Malware Families page 22 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Gremlin credential-stealerspywarekeylogger
- This information-stealing malware exfiltrates data from its victims and uploads this information to its web server for publication.
- Grenam virus
- Also known as Renamer, gnamer. A malware that modifies every JPG file found on a computer by adding a string in its bottom corner spelling out 'I am Sorry'.
- GreyEnergy backdoor
- GreyEnergy is a backdoor written in C and compiled in Visual Studio.
- Greystars ransomware
- Greystars is a ransomware family known for targeting multiple industries to encrypt victims' files and demand payment.
- Grief ransomware
- Grief is a ransomware strain that utilizes CAPTCHA pages to impede automated analysis and indexing.
- GriftHorse trojan
- GriftHorse is a mobile trojan that conducts subscription fraud by tricking users into subscribing to premium services, leading to…
- GrimAgent backdoor
- GrimAgent is a backdoor that has been used before the deployment of Ryuk ransomware since at least 2020; it is likely used by FIN6 and…
- GrimPlant backdoor
- This malware was seen during the cyberattacks on Ukrainian state organizations.
- Grinju Downloader downloader
- Grinju Downloader is a malware primarily designed to stealthily download and execute additional malicious payloads on infected systems.
- GrodexCrypt ransomware
- GrodexCrypt is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption.
- Groove ransomware
- Groove was a short-lived ransomware group and cybercrime gang that emerged in August 2021 and became notable for its aggressive…
- GroundPeony spywarebackdoor
- GroundPeony is a malware family primarily used for cyber espionage.
- Growtopia credential-stealerscreen-capturespyware
- According to PCrisk, Growtopia (also known as CyberStealer) is an information stealer written in the C# programming language.
- GrujaRSorium ransomware
- GrujaRSorium is a ransomware strain designed to encrypt files on the victim's machine and demand a ransom for decryption.
- Gruxer ransomware
- Gruxer is a type of ransomware, which encrypts victims' files and demands a ransom for the decryption key.
- GuLoader downloaderloader
- GuLoader is a file downloader that has been used since at least December 2019 to distribute a variety of remote administration tool (RAT)…
- Guard trojan
- According to Kaspersky Labs, Guard is a malware developed by threat actor WildPressure.
- Guerrilla backdoorspyware
- Guerrilla is a family of malware known for its backdoor capabilities and use in cyber espionage campaigns.
- GuiInject credential-stealertrojan
- GuiInject is a malware family known for its capability to steal user credentials by leveraging injection techniques.
- GusCrypter ransomware
- GusCrypter is a ransomware known for encrypting files and demanding ransom payments from victims.
- Guster Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Gustuff trojancredential-stealer
- Gustuff is mobile malware designed to steal users' banking and virtual currency credentials.
- Gwisin (ELF) ransomware
- Gwisin is a Linux-based ransomware variant that has predominantly targeted organizations in South Korea, especially within the energy and…
- Gwisin (Windows) ransomware
- Gwisin is a ransomware that primarily targets sectors within South Korea's critical infrastructure, particularly energy and…
- GwisinLocker ransomware
- GwisinLocker is a ransomware that targets specific industries such as energy and utilities, manufacturing, and healthcare.
- H-w0rm wormrat
- H-w0rm is an old remote access trojan and worm known for spreading via web vulnerabilities and email.
- H1N1 loadercredential-stealer
- H1N1 is a malware variant that has been distributed via a campaign using VBA macros to infect victims.
- H1N1 Loader loader
- H1N1 Loader is a malware family primarily used to distribute other malicious payloads.
- H34rtBl33d ransomware
- H34rtBl33d is a ransomware family that encrypts files on infected systems, demanding a ransom for decryption.
- HALFBAKED backdoortrojan
- HALFBAKED is a malware family consisting of multiple components intended to establish persistence in victim networks.
- HALFRIG loader
- HALFRIG is a cyber tool used by APT29 to stage and deploy CobaltStrike.
- HAMMERTOSS backdoor
- Also known as HammerDuke, NetDuke. HAMMERTOSS is a backdoor that was used by APT29 in 2015.
- HAPPYWORK downloader
- HAPPYWORK is a downloader used by APT37 to target South Korean government and financial victims in November 2016.
- HARDRAIN trojan
- HARDRAIN is a Trojan malware variant reportedly used by the North Korean government.
- HARDRAIN (Android) rat
- HARDRAIN is an Android remote access trojan (RAT) linked to North Korean threat actors, primarily targeting government entities in the…
- HARDRAIN (Windows) backdoortrojan
- HARDRAIN is a Windows-based malware associated with North Korean threat actors, particularly the Lazarus Group.
- HATVIBE backdoor
- According to Sekoia, the aim of this backdoor is to receive VBS modules for execution from a remote C2 server.
- HAWKBALL backdoor
- HAWKBALL is a backdoor that was observed in targeting of the government sector in Central Asia.
- HC6 ransomware
- HC6 is an early version of ransomware that served as a precursor to HC7, often used to target critical infrastructure sectors in Eastern…
- HC7 ransomware
- A new ransomware called HC7 is infecting victims by hacking into Windows computers that are running publicly accessible Remote Desktop…
- HCrypto ransomware
- HCrypto is a ransomware that encrypts files on the infected system and demands a ransom payment for decryption.
- HDDCryptor ransomware
- Also known as Mamba, DiskCryptor. Ransomware Uses https://diskcryptor.net for full disk encryption
- HDLocker ransomware
- HDLocker is a type of ransomware that encrypts files on infected systems, demanding a ransom payment for the decryption key.
- HDMR ransomware
- Also known as GO-SPORT. HDMR is a ransomware which encrypts user files and adds a .DMR64 extension.
- HDRoot rootkit
- HDRoot is a sophisticated rootkit known for its persistence mechanisms, often used by advanced threat actors.
- HDoor backdoor
- Also known as Custom HDoor. HDoor is malware that has been customized and used by the Naikon group.
- HELLOKITTY ransomware
- Also known as FiveHands. HELLOKITTY is a ransomware written in C++ that shares similar code structure and functionality with DEATHRANSOM and FIVEHANDS.
- HELP@AUSI ransomware
- ransomware
- HIDEDRV rootkit
- HIDEDRV is a rootkit used by APT28. It has been deployed along with Downdelph to execute and hide that malware.
- HIGHNOON backdoorloaderrootkit
- According to FireEye, HIGHNOON is a backdoor that may consist of multiple components.
- HIGHNOON.BIN rat
- HIGHNOON.BIN is a remote access trojan used mainly for cyber-espionage.
- HIGHNOTE trojanrat
- Also known as ChyNode. HIGHNOTE, also known as ChyNode, is a sophisticated Remote Access Trojan (RAT) used in cyber-espionage campaigns.
- HIUPAN worm
- HIUPAN (aka U2DiskWatch) is a is a worm that propagates through removable drives known to be leveraged by Mustang Panda and was first…
- HLOADER loader
- HLOADER is a malware loader used to deliver various malicious payloads onto infected systems.
- HLUX botnet
- HLUX, also known as Kelihos, is a botnet malware known for its peer-to-peer architecture which is used for activities such as spamming…
- HOLERUN trojanloader
- Also known as LAGTOY. HOLERUN, also known as LAGTOY, is a trojan malware that functions as a loader for other malware components.
- HOMEFRY credential-stealer
- HOMEFRY is a 64-bit Windows password dumper/cracker that has previously been used in conjunction with other Leviathan backdoors.
- HOMESTEEL credential-stealer
- HOMESTEEL is a credential-stealing malware primarily targeting financial institutions and government organizations in North America.
- HOPLIGHT trojanbackdoor
- Also known as HANGMAN. HOPLIGHT is a backdoor Trojan that has reportedly been used by the North Korean government.
- HOTWAX trojanloader
- HOTWAX is a module that upon starting imports all necessary system API functions, and searches for a .CHM file.
- HPE iLO 4 Ransomware ransomwarewiper
- Attackers are targeting Internet accessible HPE iLO 4 remote management interfaces, supposedly encrypting the hard drives, and then…
- HSHARADA ransomware
- The ransomware was identified in early April 2023 and is said to target English-speaking users and potentially other languages.
- HTCryptor ransomware
- Ransomware Includes a feature to disable the victim's windows firewall Modified in-dev HiddenTear
- HTML5 Encoding exploit-kit
- HTML5 Encoding is a malware that leverages HTML5 features to obfuscate malicious code.
- HTRAN
- Also known as HUC Packet Transmit Tool, lcx. HTRAN is a tool that proxies connections through intermediate hops and aids users in disguising their true geographical location.
- HTTP WEB BACKDOOR backdoorwebshell
- HTTP WEB BACKDOOR is a type of malware that allows unauthorized remote access over HTTP protocols.
- HTTP(S) uploader spyware
- The HTTP(S) uploader is a Lazarus tool responsible for data exfiltration, by using the HTTP or HTTPS protocols.
- HTTP-Shell webshell
- The author describes this open source shell as follows.
- HTTPBrowser rat
- Also known as Token Control, HttpDump. HTTPBrowser is malware that has been used by several threat groups.
- HTTPSnoop backdoor
- Also known as TOFULOAD. Cisco Talos states that HTTPSnoop is a simple, yet effective, backdoor that consists of novel techniques to interface with Windows HTTP…
- HTTPTroy backdoorloader
- HTTPTroy is a highly obfuscated backdoor that facilitates collection, command and control, defense evasion and exfiltration.
- HUI Loader loader
- Also known as SIDESTEP. HUI Loader is a custom DLL loader that has been used since at least 2015 by China-based threat groups including Cinnamon Tempest and…
- HYPERSCRAPE credential-stealer
- HYPERSCRAPE is a credential-stealer malware used for targeted phishing campaigns.
- HZ RAT (OS X) rat
- HZ RAT is a remote access trojan primarily targeting macOS systems.
- HZ RAT (Windows) rat
- HZ RAT is a Remote Access Trojan (RAT) used primarily for cyber espionage activities.
- HabitsRAT (ELF) rat
- HabitsRAT (ELF) is a remote access trojan targeting Linux systems, typically used for unauthorized access and control over victim machines.
- HabitsRAT (Windows) rat
- HabitsRAT is a remote access trojan primarily targeting Windows systems.
- HackBoss trojancredential-stealer
- A cryptocurrency-stealing malware distributed through Telegram
- HackBrowserData credential-stealerspyware
- HackBrowserData is a browser information stealer written in Go.
- HackSpy spywaretrojan
- HackSpy is a Py2Exe based tool, often distributed via GitHub, that serves as a spyware and trojan.
- HackdoorCrypt3r ransomware
- HackdoorCrypt3r is a ransomware variant known for encrypting files on infected systems and demanding a ransom for decryption.
- Hacked ransomware
- Hacked is a variant of the Jigsaw ransomware known for encrypting user files and demanding ransom.
- HackedLocker Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Hacking Team UEFI Rootkit rootkit
- Hacking Team UEFI Rootkit is a rootkit developed by the company Hacking Team as a method of persistence for remote access software.
- Hacksfase ransomware
- Hacksfase is a type of ransomware known for encrypting files and demanding a ransom for their release.
- Hades ransomware
- Hades is a ransomware strain known for targeting various industries with file encryption attacks.
- Hadooken rat
- Hadooken is a remote access trojan (RAT) used primarily for cyber espionage.
- Haiduc trojanrat
- Haiduc is a Remote Access Trojan (RAT) typically targeting government and technology sectors.
- Hajime worm
- Hajime is a peer-to-peer worm that targets IoT devices by exploiting vulnerabilities to propagate.
- Hakai ddos
- Hakai is a Mirai-based malware variant known primarily for conducting distributed denial-of-service (DDoS) attacks.
- Hakbit ransomware
- Also known as Thanos Ransomware. Hakbit, also known as Thanos Ransomware, is a ransomware family that encrypts files on affected systems, demanding a ransom for decryption.
- Hakuna Matata ransomware
- Hakuna Matata is a ransomware written in C#.
- Hallaj PRO RAT rat
- Hallaj PRO RAT is a remote access tool that enables attackers to control and monitor compromised systems remotely.
- Halloware ransomware
- A malware author by the name of Luc1F3R is peddling a new ransomware strain called Halloware for the lowly price of $40.
- Hamweq worm
- Hamweq is a malware worm known for spreading across networks by exploiting vulnerabilities or using removable media.
- Hancitor downloader
- Also known as Chanitor. Hancitor is a downloader that has been used by Pony and other information stealing malware.
- Hand of Thief credential-stealertrojan
- Also known as Hanthie. Hand of Thief, also known as Hanthie, is a banking trojan primarily designed to steal banking credentials.
- HandyMannyPot
- HandyMannyPot is a malware for which information is limited.
- Hannotog backdoor
- Hannotog is a type of backdoor malware uniquely assoicated with Lotus Blossom operations since at least 2022.
- HappyCrypter ransomware
- HappyCrypter is a ransomware variant known for encrypting files on victims' systems and demanding a ransom for decryption.