Malware Families page 24 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

HowAreYou ransomware
HowAreYou is a type of ransomware that encrypts files on the victim's system and demands a ransom for decryption.
HtBot botnetddos
HtBot is a malware family known for turning infected machines into proxy servers used for generating web traffic and launching DDoS attacks.
Hubnr trojan
Hubnr is a stealthy banking trojan known for targeting financial institutions.
Hucky Ransomware ransomware
Also known as Hungarian Locky Ransomware. This is most likely to affect English speaking users, since the note is written in English.
HugeMe Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
HummingBad trojan
HummingBad is a family of Android malware that generates fraudulent advertising revenue and has the ability to obtain root access on…
HummingWhale trojan
HummingWhale is an Android malware family that performs ad fraud.
Hunt ransomware
Also known as Hunt-Dharma-Crysis. Hunt ransomware is a variant of the Dharma/CrySIS ransomware family.
Hunter Stealer
Hunters International ransomware
Emerging in Q3 2023 as a Ransomware-as-a-Service (RaaS) operation, Hunters International has established itself as a distinct yet…
Hupigon ratbackdoor
Hupigon is a Remote Access Trojan (RAT) that allows attackers to obtain unauthorized access to an infected computer.
HuskLoader loader
HuskLoader is a versatile malware loader used to introduce payloads into compromised systems.
Hussar trojanbackdoor
Hussar is a trojan and backdoor malware family known to target government and financial sectors mainly in eastern Europe.
HxDef rootkit
Also known as HacDef, HackDef, HackerDefender. HxDef, also known as HackerDefender, is a well-known rootkit for Windows systems that is used to hide processes, files, and registry keys…
Hydra ransomware
Hydra is a ransomware that encrypts files on infected systems and demands a ransom payment for the decryption key.
HydraCrypt ransomware
HydraCrypt is a ransomware variant categorized under the CrypBoss family, known for encrypting victim's files and demanding a ransom for…
Hydraq rattrojan
Also known as Roarur, MdmBot, HomeUnix. Hydraq is a data-theft trojan first used by Elderwood in the 2009 Google intrusion known as Operation Aurora, though variations of this…
HyperBro backdoorrat
HyperBro is a custom in-memory backdoor used by Threat Group-3390.
HyperSSL (ELF) rat
Also known as SysUpdate. HyperSSL, also known as SysUpdate, is a Linux-based remote access tool (RAT) targeting specific sectors in Asia.
HyperStack backdoor
HyperStack is a RPC-based backdoor used by Turla since at least 2018.
I2PRAT ratcredential-stealer
Also known as I2Parcae. According to Cofense, this malware is notable for having several unique tactics, techniques, and procedures (TTPs), such as Secure Email…
IClickFix downloaderloader
IClickFix is a malicious JavaScript framework deployed on compromised WordPress sites to deliver further malware using the ClickFix social…
IDKEY credential-stealerkeylogger
IDKEY is a credential-stealing malware often used to capture sensitive information such as passwords and usernames.
IFN643 Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
IGotYou ransomware
IGotYou is a type of ransomware that encrypts files on infected systems and demands a ransom payment for the decryption key.
IISniff credential-stealerspyware
IISniff is a specialized malware targeting Microsoft IIS servers, designed to intercept and exfiltrate sensitive information from HTTP…
IISpy webshellspyware
Also known as BadIIS. IISpy, also known as BadIIS, is a sophisticated webshell and spyware that targets IIS web servers.
ILElection2020 ransomware
ILElection2020 is a ransomware type of malware known to target sectors involved with government and media, focusing on disrupting critical…
IMAPLoader loader
IMAPLoader is a .NET-based loader malware exclusively associated with CURIUM operations since at least 2022.
INC
INC Ransomware ransomware
INC Ransomware is a ransomware strain that has been used by the INC Ransom group since at least 2023 against multiple industry sectors…
INCONTROLLER exploit-kit
Also known as PIPEDREAM. INCONTROLLER is custom malware that includes multiple modules tailored towards ICS devices and technologies, including Schneider Electric…
INPIVX ransomware
INPIVX is a type of ransomware that encrypts files on a victim's system and demands a ransom payment in exchange for a decryption key.
INSOMNIA spyware
INSOMNIA is spyware that has been used by the group Evil Eye.
IPA ransomware
IPA is a type of ransomware that encrypts the victim's files and demands a ransom for decryption.
IPStorm (Android) botnetbackdoor
Also known as InterPlanetary Storm. Android variant of IPStorm (InterPlanetary Storm).
IPStorm (ELF) botnetworm
Also known as InterPlanetary Storm. IPStorm, also known as InterPlanetary Storm, is a botnet malware leveraging peer-to-peer communication for its operations.
IPStorm (Windows) botnet
IPStorm, also known as InterPlanetary Storm, is a Windows-targeted botnet leveraging Peer-to-Peer networking.
IPsec Helper rat
IPsec Helper is a post-exploitation remote access tool linked to Agrius operations.
IRATA rattrojan
According to redpiranha, IRATA (Iranian Remote Access Trojan) Android Malware is a new malware detected in the wild.
IRONHALO downloader
IRONHALO is a downloader that uses the HTTP protocol to retrieve a Base64 encoded payload from a hard-coded command-and-control (CnC)…
IRRat rat
IRRat is a remote access trojan (RAT) known for allowing attackers to remotely control infected devices.
ISFB trojancredential-stealer
Also known as Gozi ISFB, IAP, Pandemyia. 2006 Gozi v1.0, Gozi CRM, CRM, Papras 2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) In September 2010, the source code of a particular…
ISMAgent spyware
ISMAgent is a piece of spying software designed to exfiltrate data from infected systems.
ISMDoor rat
ISMDoor is a remote access tool primarily used for espionage activities.
ISMInjector trojandropper
ISMInjector is a Trojan used to install another OilRig backdoor, ISMAgent.
ISR Stealer credential-stealer
ISR Stealer is a modified version of the Hackhound Stealer.
IT.Books ransomware
IT.Books is a ransomware family known for targeting various sectors including education, government, and healthcare.
IXWare ransomware
IXWare is a ransomware family known for encrypting files on affected systems and demanding a ransom for decryption.
IZ1H9 botnetddos
ccording to Fortinet, this is a Mirai-based DDoS botnet.
Icarus credential-stealerrootkit
Icarus is a modular stealer software, written in .NET.
Ice IX botnettrojancredential-stealer
The ICE IX bot is a banking trojan derived of the Zeus botnet because it uses significant parts of Zeus’s source code.
IceApple webshellexploit-kit
IceApple is a modular Internet Information Services (IIS) post-exploitation framework, that has been used since at least 2021 against the…
IceCache backdoorwebshell
According to nao_sec, this malware is an IIS backdoor.
IceEvent backdoor
According to nao_sec, this malware is a simple passive-mode backdoor that is installed as a service.
IceRat credential-stealercryptominer
According to Karsten Hahn, this malware is actually written in JPHP, but can be treated similar to .class files produced by Java.
IcedID trojancredential-stealerbotnet
Also known as BokBot, IceID. IcedID is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017.
IcedID Downloader downloadertrojan
IcedID is a financial malware that functions primarily as a downloader.
Icefire ransomware
Icefire is a ransomware family known for targeting specific industries, primarily focusing on technology and critical infrastructure…
Icefog rattrojan
Also known as Fucobha. Icefog, also known as Fucobha, is a cyber espionage malware family primarily targeting the supply chain in sectors such as defense…
Icesword webshell
Icesword is a type of webshell known for providing attackers with remote access to compromised web servers.
Icnanker trojanbackdoor
Icnanker is a sophisticated Trojan primarily targeting the financial sector.
IconDown backdoordropper
IconDown is a backdoor malware used in targeted espionage campaigns, primarily against government and financial sectors.
IconicStealer credential-stealerspyware
Follow-up payload in 3CX supply chain incident, which according to Volexity is an infostealer collecting information about the system and…
IcyHeart trojanbackdoor
Also known as Troxen. IcyHeart, also known as Troxen, is a sophisticated piece of malware primarily used for cyber-espionage.
Iloveyou wormvirus
Also known as Love Bug, LoveLetter. Iloveyou is a computer worm that spread rapidly via email in 2000.
ImSorry ransomware
ImSorry is a type of ransomware designed to encrypt files on the infected system, demanding a ransom for decryption keys.
Imecab rat
Imecab is a Remote Access Trojan (RAT) known for targeting Japanese entities, particularly in the government and technology sectors.
Imminent Monitor rat
Imminent Monitor was a commodity remote access tool (RAT) offered for sale from 2012 until 2019, when an operation was conducted to take…
Imminent Monitor RAT rat
MITRE describes Imminent Monitor as a commodity remote access tool (RAT) offered for sale from 2012 until 2019, when an operation was…
Immortal Stealer credential-stealerspyware
ZScaler describes Immortal Stealer as a windows malware written in .NET designed to steal sensitive information from an infected machine.
Immuni ransomware
Immuni is ransomware designed to encrypt files on the infected systems, demanding a ransom payment for decryption.
Impacket credential-stealerexploit-kitspyware
Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols.
ImprudentCook downloader
ImprudentCook is an HTTP(S) downloader. It was delivered in the Operation DreamJob type of activity targeting aerospace and defense…
Ims00ry ransomware
Ims00ry is a ransomware that encrypts files on infected systems and demands a ransom for decryption.
Incanto ransomware
Incanto is a type of ransomware known for encrypting victim data and demanding a ransom for its decryption.
Incubator keylogger
Keylogger written in Visual Basic dating back to at least 2012.
Indetectables RAT rat
Indetectables RAT is a remote access tool that offers stealth capabilities and is often used in cybercrime activities.
IndigoDrop dropper
IndigoDrop is a piece of malware primarily used as a dropper to deploy additional payloads.
Indrik ransomware
Indrik is a type of ransomware that encrypts victim's files and demands a ransom for decryption.
InducVirus ransomware
InducVirus is a type of ransomware that encrypts files and demands payment for decryption.
Industrial Spy ransomware
Industrial Spy is a ransomware that emerged in April 2022.
Industroyer
Also known as CRASHOVERRIDE. Industroyer is a sophisticated piece of malware designed to cause an Impact to the working processes of Industrial Control Systems (ICS)…
Industroyer wiper
Also known as CRASHOVERRIDE, Win32/Industroyer, Crash. Industroyer is a sophisticated malware framework designed to cause an impact to the working processes of Industrial Control Systems (ICS)…
Industroyer2 trojan
Industroyer2 is a compiled and static piece of malware that has the ability to communicate over the IEC-104 protocol.
Inferno
No description available.
InfinityLock ransomware
InfinityLock is a ransomware family known for encrypting files on infected systems and demanding payment for decryption keys.
InfoDot ransomware
InfoDot is a ransomware strain that encrypts the victim's files and demands payment for the decryption key.
Infy spyware
Also known as Foudre. Infy, also known as Foudre, is an advanced spyware used primarily for cyber espionage.
Inlock ransomware
Inlock is a ransomware family that primarily targets financial services and government sectors.
InnaputRAT rat
InnaputRAT is a remote access tool that can exfiltrate files from a victim’s machine.
InnfiRAT ratscreen-capture
new RAT called InnfiRAT, which is written in .NET and designed to perform specific tasks from an infected machine
InsaneCrypt ransomware
InsaneCrypt is a type of ransomware that encrypts files on infected systems, demanding a ransom payment in exchange for decryption.
InsidiousGh0st (ELF) rat
RAT. Functionality like ExecShell, GetFileList/SendFile/DownloadFile, Socks5, PortmapManager/GetConn/SendConn. Transport also supports…
InsidiousGh0st (OS X) rat
RAT. Functionality like ExecShell, GetFileList/SendFile/DownloadFile, Socks5, PortmapManager/GetConn/SendConn. Transport also supports…
InstallPay ransomware
InstallPay is a type of ransomware that encrypts data on infected systems, demanding payment for decryption.
Interception (OS X) spywaretrojan
Interception is a macOS spyware that focuses on data exfiltration and system surveillance.
Interception (Windows) rat
ESET noticed attacks against aerospace and military companies in Europe and the Middle East that took place between September and December…
Interlock (ELF) ransomware
According to Sekoia, this is the ransomware used by the Interlock ransomware intrusion set, which was first observed in September 2024…
Interlock (Windows) ransomware
According to Sekoia, this is the ransomware used by the Interlock ransomware intrusion set, which was first observed in September 2024…