Malware Families page 23 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- HappyDayzz ransomware
- HappyDayzz is a ransomware that encrypts files on infected systems and demands a ransom for decryption.
- HappyLocker (HiddenTear?) ransomware
- HappyLocker is a ransomware variant related to the HiddenTear project, known for encrypting victims' files and demanding a ransom for…
- Harasom ransomware
- Harasom is a type of ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
- Harnig downloader
- Also known as Piptea. Harnig, also known as Piptea, is a malware downloader used to install additional malicious software onto infected systems.
- Haron ransomware
- Haron is a ransomware strain known for targeting multiple industries with double-extortion tactics.
- Haron Ransomware ransomware
- Haron Ransomware is a file-encrypting malware that targets various industries with the intent of extortion.
- Hatef wiper
- Hatef is a wiper malware identified by Intezer.
- Hav-RAT rat
- Hav-RAT is a remote access tool written in Delphi, known for targeting government and financial sectors.
- HavanaCrypt ransomware
- HavanaCrypt is a ransomware variant that emerged in mid-2022, characterized by its capability to encrypt files on an infected machine…
- Havex RAT rat
- Havex is a remote access trojan (RAT) that was discovered in 2013 as part of a widespread espionage campaign targeting industrial control…
- Havij exploit-kit
- Havij is an automatic SQL Injection tool distributed by the Iranian ITSecTeam security company.
- Havoc ratbackdoorransomware
- Also known as HavocCrypt Ransomware, Havokiz. Havoc is an open-source post-exploitation command and control (C2) framework first released on GitHub in October 2022 by C5pider (Paul…
- HawkEye ratkeyloggercredential-stealer
- HawkEye is a popular RAT that can be used as a keylogger, it is also able to identify login events and record the destination, username…
- HawkEye Keylogger keyloggercredential-stealerloader
- Also known as HawkEye, HawkEye Reborn, Predator Pain. HawKeye is a keylogger that is distributed since 2013.
- HawkShaw rat
- HawkShaw is a sophisticated remote access tool used primarily for cyber espionage.
- Hawking
- Hawking is a relatively unknown malware with limited public information available.
- Haxerboi Ransomware ransomware
- Haxerboi Ransomware is a type of malicious software designed to extort money from victims by encrypting their files and demanding a ransom…
- Haze ransomware
- Haze is a ransomware variant that encrypts files on infected systems, demanding a ransom for decryption keys.
- HazyLoad loader
- HazyLoad is a malware loader designed to deploy additional malicious payloads on compromised systems.
- HeadCrab cryptominer
- HeadCrab is a sophisticated malware primarily used to mine cryptocurrency.
- HeaderTip backdoor
- The Chinese threat actor "Scarab" is using a custom backdoor dubbed "HeaderTip" according to SentinelLABS.
- Headlace
- Headlace is a malware entity with limited available public information.
- HeartCrypt
- HeartCrypt is a packer-as-a-service (PaaS) used to protect malware that has been available since at least 2024.
- Heimdall ransomware
- Heimdall is a ransomware that encrypts files and appends a specific marker 'Heimdall---'.
- Helauto ratloader
- Helauto is a remote access trojan known for its ability to provide unauthorized access and control over targeted systems.
- HelloBot (ELF) botnetddos
- HelloBot (ELF) is a Linux-based botnet malware typically used for Distributed Denial-of-Service (DDoS) attacks.
- HelloBot (Windows) botnettrojan
- HelloBot is a malware family primarily targeting financial services and technology companies.
- HelloKitty (ELF) ransomware
- HelloKitty (ELF) is a Linux variant of the HelloKitty ransomware, known for targeting Linux systems, particularly in sectors like…
- HelloKitty (Windows) ransomware
- Also known as KittyCrypt. Unit42 states that HelloKitty is a ransomware family that first surfaced at the end of 2020, primarily targeting Windows systems.
- HelloXD ransomware
- HelloXD is a ransomware family performing double extortion attacks that surfaced in November 2021.
- Helminth backdoor
- Helminth is a backdoor that has at least two variants - one written in VBScript and PowerShell that is delivered via a macros in Excel…
- Heloag downloaderrat
- Heloag is a sophisticated malware commonly associated with APT37 and the Lazarus Group, known for targeting the government sector.
- HelpDCFile ransomware
- HelpDCFile is a ransomware strain that encrypts the victim's files and demands a ransom for decryption.
- HelpMe ransomware
- HelpMe is a ransomware strain known for encrypting victim files and demanding a ransom for decryption.
- Help_dcfile ransomware
- Help_dcfile is a ransomware variant that encrypts files on infected systems and demands a ransom payment for decryption.
- HemiGate backdoorrat
- HemiGate is a sophisticated backdoor and remote access tool (RAT) utilized primarily in cyber-espionage campaigns targeting government and…
- HenBox spywaretrojan
- HenBox is Android malware that attempts to only execute on Xiaomi devices running the MIUI operating system.
- Herbst ransomware
- Herbst is a ransomware strain known for encrypting files on infected systems and demanding ransom payments in exchange for decryption keys.
- Heriplor rat
- Heriplor is a remote access trojan (RAT) used primarily for cyber-espionage activities.
- Hermes Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Hermes837 ransomware
- Hermes837 is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
- HermesVirus HT ransomware
- HermesVirus HT is a ransomware family that encrypts victims' files and demands payment for decryption.
- HermeticWiper wiper
- Also known as Trojan.Killdisk, DriveSlayer, FoxBlade. HermeticWiper is a data wiper that has been used since at least early 2022, primarily against Ukraine with additional activity observed in…
- HermeticWizard wormwiper
- HermeticWizard is a worm that has been used to spread HermeticWiper in attacks against organizations in Ukraine since at least 2022.
- Hermit spyware
- Lookout states that Hermit is an advanced spyware designed to target iOS and Android mobile devices.
- HeroRAT rat
- HeroRAT is a remote access trojan targeting Android devices, capable of controlling infected devices and stealing sensitive information.
- Heropoint ransomware
- Heropoint is ransomware known for encrypting files on victim systems and demanding a ransom payment for decryption.
- HerpesBot botnet
- HerpesBot is a botnet family with the capability to control infected devices.
- Heseber trojanloader
- Heseber is a sophisticated malware family primarily used in cyber espionage campaigns.
- HesperBot trojancredential-stealerkeylogger
- HesperBot is a sophisticated banking Trojan known for targeting financial institutions primarily in Turkey, the Czech Republic, and the UK.
- HexEval Loader loaderdownloader
- HexEval Loader is a hex-encoded loader that collects host data, decodes follow-on scripts and acts as a downloader for the BeaverTail…
- HexaLocker ransomware
- On August 9th, 2024, the HexaLocker team advertised a new Windows ransomware on its Telegram channel.
- Heyoka Backdoor backdoor
- Heyoka Backdoor is a custom backdoor--based on the Heyoka open source exfiltration tool--that has been used by Aoqin Dragon since at least…
- Hi Buddy! ransomware
- Hi Buddy! is a ransomware variant based on the HiddenTear source code.
- Hi-Zor rat
- Hi-Zor is a remote access tool (RAT) that has characteristics similar to Sakula.
- Hi-Zor RAT rat
- Hi-Zor RAT is a remote access trojan that has been identified in espionage campaigns primarily targeting government and infrastructure…
- HiAsm backdoorrat
- HiAsm is a remote access trojan (RAT) that typically gains unauthorized access to victim machines, allowing attackers to execute remote…
- HiatusRAT rat
- Lumen discovered this malware used in campaign targeting business-grade routers using a RAT they call HiatusRAT and a variant of tcpdump…
- Hidden Bee botnetcryptominer
- Hidden Bee is a malware family known for its complex infection chains.
- HiddenAd
- HiddenAd is a malware that shows ads as overlays on the phone.
- HiddenBeer ransomware
- HiddenBeer is a ransomware family known for encrypting data and demanding a ransom for the decryption key.
- HiddenFace backdoor
- Also known as NOOPDOOR. HiddenFace is a modular backdoor developed and used exclusively by MirrorFace since at least 2021.
- HiddenLotus dropper
- According to Malwarebytes, The HiddenLotus "dropper" is an application named Lê Thu Hà (HAEDC).pdf, using an old trick of disguising…
- HiddenTear ransomware
- Also known as Cryptear, EDA2, Hidden Tear. HiddenTear is an open-source ransomware written in C#.
- HiddenWasp trojan
- HiddenWasp is a Linux-based Trojan used to target systems for remote control.
- Hide and Seek botnetworm
- Also known as HNS. Hide and Seek, also known as HNS, is a sophisticated IoT malware operating as a decentralized peer-to-peer botnet.
- HijackLoader loader
- Also known as DOILoader, GHOSTPULSE, IDAT Loader. According to Rapid7, this is a loader first spotted in July 2023.
- Hikit backdoor
- Hikit is malware that has been used by Axiom for late-stage persistence and exfiltration after the initial compromise.
- HilalRAT rat
- HilalRAT is a remote access-capable Android malware, developed and used by UNC788.
- Hildacrypt ransomware
- The Hildacrypt ransomware encrypts the victim’s files with a strong encryption algorithm and the filename extension .hilda until the…
- Hildegard cryptominer
- Hildegard is malware that targets misconfigured kubelets for initial access and runs cryptocurrency miner operations.
- Himera Loader loader
- Himera Loader is a type of malware used to deliver additional malicious payloads onto the targeted system.
- HinataBot ddosbotnet
- HinataBot is a Go-based DDoS-focused botnet.
- Hipid rat
- Hipid is a Remote Access Trojan (RAT) used primarily in cyber espionage campaigns targeting government and technology sectors.
- Hisoka ratcredential-stealer
- Hisoka is a remote access tool (RAT) known for its capabilities in stealing credentials and targeting government and financial sectors.
- Hitler ransomwarewiper
- Hitler ransomware is a malicious software that encrypts files on the victim's computer and deletes them after a set period, causing…
- Hive ransomware
- First observed in June 2021, Hive ransomware was originally written in GoLang but recently, new Hive variants have been seen written in…
- Hive (ELF) ransomware
- Hive ransomware is a prominent threat known for its sophisticated data encryption techniques and double-extortion tactics, targeting…
- Hive (Vault 8) ransomware
- Hive is a ransomware-as-a-service operation known for targeting organizations in critical industries, engaging in double extortion tactics…
- Hive (Windows) ransomware
- Hive is a strain of ransomware that was first discovered in June 2021.
- Hodur rat
- Hodur is a remote access trojan associated with cyber espionage activities, primarily targeting governmental and financial sectors.
- Hog ransomware
- Hog is a type of ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
- Holcus Installer (Adware)
- Holcus Installer is adware tied to malicious campaigns known as eGobbler and Nephos7.
- HoldingHands rat
- HoldingHands is a sophisticated modular Remote Access Trojan (RAT) and cyberespionage tool used primarily in targeted multi-stage…
- HolidayCheer ransomware
- HolidayCheer is a ransomware that encrypts a victim's data and demands payment in cryptocurrency.
- Hollycrypt Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- HolyCrypt ransomware
- HolyCrypt is a type of ransomware that encrypts victims' files and demands ransom for decryption.
- Honor ransomware
- Honor is a ransomware that encrypts files on the infected system and demands payment for decryption.
- Hook rattrojan
- According to ThreatFabric, this is a malware family based on apk.ermac.
- HookInjEx loadertrojan
- HookInjEx is a trojan and loader malware that is capable of injecting malicious code into legitimate processes, allowing attackers to gain…
- Hopscotch backdoorspywarerootkit
- Hopscotch is a component of the sophisticated Regin framework, known for its use in espionage and surveillance activities against…
- Hornbill spyware
- Hornbill is one of two mobile malware families known to be used by the APT Confucius.
- Horros ransomware
- Horros is a type of ransomware that encrypts files on an infected system, demanding a ransom for their decryption.
- Horse Shell backdoorrat
- Checkpoint Research describes this as part of a custom firmware image affiliated with the Chinese state-sponsored actor “Camaro Dragon”, a…
- Horus rat
- According to Check Point Research, this is a custom-built agent for Mythic, the open-source red teaming C2 framework.
- Horus Eyes RAT trojanrat
- Warsaw trojan is a new banking trojan based on the Hours Eyes RAT core engine.
- HorusEyes RAT rat
- HorusEyes RAT is a Remote Access Tool written in VB.NET used for unauthorized access and control over a victim's system.
- HotCroissant rat
- HotCroissant is a remote access trojan (RAT) attributed by U.S.
- Hotarus ransomware
- Hotarus is a ransomware and data extortion group first observed in March 2021, believed to be linked to threat actors of Latin American…
- Houdini rat
- Also known as Hworm, Jenxcus, Kognito. Houdini is a VBS-based RAT dating back to 2013.