2P botnetcredential-stealerransomware
- Also known as GOZ, Gameover ZeuS, Mapp. Gameover ZeuS is a peer-to-peer botnet based on components from the earlier ZeuS trojan.
- GammA ransomware
- GammA is a type of ransomware designed to encrypt the victim's files and demand a ransom for decryption.
- Gamotrol trojanspyware
- Gamotrol is a relatively new malware family known for targeting critical sectors such as financial services and government institutions.
- GandCrab ransomwareexploit-kit
- Also known as GrandCrab. A new ransomware called GandCrab was released towards the end of last week that is currently being distributed via exploit kits.
- GarryWeber Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Gasket backdoorransomware
- A backdoor used by Mespinoza ransomware gang to maintain access to a compromised network.
- Gaudox loaderrootkit
- Gaudox is a http loader, written in C/C++.
- Gauss credential-stealerspyware
- Gauss is an advanced espionage toolkit discovered in 2012, designed for cyber-espionage activities in the Middle East, with a focus on…
- Gazavat backdoorddostrojan
- Gazavat (which is often tagged as Expiro by AV vendors) is a multi-functional backdoor that has code overlaps with the POS malware DMSniff.
- Gazer backdoor
- Also known as WhiteBear. Gazer is a backdoor used by Turla since at least 2016.
- Gdrive downloaderspyware
- Also known as DoomDrive, GoogleDriveSucks. According to Unit 42, this is a .NET X64 malware that is capable of interaction with GoogleDrive, allowing an attacker to have victim…
- GearInformer spyware
- GearInformer is a type of spyware designed to extract sensitive information from targeted systems.
- Gelsemium dropperloaderbackdoor
- Also known as Gelsevirine, Gelsenicine, Gelsemine. Gelsemium is a modular malware comprised of a dropper (Gelsemine), a loader (Gelsenicine), and main (Gelsevirine) plug-ins written using…
- GeminiDuke rat
- GeminiDuke is malware that was used by APT29 from 2009 to 2012.
- Geminis3 ransomware
- Geminis3 is a ransomware family that encrypts files on infected systems, demanding a ransom for decryption.
- Gendarmerie ransomware
- Gendarmerie is a type of ransomware that encrypts files on infected devices and demands a ransom for decryption.
- Geneve ransomware
- Geneve is a ransomware that encrypts files on infected systems, demanding a ransom for decryption.
- Genobot ransomware
- Genobot is a ransomware family that encrypts the victim's files and demands a ransom for decryption keys.
- Geost trojan
- Geost is an Android banking trojan that primarily targets financial institutions in Russia, stealing credentials and intercepting SMS…
- Gerber Ransomware 1.0 ransomware
- Gerber Ransomware 1.0 is a file-encrypting malware that aims to extort victims by demanding a ransom in exchange for decryption keys.
- Gerber Ransomware 3.0 ransomware
- Gerber Ransomware 3.0 is a file-encrypting malware that demands ransom payments in cryptocurrency.
- GermanWiper ransomwarewiper
- GermanWiper is a ransomware that masquerades as a traditional file-encrypting malware but instead irreversibly wipes files.
- Get2 downloader
- Also known as FRIENDSPEAK, GetandGo. Get2 is a downloader written in C++ that has been used by TA505 to deliver FlawedGrace, FlawedAmmyy, Snatch and SDBbot.
- GetCrypt ransomwareexploit-kit
- A new ransomware is in the dark market which encrypts all the files on the device and redirects victims to the RIG exploit kit.
- GetMail credential-stealer
- GetMail is a credential-stealing malware primarily used to harvest email information.
- GetMyPass credential-stealer
- Also known as getmypos. GetMyPass is a credential-stealing malware primarily targeting payment card data from point-of-sale systems.
- Gh0stBins rat
- Also known as Gh0stBins RAT. Gh0stBins is a Remote Access Trojan (RAT) used for cyber espionage, allowing attackers to remotely control infected systems.
- Gh0stTimes rat
- Custom RAT developed by the BlackTech actor, based on the Gh0st RAT.
- Gh0stnet rat
- Also known as Remosh. Gh0stnet, also known as Remosh, is a remote access tool (RAT) commonly used in cyber-espionage campaigns.
- Ghimob trojan
- Ghimob is a trojan primarily targeting financial services in Latin American countries.
- Ghole trojanbackdoor
- Also known as CoreImpact (Modified), Gholee. Ghole, also known as Gholee, is a sophisticated malware family associated with cyber-espionage campaigns.
- GhosTEncryptor ransomware
- GhosTEncryptor is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
- Ghost RAT ratkeyloggerscreen-capture
- Also known as Farfli, Gh0st RAT, PCRat. According to Security Ninja, Gh0st RAT (Remote Access Terminal) is a trojan “Remote Access Tool” used on Windows platforms, and has been…
- GhostAdmin ratscreen-capture
- Also known as Ghost iBot. GhostAdmin is a Remote Access Trojan (RAT) known for its capabilities in screen capturing and data exfiltration, often used in…
- GhostChat trojanspyware
- According to ESET Research, GhostChat is a malicious Android app (package name com.datingbatch.chatapp) disguised to appear a legitimate…
- GhostCrypt ransomware
- GhostCrypt is a type of ransomware based on the Hidden Tear source code.
- GhostCtrl rattrojan
- GhostCtrl is a remote access trojan (RAT) that targets Android devices.
- GhostEmperor backdoorrootkit
- GhostEmperor is a sophisticated malware used by a likely APT group, targeting government and tech sectors in Asia.
- GhostHammer ransomware
- GhostHammer is a type of ransomware designed to encrypt files on infected systems and demand ransom for decryption keys.
- GhostLocker ransomware
- GhostLocker is a ransomware family known for encrypting files on infected systems and demanding a ransom for decryption.
- GhostMiner cryptominer
- GhostMiner is a sophisticated cryptocurrency mining malware that employs fileless techniques to evade detection.
- GhostPenguin backdoorrat
- GhostPenguin is a highly sophisticated remote access tool used primarily in cyber-espionage campaigns targeting government and technology…
- GhostSecret rattrojan
- GhostSecret is a sophisticated malware family associated with cyber espionage.
- GhostSocks botnet
- GhostSocks, a Golang-based proxy malware, was first advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in…
- GhostWeaver backdoorcredential-stealer
- According to TRAC Labs, the GhostWeaver backdoor not only maintains continuous, authenticated communication with its command-and-control…
- Gibberish ransomware
- Gibberish is a type of ransomware that encrypts files on the affected system, demanding a ransom for decryption.
- Gibon ransomware
- Gibon is a type of ransomware that encrypts files on the victim's machine and demands a ransom payment for their decryption.
- Giffy trojan
- Giffy is a trojan malware family that primarily targets financial services, healthcare, and government sectors.
- Gigabud ratcredential-stealerscreen-capture
- Gigabud is the name of an Android Remote Access Trojan (RAT) Android that can record the victim's screen and steal banking credentials by…
- Gingerbread ransomware
- Gingerbread is a ransomware family known for encrypting files on the victim's machine and demanding a ransom for decryption.
- Ginp trojancredential-stealer
- Ginp is an Android banking trojan that has been used to target Spanish banks.
- Ginwui rat
- Ginwui is a remote access trojan (RAT) that targets government and public sector organizations.
- Ginzo Stealer credential-stealer
- Ginzo Stealer is an information-stealing malware developed in the .NET framework.
- Gitpaste-12 botnetcryptominerworm
- Gitpaste-12 is a modular malware first observed in October 2020 targeting Linux based x86 servers, as well as Linux ARM and MIPS based IoT…
- Giyotin ransomware
- Giyotin is a ransomware identified as engaging in encrypting victims' files and demanding a ransom payment.
- Gladius ransomware
- Gladius is a formidable ransomware known for encrypting victims' files and demanding a cryptocurrency ransom for their release.
- GlanceLove trojanratkeylogger
- GlanceLove is an advanced remote access trojan (RAT) used for cyber espionage.
- GlassRAT rat
- GlassRAT is a remote access Trojan typically used for cyber espionage.
- GlassWorm worm
- GlassWorm is a worm that propagated through supply chain attacks by compromising repository credentials from victim environments and…
- Glasses credential-stealer
- Also known as Wordpress Bruteforcer. Glasses, also known as Wordpress Bruteforcer, is a malware family used for brute-forcing Wordpress sites.
- GlitchPOS credential-stealer
- GlitchPOS is a malware family designed to target point-of-sale (POS) systems.
- Globe v1 ransomware
- Also known as Purge. Globe v1, also known as Purge, is a ransomware family that encrypts files on infected systems and demands a ransom for decryption.
- Globe2 Ransomware ransomware
- Also known as Purge Ransomware. This is most likely to affect English speaking users, since the note is written in English.