Malware Families page 21 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Globe3 Ransomware ransomware
Also known as Purge Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
GlobeImposter ransomware
Also known as Fake Globe. During December 2017, a new variant of the GlobeImposter Ransomware was detected for the first time and reported on…
GlowSpark ratcredential-stealer
GlowSpark is a remote access trojan (RAT) known for its capabilities to steal credentials and provide remote access to compromised systems.
Glupteba botnetcredential-stealercryptominer
Glupteba is a trojan horse malware that is one of the top ten malware variants of 2021.
Glupteba Proxy botnet
ARM32 SOCKS proxy, written in Go, used in the Glupteba campaign.
Glutton backdoorwebshell
According to Xlab, Glutton is a modular PHP fileless attack framework, capable of data exfiltration and running backdoors.
Gmera trojancredential-stealer
Also known as Kassi, StockSteal. According to PCrisk, GMERA (also known as Kassi trojan) is malicious software that disguises itself as Stockfolio, a legitimate trading…
GnatSpy spyware
GnatSpy is a surveillance malware family targeting mobile devices, specifically Android.
GoBear backdoor
GoBear is a Go-based backdoor that abuses legitimate, stolen certificates for defense evasion purposes.
GoBotKR botnetddos
GoBotKR is a malware family that primarily acts as a botnet, leveraging compromised devices to perform distributed denial of service…
GoCryptoLocker ransomware
GoCryptoLocker is a type of ransomware that encrypts files on infected systems, demanding payment for decryption keys.
GoGoogle ransomware
Also known as BossiTossi. GoGoogle, also known as BossiTossi, is a ransomware strain.
GoGra backdoor
Also known as Onedrivetools. According to Symantec, a previously unseen backdoor that was deployed against a media organization in South Asia in November, 2023.
GoHack ransomware
GoHack is a ransomware known for encrypting victim files and demanding ransom payments.
GoMet ratbackdoor
GoMet is a remote access Trojan (RAT) known for its ability to backdoor systems, allowing attackers to execute commands remotely.
GoRansom POC ransomware
GoRansom POC is a proof-of-concept ransomware, demonstrating the feasibility of creating ransomware using the Go programming language.
GoRed trojanspyware
GoRed is a stealthy espionage-oriented malware, primarily targeting governmental and financial entities in the US and Russia.
GoTitan botnetddos
GoTitan is a DDoS bot under development, which support ten different methods of launching distributed denial-of-service (DDoS) attacks…
GoToHTTP rat
According to ESET Research, GoToHTTP is a benign tool that allows establishing a remote connection that can be accessed from a browser.
GoatRAT rat
GoatRAT is a remote access trojan used primarily for espionage purposes.
GobRAT rat
GobRAT is a remote access trojan that has been identified targeting entities primarily in Japan.
God Crypt Joke Ransomware ransomware
Also known as Godsomware v1.0, Ransomware God Crypt. MalwareHunterTeam found a new ransomware called God Crypt that does not appear to decrypt and appears to be a joke ransomware.
GodFather trojancredential-stealer
GodFather is an Android banking malware that uses virtualization to mimic legitimate applications and abuses accessibility services and…
GodRAT rat
GodRAT shares a common origin with AwesomePuppet RAT, alongside Gh0st RAT code similarities.
Godlike12 rat
Also known as GOSLU. Godlike12, also known as GOSLU, is a remote access tool (RAT) primarily used in cyber espionage campaigns targeting government and…
Godlua backdoorcryptominer
Godlua is a Linux-based backdoor malware written in Golang.
Godra ransomware
Godra is a ransomware family that encrypts user data and demands payment for decryption.
Godzilla Loader loader
Godzilla Loader is a malware family primarily used to facilitate the distribution of additional malicious payloads, often targeting…
Godzilla Webshell webshell
Godzilla Webshell is a malicious shell script used to maintain access to compromised web servers.
Gofing virus
Also known as Velocity Polymorphic Compression Malware. A file infector written in Go, discovered by Karsten Hahn in February 2022.
Goggles
Goggles is a malware entity with currently limited descriptive information available.
GolangGhost (OS X) backdoor
GolangGhost is a malware observed targeting OS X systems, utilizing the Go programming language for development.
GolangGhost (Windows) rat
Also known as BitStep RAT, WeaselStore. GolanGhost is a RAT written in Go. It uses C2 to receive commands and exfiltrate data such as browser information targeting especially…
Gold Dragon spyware
Gold Dragon is a Korean-language, data gathering implant that was first observed in the wild in South Korea in July 2017.
GoldDigger credential-stealer
GoldDigger is a type of credential-stealing malware primarily targeting the financial services industry.
GoldDragon backdoor
Also known as Lovexxx. GoldDragon was a second-stage backdoor which established a permanent presence on the victim’s system once the first-stage, file-less…
GoldFinder spyware
GoldFinder is a custom HTTP tracer tool written in Go that logs the route a packet takes between a compromised network and a C2 server.
GoldMax backdoor
Also known as SUNSHUTTLE. GoldMax is a second-stage C2 backdoor written in Go with Windows and Linux variants that are nearly identical in functionality.
Golden Axe ransomware
Golden Axe is a ransomware family known for targeting critical industries such as financial services, healthcare, and manufacturing.
Golden Cup spyware
Golden Cup is Android spyware that has been used to target World Cup fans.
GoldenEagle spyware
GoldenEagle is a piece of Android malware that has been used in targeting of Uyghurs, Muslims, Tibetans, individuals in Turkey, and…
GoldenEye ransomware
Also known as Petya/Mischa. GoldenEye, also known as Petya/Mischa, is a ransomware variant that encrypts the Master Boot Record (MBR) to lock users out of their…
GoldenEye Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
GoldenHelper backdoor
GoldenHelper is a backdoor malware associated with the Chinese tax software called Golden Tax Invoicing.
GoldenRAT rat
GoldenRAT is a remote access Trojan (RAT) primarily targeting government and telecommunications sectors in Latin America.
GoldenSpy backdoor
GoldenSpy is a backdoor malware which has been packaged with legitimate tax preparation software.
GolfSpy spyware
GolfSpy is Android spyware deployed by the group Bouncing Golf.
Golroted rat
Golroted is a remote access trojan that has been utilized in cyber-espionage campaigns.
Gomasom ransomware
Gomasom is a type of ransomware that encrypts files on the victim's computer and demands a ransom for the decryption key.
Gomir backdoor
Gomir is a Linux backdoor variant of the Go-based malware GoBear, uniquely assoicated with Kimsuky operations.
Gomme ransomware
Gomme is a type of ransomware designed to encrypt files and demand a ransom for their decryption.
Gomorrah stealer credential-stealerloader
Gomorrah is a stealer with no or little obfuscation that appeared around March 2020.
GonnaCry Ransmware ransomware
GonnaCry Ransomware is a malicious software that encrypts the victim's files and demands a ransom payment for decryption.
GooPic Drooper dropper
GooPic Drooper is a lightweight malware primarily used as a dropper for other malicious payloads.
Goodor backdoorrat
Also known as Fuerboos. Goodor, also known as Fuerboos, is a remote access Trojan that has been used in cyber espionage campaigns targeting the government and…
Goofed HT ransomware
Goofed HT is a ransomware strain that encrypts files on victim systems and demands a ransom for decryption.
GoogleDrive RAT rat
GoogleDrive RAT is a remote access trojan that exploits cloud storage services to exfiltrate data.
Gooligan trojancredential-stealer
Also known as Ghost Push. Gooligan is a malware family that runs privilege escalation exploits on Android devices and then uses its escalated privileges to steal…
Goopic ransomware
Goopic is a ransomware that encrypts files on the victim's machine and demands a ransom payment for decryption.
Goopy backdoortrojan
Goopy is a Windows backdoor and Trojan used by APT32 and shares several similarities to another backdoor used by the group (Denis).
GooseEgg
GooseEgg is a newly identified malware with limited information available.
GootKit trojanloadercredential-stealer
Also known as Waldek, Xswkit, talalpek. Gootkit is a banking trojan consisting of an x86 loader and a payload embedding nodejs as well as a set of js scripts.
Gootloader loader
Also known as SLOWPOUR. Gootloader is a Javascript-based infection framework that has been used since at least 2020 as a delivery method for the Gootkit banking…
Gophe trojan
Gophe is a Trojan primarily used for information stealing from infected systems.
Gopher ransomware
Gopher is an OSX ransomware that serves as a proof of concept.
GopherRAT rat
GopherRAT is a remote access trojan known for its use in cyber espionage activities targeting organizations primarily in India and Pakistan.
Gopuram backdoor
Gopuram is a sophisticated backdoor malware primarily targeting financial institutions in South Asia.
Gorgon ransomware
Gorgon ransomware is a malicious software used by the Gorgon Group, a threat actor known for its cybercrime activities.
Gorilla botnetddos
Gorilla is a botnet malware, which is a variant of the Mirai botnet family.
Gosar rat
According to Elastic, this is a rewrite of Quasar RAT in Go.
Gotcha ransomware
Gotcha is a ransomware strain known for encrypting files on infected systems and demanding a ransom for their release.
GottaCry ransomware
GottaCry is a type of ransomware that encrypts files on affected systems and demands a ransom payment for the decryption key.
GovRAT rat
GovRAT is a Remote Access Trojan primarily used for cyber-espionage, targeting governmental organizations and financial institutions…
Gozi credential-stealertrojanspyware
Also known as CRM, Gozi CRM, Papras. 2000 Ursnif aka Snifula 2006 Gozi v1.0, Gozi CRM, CRM, Papras 2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) -> 2010 Gozi Prinimalka ->…
GrabBot botnetcredential-stealer
GrabBot is a type of malware known for creating botnets to facilitate credential theft from its victims.
Graftor trojanspyware
Also known as MewsSpy. Graftor, also known as MewsSpy, is a sophisticated trojan spyware family designed to exfiltrate sensitive data from targeted organizations.
Grager backdoor
Grager is a backdoor deployed against three organizations in Taiwan, Hong Kong, and Vietnam in April 2024.
GrandSteal credential-stealerkeylogger
GrandSteal is a credential-stealing malware family primarily targeting login credentials from various applications and web services.
Grandoreiro trojan
Grandoreiro is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model.
GraphDrop downloaderloaderrat
Also known as GraphicalProton, SPICYBEAT. PANW Unit 42 describes this malware as capable of up and downloading files as well as loading additional shellcode payloads into selected…
GraphSteel backdoor
This malware was seen during the cyberattacks on Ukrainian state organizations.
GraphicBooting trojanrootkit
GraphicBooting is a sophisticated Trojan with rootkit capabilities primarily targeting government and defense sectors in the US and China.
GraphicalNeutrino loader
Also known as SNOWYAMBER. This loader abuses the benign service Notion for data exchange.
Graphican backdoor
According to Symantec, Graphican is an evolution of the known APT15 backdoor Ketrican, which itself was based on a previous malware -…
Graphiron downloaderspyware
Downloader / information stealer used by UAC-0056, observed since at least October 2022.
Graphite downloaderloader
Trellix describes Graphite as a malware using the Microsoft Graph API and OneDrive for C&C.
Graphon backdoor
Graphon is a sophisticated backdoor used to gain unauthorized access to targeted systems.
Gratem rat
Gratem is a remote access trojan (RAT) primarily used for gathering sensitive information from targeted systems.
Gravity RAT (Android) rat
Gravity RAT is an Android-based remote access trojan that has been used primarily for espionage purposes.
Gravity RAT (Windows) rat
Gravity RAT is a remote access tool designed to infiltrate Windows systems, primarily targeting government, education, and technology…
GravityRAT rat
GravityRAT is a remote access tool (RAT) and has been in ongoing development since 2016.
Greame backdoorspyware
Greame is a sophisticated piece of malware that primarily functions as a backdoor and spyware, targeting financial and government sectors…
GreedyAntd backdoorrat
GreedyAntd is a remote access tool used in cyber espionage campaigns.
Greek Hackers RAT rat
Greek Hackers RAT is a remote access trojan primarily associated with cyber espionage activities targeting local government and technology…
Green Lambert backdoor
Green Lambert is a modular backdoor that security researchers assess has been used by an advanced threat group referred to as Longhorn and…
GreenBlood
GreenBlood is a malware entity with insufficient detailed publicly available information to conclusively determine its specific targeting…
GreenDispenser trojan
GreenDispenser is a type of ATM malware that allows attackers to dispense cash from ATMs on demand.
GreenShaitan rat
Also known as eoehttp. GreenShaitan is a remote access trojan (RAT) known for its cyber-espionage activities, targeting mainly government and public sector…
GreetingGhoul rattrojan
GreetingGhoul is a sophisticated remote access trojan (RAT) used primarily for cyber espionage activities.
Gremit Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.