Malware Families page 21 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Globe3 Ransomware ransomware
- Also known as Purge Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- GlobeImposter ransomware
- Also known as Fake Globe. During December 2017, a new variant of the GlobeImposter Ransomware was detected for the first time and reported on…
- GlowSpark ratcredential-stealer
- GlowSpark is a remote access trojan (RAT) known for its capabilities to steal credentials and provide remote access to compromised systems.
- Glupteba botnetcredential-stealercryptominer
- Glupteba is a trojan horse malware that is one of the top ten malware variants of 2021.
- Glupteba Proxy botnet
- ARM32 SOCKS proxy, written in Go, used in the Glupteba campaign.
- Glutton backdoorwebshell
- According to Xlab, Glutton is a modular PHP fileless attack framework, capable of data exfiltration and running backdoors.
- Gmera trojancredential-stealer
- Also known as Kassi, StockSteal. According to PCrisk, GMERA (also known as Kassi trojan) is malicious software that disguises itself as Stockfolio, a legitimate trading…
- GnatSpy spyware
- GnatSpy is a surveillance malware family targeting mobile devices, specifically Android.
- GoBear backdoor
- GoBear is a Go-based backdoor that abuses legitimate, stolen certificates for defense evasion purposes.
- GoBotKR botnetddos
- GoBotKR is a malware family that primarily acts as a botnet, leveraging compromised devices to perform distributed denial of service…
- GoCryptoLocker ransomware
- GoCryptoLocker is a type of ransomware that encrypts files on infected systems, demanding payment for decryption keys.
- GoGoogle ransomware
- Also known as BossiTossi. GoGoogle, also known as BossiTossi, is a ransomware strain.
- GoGra backdoor
- Also known as Onedrivetools. According to Symantec, a previously unseen backdoor that was deployed against a media organization in South Asia in November, 2023.
- GoHack ransomware
- GoHack is a ransomware known for encrypting victim files and demanding ransom payments.
- GoMet ratbackdoor
- GoMet is a remote access Trojan (RAT) known for its ability to backdoor systems, allowing attackers to execute commands remotely.
- GoRansom POC ransomware
- GoRansom POC is a proof-of-concept ransomware, demonstrating the feasibility of creating ransomware using the Go programming language.
- GoRed trojanspyware
- GoRed is a stealthy espionage-oriented malware, primarily targeting governmental and financial entities in the US and Russia.
- GoTitan botnetddos
- GoTitan is a DDoS bot under development, which support ten different methods of launching distributed denial-of-service (DDoS) attacks…
- GoToHTTP rat
- According to ESET Research, GoToHTTP is a benign tool that allows establishing a remote connection that can be accessed from a browser.
- GoatRAT rat
- GoatRAT is a remote access trojan used primarily for espionage purposes.
- GobRAT rat
- GobRAT is a remote access trojan that has been identified targeting entities primarily in Japan.
- God Crypt Joke Ransomware ransomware
- Also known as Godsomware v1.0, Ransomware God Crypt. MalwareHunterTeam found a new ransomware called God Crypt that does not appear to decrypt and appears to be a joke ransomware.
- GodFather trojancredential-stealer
- GodFather is an Android banking malware that uses virtualization to mimic legitimate applications and abuses accessibility services and…
- GodRAT rat
- GodRAT shares a common origin with AwesomePuppet RAT, alongside Gh0st RAT code similarities.
- Godlike12 rat
- Also known as GOSLU. Godlike12, also known as GOSLU, is a remote access tool (RAT) primarily used in cyber espionage campaigns targeting government and…
- Godlua backdoorcryptominer
- Godlua is a Linux-based backdoor malware written in Golang.
- Godra ransomware
- Godra is a ransomware family that encrypts user data and demands payment for decryption.
- Godzilla Loader loader
- Godzilla Loader is a malware family primarily used to facilitate the distribution of additional malicious payloads, often targeting…
- Godzilla Webshell webshell
- Godzilla Webshell is a malicious shell script used to maintain access to compromised web servers.
- Gofing virus
- Also known as Velocity Polymorphic Compression Malware. A file infector written in Go, discovered by Karsten Hahn in February 2022.
- Goggles
- Goggles is a malware entity with currently limited descriptive information available.
- GolangGhost (OS X) backdoor
- GolangGhost is a malware observed targeting OS X systems, utilizing the Go programming language for development.
- GolangGhost (Windows) rat
- Also known as BitStep RAT, WeaselStore. GolanGhost is a RAT written in Go. It uses C2 to receive commands and exfiltrate data such as browser information targeting especially…
- Gold Dragon spyware
- Gold Dragon is a Korean-language, data gathering implant that was first observed in the wild in South Korea in July 2017.
- GoldDigger credential-stealer
- GoldDigger is a type of credential-stealing malware primarily targeting the financial services industry.
- GoldDragon backdoor
- Also known as Lovexxx. GoldDragon was a second-stage backdoor which established a permanent presence on the victim’s system once the first-stage, file-less…
- GoldFinder spyware
- GoldFinder is a custom HTTP tracer tool written in Go that logs the route a packet takes between a compromised network and a C2 server.
- GoldMax backdoor
- Also known as SUNSHUTTLE. GoldMax is a second-stage C2 backdoor written in Go with Windows and Linux variants that are nearly identical in functionality.
- Golden Axe ransomware
- Golden Axe is a ransomware family known for targeting critical industries such as financial services, healthcare, and manufacturing.
- Golden Cup spyware
- Golden Cup is Android spyware that has been used to target World Cup fans.
- GoldenEagle spyware
- GoldenEagle is a piece of Android malware that has been used in targeting of Uyghurs, Muslims, Tibetans, individuals in Turkey, and…
- GoldenEye ransomware
- Also known as Petya/Mischa. GoldenEye, also known as Petya/Mischa, is a ransomware variant that encrypts the Master Boot Record (MBR) to lock users out of their…
- GoldenEye Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- GoldenHelper backdoor
- GoldenHelper is a backdoor malware associated with the Chinese tax software called Golden Tax Invoicing.
- GoldenRAT rat
- GoldenRAT is a remote access Trojan (RAT) primarily targeting government and telecommunications sectors in Latin America.
- GoldenSpy backdoor
- GoldenSpy is a backdoor malware which has been packaged with legitimate tax preparation software.
- GolfSpy spyware
- GolfSpy is Android spyware deployed by the group Bouncing Golf.
- Golroted rat
- Golroted is a remote access trojan that has been utilized in cyber-espionage campaigns.
- Gomasom ransomware
- Gomasom is a type of ransomware that encrypts files on the victim's computer and demands a ransom for the decryption key.
- Gomir backdoor
- Gomir is a Linux backdoor variant of the Go-based malware GoBear, uniquely assoicated with Kimsuky operations.
- Gomme ransomware
- Gomme is a type of ransomware designed to encrypt files and demand a ransom for their decryption.
- Gomorrah stealer credential-stealerloader
- Gomorrah is a stealer with no or little obfuscation that appeared around March 2020.
- GonnaCry Ransmware ransomware
- GonnaCry Ransomware is a malicious software that encrypts the victim's files and demands a ransom payment for decryption.
- GooPic Drooper dropper
- GooPic Drooper is a lightweight malware primarily used as a dropper for other malicious payloads.
- Goodor backdoorrat
- Also known as Fuerboos. Goodor, also known as Fuerboos, is a remote access Trojan that has been used in cyber espionage campaigns targeting the government and…
- Goofed HT ransomware
- Goofed HT is a ransomware strain that encrypts files on victim systems and demands a ransom for decryption.
- GoogleDrive RAT rat
- GoogleDrive RAT is a remote access trojan that exploits cloud storage services to exfiltrate data.
- Gooligan trojancredential-stealer
- Also known as Ghost Push. Gooligan is a malware family that runs privilege escalation exploits on Android devices and then uses its escalated privileges to steal…
- Goopic ransomware
- Goopic is a ransomware that encrypts files on the victim's machine and demands a ransom payment for decryption.
- Goopy backdoortrojan
- Goopy is a Windows backdoor and Trojan used by APT32 and shares several similarities to another backdoor used by the group (Denis).
- GooseEgg
- GooseEgg is a newly identified malware with limited information available.
- GootKit trojanloadercredential-stealer
- Also known as Waldek, Xswkit, talalpek. Gootkit is a banking trojan consisting of an x86 loader and a payload embedding nodejs as well as a set of js scripts.
- Gootloader loader
- Also known as SLOWPOUR. Gootloader is a Javascript-based infection framework that has been used since at least 2020 as a delivery method for the Gootkit banking…
- Gophe trojan
- Gophe is a Trojan primarily used for information stealing from infected systems.
- Gopher ransomware
- Gopher is an OSX ransomware that serves as a proof of concept.
- GopherRAT rat
- GopherRAT is a remote access trojan known for its use in cyber espionage activities targeting organizations primarily in India and Pakistan.
- Gopuram backdoor
- Gopuram is a sophisticated backdoor malware primarily targeting financial institutions in South Asia.
- Gorgon ransomware
- Gorgon ransomware is a malicious software used by the Gorgon Group, a threat actor known for its cybercrime activities.
- Gorilla botnetddos
- Gorilla is a botnet malware, which is a variant of the Mirai botnet family.
- Gosar rat
- According to Elastic, this is a rewrite of Quasar RAT in Go.
- Gotcha ransomware
- Gotcha is a ransomware strain known for encrypting files on infected systems and demanding a ransom for their release.
- GottaCry ransomware
- GottaCry is a type of ransomware that encrypts files on affected systems and demands a ransom payment for the decryption key.
- GovRAT rat
- GovRAT is a Remote Access Trojan primarily used for cyber-espionage, targeting governmental organizations and financial institutions…
- Gozi credential-stealertrojanspyware
- Also known as CRM, Gozi CRM, Papras. 2000 Ursnif aka Snifula 2006 Gozi v1.0, Gozi CRM, CRM, Papras 2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) -> 2010 Gozi Prinimalka ->…
- GrabBot botnetcredential-stealer
- GrabBot is a type of malware known for creating botnets to facilitate credential theft from its victims.
- Graftor trojanspyware
- Also known as MewsSpy. Graftor, also known as MewsSpy, is a sophisticated trojan spyware family designed to exfiltrate sensitive data from targeted organizations.
- Grager backdoor
- Grager is a backdoor deployed against three organizations in Taiwan, Hong Kong, and Vietnam in April 2024.
- GrandSteal credential-stealerkeylogger
- GrandSteal is a credential-stealing malware family primarily targeting login credentials from various applications and web services.
- Grandoreiro trojan
- Grandoreiro is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model.
- GraphDrop downloaderloaderrat
- Also known as GraphicalProton, SPICYBEAT. PANW Unit 42 describes this malware as capable of up and downloading files as well as loading additional shellcode payloads into selected…
- GraphSteel backdoor
- This malware was seen during the cyberattacks on Ukrainian state organizations.
- GraphicBooting trojanrootkit
- GraphicBooting is a sophisticated Trojan with rootkit capabilities primarily targeting government and defense sectors in the US and China.
- GraphicalNeutrino loader
- Also known as SNOWYAMBER. This loader abuses the benign service Notion for data exchange.
- Graphican backdoor
- According to Symantec, Graphican is an evolution of the known APT15 backdoor Ketrican, which itself was based on a previous malware -…
- Graphiron downloaderspyware
- Downloader / information stealer used by UAC-0056, observed since at least October 2022.
- Graphite downloaderloader
- Trellix describes Graphite as a malware using the Microsoft Graph API and OneDrive for C&C.
- Graphon backdoor
- Graphon is a sophisticated backdoor used to gain unauthorized access to targeted systems.
- Gratem rat
- Gratem is a remote access trojan (RAT) primarily used for gathering sensitive information from targeted systems.
- Gravity RAT (Android) rat
- Gravity RAT is an Android-based remote access trojan that has been used primarily for espionage purposes.
- Gravity RAT (Windows) rat
- Gravity RAT is a remote access tool designed to infiltrate Windows systems, primarily targeting government, education, and technology…
- GravityRAT rat
- GravityRAT is a remote access tool (RAT) and has been in ongoing development since 2016.
- Greame backdoorspyware
- Greame is a sophisticated piece of malware that primarily functions as a backdoor and spyware, targeting financial and government sectors…
- GreedyAntd backdoorrat
- GreedyAntd is a remote access tool used in cyber espionage campaigns.
- Greek Hackers RAT rat
- Greek Hackers RAT is a remote access trojan primarily associated with cyber espionage activities targeting local government and technology…
- Green Lambert backdoor
- Green Lambert is a modular backdoor that security researchers assess has been used by an advanced threat group referred to as Longhorn and…
- GreenBlood
- GreenBlood is a malware entity with insufficient detailed publicly available information to conclusively determine its specific targeting…
- GreenDispenser trojan
- GreenDispenser is a type of ATM malware that allows attackers to dispense cash from ATMs on demand.
- GreenShaitan rat
- Also known as eoehttp. GreenShaitan is a remote access trojan (RAT) known for its cyber-espionage activities, targeting mainly government and public sector…
- GreetingGhoul rattrojan
- GreetingGhoul is a sophisticated remote access trojan (RAT) used primarily for cyber espionage activities.
- Gremit Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.