Malware Families page 23 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

HappyDayzz ransomware
HappyDayzz is a ransomware that encrypts files on infected systems and demands a ransom for decryption.
HappyLocker (HiddenTear?) ransomware
HappyLocker is a ransomware variant related to the HiddenTear project, known for encrypting victims' files and demanding a ransom for…
Harasom ransomware
Harasom is a type of ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
Harnig downloader
Also known as Piptea. Harnig, also known as Piptea, is a malware downloader used to install additional malicious software onto infected systems.
Haron ransomware
Haron is a ransomware strain known for targeting multiple industries with double-extortion tactics.
Haron Ransomware ransomware
Haron Ransomware is a file-encrypting malware that targets various industries with the intent of extortion.
Hatef wiper
Hatef is a wiper malware identified by Intezer.
Hav-RAT rat
Hav-RAT is a remote access tool written in Delphi, known for targeting government and financial sectors.
HavanaCrypt ransomware
HavanaCrypt is a ransomware variant that emerged in mid-2022, characterized by its capability to encrypt files on an infected machine…
Havex RAT rat
Havex is a remote access trojan (RAT) that was discovered in 2013 as part of a widespread espionage campaign targeting industrial control…
Havij exploit-kit
Havij is an automatic SQL Injection tool distributed by the Iranian ITSecTeam security company.
Havoc ratbackdoorransomware
Also known as HavocCrypt Ransomware, Havokiz. Havoc is an open-source post-exploitation command and control (C2) framework first released on GitHub in October 2022 by C5pider (Paul…
HawkEye ratkeyloggercredential-stealer
HawkEye is a popular RAT that can be used as a keylogger, it is also able to identify login events and record the destination, username…
HawkEye Keylogger keyloggercredential-stealerloader
Also known as HawkEye, HawkEye Reborn, Predator Pain. HawKeye is a keylogger that is distributed since 2013.
HawkShaw rat
HawkShaw is a sophisticated remote access tool used primarily for cyber espionage.
Hawking
Hawking is a relatively unknown malware with limited public information available.
Haxerboi Ransomware ransomware
Haxerboi Ransomware is a type of malicious software designed to extort money from victims by encrypting their files and demanding a ransom…
Haze ransomware
Haze is a ransomware variant that encrypts files on infected systems, demanding a ransom for decryption keys.
HazyLoad loader
HazyLoad is a malware loader designed to deploy additional malicious payloads on compromised systems.
HeadCrab cryptominer
HeadCrab is a sophisticated malware primarily used to mine cryptocurrency.
HeaderTip backdoor
The Chinese threat actor "Scarab" is using a custom backdoor dubbed "HeaderTip" according to SentinelLABS.
Headlace
Headlace is a malware entity with limited available public information.
HeartCrypt
HeartCrypt is a packer-as-a-service (PaaS) used to protect malware that has been available since at least 2024.
Heimdall ransomware
Heimdall is a ransomware that encrypts files and appends a specific marker 'Heimdall---'.
Helauto ratloader
Helauto is a remote access trojan known for its ability to provide unauthorized access and control over targeted systems.
HelloBot (ELF) botnetddos
HelloBot (ELF) is a Linux-based botnet malware typically used for Distributed Denial-of-Service (DDoS) attacks.
HelloBot (Windows) botnettrojan
HelloBot is a malware family primarily targeting financial services and technology companies.
HelloKitty (ELF) ransomware
HelloKitty (ELF) is a Linux variant of the HelloKitty ransomware, known for targeting Linux systems, particularly in sectors like…
HelloKitty (Windows) ransomware
Also known as KittyCrypt. Unit42 states that HelloKitty is a ransomware family that first surfaced at the end of 2020, primarily targeting Windows systems.
HelloXD ransomware
HelloXD is a ransomware family performing double extortion attacks that surfaced in November 2021.
Helminth backdoor
Helminth is a backdoor that has at least two variants - one written in VBScript and PowerShell that is delivered via a macros in Excel…
Heloag downloaderrat
Heloag is a sophisticated malware commonly associated with APT37 and the Lazarus Group, known for targeting the government sector.
HelpDCFile ransomware
HelpDCFile is a ransomware strain that encrypts the victim's files and demands a ransom for decryption.
HelpMe ransomware
HelpMe is a ransomware strain known for encrypting victim files and demanding a ransom for decryption.
Help_dcfile ransomware
Help_dcfile is a ransomware variant that encrypts files on infected systems and demands a ransom payment for decryption.
HemiGate backdoorrat
HemiGate is a sophisticated backdoor and remote access tool (RAT) utilized primarily in cyber-espionage campaigns targeting government and…
HenBox spywaretrojan
HenBox is Android malware that attempts to only execute on Xiaomi devices running the MIUI operating system.
Herbst ransomware
Herbst is a ransomware strain known for encrypting files on infected systems and demanding ransom payments in exchange for decryption keys.
Heriplor rat
Heriplor is a remote access trojan (RAT) used primarily for cyber-espionage activities.
Hermes Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Hermes837 ransomware
Hermes837 is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
HermesVirus HT ransomware
HermesVirus HT is a ransomware family that encrypts victims' files and demands payment for decryption.
HermeticWiper wiper
Also known as Trojan.Killdisk, DriveSlayer, FoxBlade. HermeticWiper is a data wiper that has been used since at least early 2022, primarily against Ukraine with additional activity observed in…
HermeticWizard wormwiper
HermeticWizard is a worm that has been used to spread HermeticWiper in attacks against organizations in Ukraine since at least 2022.
Hermit spyware
Lookout states that Hermit is an advanced spyware designed to target iOS and Android mobile devices.
HeroRAT rat
HeroRAT is a remote access trojan targeting Android devices, capable of controlling infected devices and stealing sensitive information.
Heropoint ransomware
Heropoint is ransomware known for encrypting files on victim systems and demanding a ransom payment for decryption.
HerpesBot botnet
HerpesBot is a botnet family with the capability to control infected devices.
Heseber trojanloader
Heseber is a sophisticated malware family primarily used in cyber espionage campaigns.
HesperBot trojancredential-stealerkeylogger
HesperBot is a sophisticated banking Trojan known for targeting financial institutions primarily in Turkey, the Czech Republic, and the UK.
HexEval Loader loaderdownloader
HexEval Loader is a hex-encoded loader that collects host data, decodes follow-on scripts and acts as a downloader for the BeaverTail…
HexaLocker ransomware
On August 9th, 2024, the HexaLocker team advertised a new Windows ransomware on its Telegram channel.
Heyoka Backdoor backdoor
Heyoka Backdoor is a custom backdoor--based on the Heyoka open source exfiltration tool--that has been used by Aoqin Dragon since at least…
Hi Buddy! ransomware
Hi Buddy! is a ransomware variant based on the HiddenTear source code.
Hi-Zor rat
Hi-Zor is a remote access tool (RAT) that has characteristics similar to Sakula.
Hi-Zor RAT rat
Hi-Zor RAT is a remote access trojan that has been identified in espionage campaigns primarily targeting government and infrastructure…
HiAsm backdoorrat
HiAsm is a remote access trojan (RAT) that typically gains unauthorized access to victim machines, allowing attackers to execute remote…
HiatusRAT rat
Lumen discovered this malware used in campaign targeting business-grade routers using a RAT they call HiatusRAT and a variant of tcpdump…
Hidden Bee botnetcryptominer
Hidden Bee is a malware family known for its complex infection chains.
HiddenAd
HiddenAd is a malware that shows ads as overlays on the phone.
HiddenBeer ransomware
HiddenBeer is a ransomware family known for encrypting data and demanding a ransom for the decryption key.
HiddenFace backdoor
Also known as NOOPDOOR. HiddenFace is a modular backdoor developed and used exclusively by MirrorFace since at least 2021.
HiddenLotus dropper
According to Malwarebytes, The HiddenLotus "dropper" is an application named Lê Thu Hà (HAEDC).pdf, using an old trick of disguising…
HiddenTear ransomware
Also known as Cryptear, EDA2, Hidden Tear. HiddenTear is an open-source ransomware written in C#.
HiddenWasp trojan
HiddenWasp is a Linux-based Trojan used to target systems for remote control.
Hide and Seek botnetworm
Also known as HNS. Hide and Seek, also known as HNS, is a sophisticated IoT malware operating as a decentralized peer-to-peer botnet.
HijackLoader loader
Also known as DOILoader, GHOSTPULSE, IDAT Loader. According to Rapid7, this is a loader first spotted in July 2023.
Hikit backdoor
Hikit is malware that has been used by Axiom for late-stage persistence and exfiltration after the initial compromise.
HilalRAT rat
HilalRAT is a remote access-capable Android malware, developed and used by UNC788.
Hildacrypt ransomware
The Hildacrypt ransomware encrypts the victim’s files with a strong encryption algorithm and the filename extension .hilda until the…
Hildegard cryptominer
Hildegard is malware that targets misconfigured kubelets for initial access and runs cryptocurrency miner operations.
Himera Loader loader
Himera Loader is a type of malware used to deliver additional malicious payloads onto the targeted system.
HinataBot ddosbotnet
HinataBot is a Go-based DDoS-focused botnet.
Hipid rat
Hipid is a Remote Access Trojan (RAT) used primarily in cyber espionage campaigns targeting government and technology sectors.
Hisoka ratcredential-stealer
Hisoka is a remote access tool (RAT) known for its capabilities in stealing credentials and targeting government and financial sectors.
Hitler ransomwarewiper
Hitler ransomware is a malicious software that encrypts files on the victim's computer and deletes them after a set period, causing…
Hive ransomware
First observed in June 2021, Hive ransomware was originally written in GoLang but recently, new Hive variants have been seen written in…
Hive (ELF) ransomware
Hive ransomware is a prominent threat known for its sophisticated data encryption techniques and double-extortion tactics, targeting…
Hive (Vault 8) ransomware
Hive is a ransomware-as-a-service operation known for targeting organizations in critical industries, engaging in double extortion tactics…
Hive (Windows) ransomware
Hive is a strain of ransomware that was first discovered in June 2021.
Hodur rat
Hodur is a remote access trojan associated with cyber espionage activities, primarily targeting governmental and financial sectors.
Hog ransomware
Hog is a type of ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
Holcus Installer (Adware)
Holcus Installer is adware tied to malicious campaigns known as eGobbler and Nephos7.
HoldingHands rat
HoldingHands is a sophisticated modular Remote Access Trojan (RAT) and cyberespionage tool used primarily in targeted multi-stage…
HolidayCheer ransomware
HolidayCheer is a ransomware that encrypts a victim's data and demands payment in cryptocurrency.
Hollycrypt Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
HolyCrypt ransomware
HolyCrypt is a type of ransomware that encrypts victims' files and demands ransom for decryption.
Honor ransomware
Honor is a ransomware that encrypts files on the infected system and demands payment for decryption.
Hook rattrojan
According to ThreatFabric, this is a malware family based on apk.ermac.
HookInjEx loadertrojan
HookInjEx is a trojan and loader malware that is capable of injecting malicious code into legitimate processes, allowing attackers to gain…
Hopscotch backdoorspywarerootkit
Hopscotch is a component of the sophisticated Regin framework, known for its use in espionage and surveillance activities against…
Hornbill spyware
Hornbill is one of two mobile malware families known to be used by the APT Confucius.
Horros ransomware
Horros is a type of ransomware that encrypts files on an infected system, demanding a ransom for their decryption.
Horse Shell backdoorrat
Checkpoint Research describes this as part of a custom firmware image affiliated with the Chinese state-sponsored actor “Camaro Dragon”, a…
Horus rat
According to Check Point Research, this is a custom-built agent for Mythic, the open-source red teaming C2 framework.
Horus Eyes RAT trojanrat
Warsaw trojan is a new banking trojan based on the Hours Eyes RAT core engine.
HorusEyes RAT rat
HorusEyes RAT is a Remote Access Tool written in VB.NET used for unauthorized access and control over a victim's system.
HotCroissant rat
HotCroissant is a remote access trojan (RAT) attributed by U.S.
Hotarus ransomware
Hotarus is a ransomware and data extortion group first observed in March 2021, believed to be linked to threat actors of Latin American…
Houdini rat
Also known as Hworm, Jenxcus, Kognito. Houdini is a VBS-based RAT dating back to 2013.