Malware Families page 22 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Gremlin credential-stealerspywarekeylogger
This information-stealing malware exfiltrates data from its victims and uploads this information to its web server for publication.
Grenam virus
Also known as Renamer, gnamer. A malware that modifies every JPG file found on a computer by adding a string in its bottom corner spelling out 'I am Sorry'.
GreyEnergy backdoor
GreyEnergy is a backdoor written in C and compiled in Visual Studio.
Greystars ransomware
Greystars is a ransomware family known for targeting multiple industries to encrypt victims' files and demand payment.
Grief ransomware
Grief is a ransomware strain that utilizes CAPTCHA pages to impede automated analysis and indexing.
GriftHorse trojan
GriftHorse is a mobile trojan that conducts subscription fraud by tricking users into subscribing to premium services, leading to…
GrimAgent backdoor
GrimAgent is a backdoor that has been used before the deployment of Ryuk ransomware since at least 2020; it is likely used by FIN6 and…
GrimPlant backdoor
This malware was seen during the cyberattacks on Ukrainian state organizations.
Grinju Downloader downloader
Grinju Downloader is a malware primarily designed to stealthily download and execute additional malicious payloads on infected systems.
GrodexCrypt ransomware
GrodexCrypt is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption.
Groove ransomware
Groove was a short-lived ransomware group and cybercrime gang that emerged in August 2021 and became notable for its aggressive…
GroundPeony spywarebackdoor
GroundPeony is a malware family primarily used for cyber espionage.
Growtopia credential-stealerscreen-capturespyware
According to PCrisk, Growtopia (also known as CyberStealer) is an information stealer written in the C# programming language.
GrujaRSorium ransomware
GrujaRSorium is a ransomware strain designed to encrypt files on the victim's machine and demand a ransom for decryption.
Gruxer ransomware
Gruxer is a type of ransomware, which encrypts victims' files and demands a ransom for the decryption key.
GuLoader downloaderloader
GuLoader is a file downloader that has been used since at least December 2019 to distribute a variety of remote administration tool (RAT)…
Guard trojan
According to Kaspersky Labs, Guard is a malware developed by threat actor WildPressure.
Guerrilla backdoorspyware
Guerrilla is a family of malware known for its backdoor capabilities and use in cyber espionage campaigns.
GuiInject credential-stealertrojan
GuiInject is a malware family known for its capability to steal user credentials by leveraging injection techniques.
GusCrypter ransomware
GusCrypter is a ransomware known for encrypting files and demanding ransom payments from victims.
Guster Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Gustuff trojancredential-stealer
Gustuff is mobile malware designed to steal users' banking and virtual currency credentials.
Gwisin (ELF) ransomware
Gwisin is a Linux-based ransomware variant that has predominantly targeted organizations in South Korea, especially within the energy and…
Gwisin (Windows) ransomware
Gwisin is a ransomware that primarily targets sectors within South Korea's critical infrastructure, particularly energy and…
GwisinLocker ransomware
GwisinLocker is a ransomware that targets specific industries such as energy and utilities, manufacturing, and healthcare.
H-w0rm wormrat
H-w0rm is an old remote access trojan and worm known for spreading via web vulnerabilities and email.
H1N1 loadercredential-stealer
H1N1 is a malware variant that has been distributed via a campaign using VBA macros to infect victims.
H1N1 Loader loader
H1N1 Loader is a malware family primarily used to distribute other malicious payloads.
H34rtBl33d ransomware
H34rtBl33d is a ransomware family that encrypts files on infected systems, demanding a ransom for decryption.
HALFBAKED backdoortrojan
HALFBAKED is a malware family consisting of multiple components intended to establish persistence in victim networks.
HALFRIG loader
HALFRIG is a cyber tool used by APT29 to stage and deploy CobaltStrike.
HAMMERTOSS backdoor
Also known as HammerDuke, NetDuke. HAMMERTOSS is a backdoor that was used by APT29 in 2015.
HAPPYWORK downloader
HAPPYWORK is a downloader used by APT37 to target South Korean government and financial victims in November 2016.
HARDRAIN trojan
HARDRAIN is a Trojan malware variant reportedly used by the North Korean government.
HARDRAIN (Android) rat
HARDRAIN is an Android remote access trojan (RAT) linked to North Korean threat actors, primarily targeting government entities in the…
HARDRAIN (Windows) backdoortrojan
HARDRAIN is a Windows-based malware associated with North Korean threat actors, particularly the Lazarus Group.
HATVIBE backdoor
According to Sekoia, the aim of this backdoor is to receive VBS modules for execution from a remote C2 server.
HAWKBALL backdoor
HAWKBALL is a backdoor that was observed in targeting of the government sector in Central Asia.
HC6 ransomware
HC6 is an early version of ransomware that served as a precursor to HC7, often used to target critical infrastructure sectors in Eastern…
HC7 ransomware
A new ransomware called HC7 is infecting victims by hacking into Windows computers that are running publicly accessible Remote Desktop…
HCrypto ransomware
HCrypto is a ransomware that encrypts files on the infected system and demands a ransom payment for decryption.
HDDCryptor ransomware
Also known as Mamba, DiskCryptor. Ransomware Uses https://diskcryptor.net for full disk encryption
HDLocker ransomware
HDLocker is a type of ransomware that encrypts files on infected systems, demanding a ransom payment for the decryption key.
HDMR ransomware
Also known as GO-SPORT. HDMR is a ransomware which encrypts user files and adds a .DMR64 extension.
HDRoot rootkit
HDRoot is a sophisticated rootkit known for its persistence mechanisms, often used by advanced threat actors.
HDoor backdoor
Also known as Custom HDoor. HDoor is malware that has been customized and used by the Naikon group.
HELLOKITTY ransomware
Also known as FiveHands. HELLOKITTY is a ransomware written in C++ that shares similar code structure and functionality with DEATHRANSOM and FIVEHANDS.
HELP@AUSI ransomware
ransomware
HIDEDRV rootkit
HIDEDRV is a rootkit used by APT28. It has been deployed along with Downdelph to execute and hide that malware.
HIGHNOON backdoorloaderrootkit
According to FireEye, HIGHNOON is a backdoor that may consist of multiple components.
HIGHNOON.BIN rat
HIGHNOON.BIN is a remote access trojan used mainly for cyber-espionage.
HIGHNOTE trojanrat
Also known as ChyNode. HIGHNOTE, also known as ChyNode, is a sophisticated Remote Access Trojan (RAT) used in cyber-espionage campaigns.
HIUPAN worm
HIUPAN (aka U2DiskWatch) is a is a worm that propagates through removable drives known to be leveraged by Mustang Panda and was first…
HLOADER loader
HLOADER is a malware loader used to deliver various malicious payloads onto infected systems.
HLUX botnet
HLUX, also known as Kelihos, is a botnet malware known for its peer-to-peer architecture which is used for activities such as spamming…
HOLERUN trojanloader
Also known as LAGTOY. HOLERUN, also known as LAGTOY, is a trojan malware that functions as a loader for other malware components.
HOMEFRY credential-stealer
HOMEFRY is a 64-bit Windows password dumper/cracker that has previously been used in conjunction with other Leviathan backdoors.
HOMESTEEL credential-stealer
HOMESTEEL is a credential-stealing malware primarily targeting financial institutions and government organizations in North America.
HOPLIGHT trojanbackdoor
Also known as HANGMAN. HOPLIGHT is a backdoor Trojan that has reportedly been used by the North Korean government.
HOTWAX trojanloader
HOTWAX is a module that upon starting imports all necessary system API functions, and searches for a .CHM file.
HPE iLO 4 Ransomware ransomwarewiper
Attackers are targeting Internet accessible HPE iLO 4 remote management interfaces, supposedly encrypting the hard drives, and then…
HSHARADA ransomware
The ransomware was identified in early April 2023 and is said to target English-speaking users and potentially other languages.
HTCryptor ransomware
Ransomware Includes a feature to disable the victim's windows firewall Modified in-dev HiddenTear
HTML5 Encoding exploit-kit
HTML5 Encoding is a malware that leverages HTML5 features to obfuscate malicious code.
HTRAN
Also known as HUC Packet Transmit Tool, lcx. HTRAN is a tool that proxies connections through intermediate hops and aids users in disguising their true geographical location.
HTTP WEB BACKDOOR backdoorwebshell
HTTP WEB BACKDOOR is a type of malware that allows unauthorized remote access over HTTP protocols.
HTTP(S) uploader spyware
The HTTP(S) uploader is a Lazarus tool responsible for data exfiltration, by using the HTTP or HTTPS protocols.
HTTP-Shell webshell
The author describes this open source shell as follows.
HTTPBrowser rat
Also known as Token Control, HttpDump. HTTPBrowser is malware that has been used by several threat groups.
HTTPSnoop backdoor
Also known as TOFULOAD. Cisco Talos states that HTTPSnoop is a simple, yet effective, backdoor that consists of novel techniques to interface with Windows HTTP…
HTTPTroy backdoorloader
HTTPTroy is a highly obfuscated backdoor that facilitates collection, command and control, defense evasion and exfiltration.
HUI Loader loader
Also known as SIDESTEP. HUI Loader is a custom DLL loader that has been used since at least 2015 by China-based threat groups including Cinnamon Tempest and…
HYPERSCRAPE credential-stealer
HYPERSCRAPE is a credential-stealer malware used for targeted phishing campaigns.
HZ RAT (OS X) rat
HZ RAT is a remote access trojan primarily targeting macOS systems.
HZ RAT (Windows) rat
HZ RAT is a Remote Access Trojan (RAT) used primarily for cyber espionage activities.
HabitsRAT (ELF) rat
HabitsRAT (ELF) is a remote access trojan targeting Linux systems, typically used for unauthorized access and control over victim machines.
HabitsRAT (Windows) rat
HabitsRAT is a remote access trojan primarily targeting Windows systems.
HackBoss trojancredential-stealer
A cryptocurrency-stealing malware distributed through Telegram
HackBrowserData credential-stealerspyware
HackBrowserData is a browser information stealer written in Go.
HackSpy spywaretrojan
HackSpy is a Py2Exe based tool, often distributed via GitHub, that serves as a spyware and trojan.
HackdoorCrypt3r ransomware
HackdoorCrypt3r is a ransomware variant known for encrypting files on infected systems and demanding a ransom for decryption.
Hacked ransomware
Hacked is a variant of the Jigsaw ransomware known for encrypting user files and demanding ransom.
HackedLocker Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Hacking Team UEFI Rootkit rootkit
Hacking Team UEFI Rootkit is a rootkit developed by the company Hacking Team as a method of persistence for remote access software.
Hacksfase ransomware
Hacksfase is a type of ransomware known for encrypting files and demanding a ransom for their release.
Hades ransomware
Hades is a ransomware strain known for targeting various industries with file encryption attacks.
Hadooken rat
Hadooken is a remote access trojan (RAT) used primarily for cyber espionage.
Haiduc trojanrat
Haiduc is a Remote Access Trojan (RAT) typically targeting government and technology sectors.
Hajime worm
Hajime is a peer-to-peer worm that targets IoT devices by exploiting vulnerabilities to propagate.
Hakai ddos
Hakai is a Mirai-based malware variant known primarily for conducting distributed denial-of-service (DDoS) attacks.
Hakbit ransomware
Also known as Thanos Ransomware. Hakbit, also known as Thanos Ransomware, is a ransomware family that encrypts files on affected systems, demanding a ransom for decryption.
Hakuna Matata ransomware
Hakuna Matata is a ransomware written in C#.
Hallaj PRO RAT rat
Hallaj PRO RAT is a remote access tool that enables attackers to control and monitor compromised systems remotely.
Halloware ransomware
A malware author by the name of Luc1F3R is peddling a new ransomware strain called Halloware for the lowly price of $40.
Hamweq worm
Hamweq is a malware worm known for spreading across networks by exploiting vulnerabilities or using removable media.
Hancitor downloader
Also known as Chanitor. Hancitor is a downloader that has been used by Pony and other information stealing malware.
Hand of Thief credential-stealertrojan
Also known as Hanthie. Hand of Thief, also known as Hanthie, is a banking trojan primarily designed to steal banking credentials.
HandyMannyPot
HandyMannyPot is a malware for which information is limited.
Hannotog backdoor
Hannotog is a type of backdoor malware uniquely assoicated with Lotus Blossom operations since at least 2022.
HappyCrypter ransomware
HappyCrypter is a ransomware variant known for encrypting files on victims' systems and demanding a ransom for decryption.