Malware Families page 24 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- HowAreYou ransomware
- HowAreYou is a type of ransomware that encrypts files on the victim's system and demands a ransom for decryption.
- HtBot botnetddos
- HtBot is a malware family known for turning infected machines into proxy servers used for generating web traffic and launching DDoS attacks.
- Hubnr trojan
- Hubnr is a stealthy banking trojan known for targeting financial institutions.
- Hucky Ransomware ransomware
- Also known as Hungarian Locky Ransomware. This is most likely to affect English speaking users, since the note is written in English.
- HugeMe Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- HummingBad trojan
- HummingBad is a family of Android malware that generates fraudulent advertising revenue and has the ability to obtain root access on…
- HummingWhale trojan
- HummingWhale is an Android malware family that performs ad fraud.
- Hunt ransomware
- Also known as Hunt-Dharma-Crysis. Hunt ransomware is a variant of the Dharma/CrySIS ransomware family.
- Hunter Stealer
- Hunters International ransomware
- Emerging in Q3 2023 as a Ransomware-as-a-Service (RaaS) operation, Hunters International has established itself as a distinct yet…
- Hupigon ratbackdoor
- Hupigon is a Remote Access Trojan (RAT) that allows attackers to obtain unauthorized access to an infected computer.
- HuskLoader loader
- HuskLoader is a versatile malware loader used to introduce payloads into compromised systems.
- Hussar trojanbackdoor
- Hussar is a trojan and backdoor malware family known to target government and financial sectors mainly in eastern Europe.
- HxDef rootkit
- Also known as HacDef, HackDef, HackerDefender. HxDef, also known as HackerDefender, is a well-known rootkit for Windows systems that is used to hide processes, files, and registry keys…
- Hydra ransomware
- Hydra is a ransomware that encrypts files on infected systems and demands a ransom payment for the decryption key.
- HydraCrypt ransomware
- HydraCrypt is a ransomware variant categorized under the CrypBoss family, known for encrypting victim's files and demanding a ransom for…
- Hydraq rattrojan
- Also known as Roarur, MdmBot, HomeUnix. Hydraq is a data-theft trojan first used by Elderwood in the 2009 Google intrusion known as Operation Aurora, though variations of this…
- HyperBro backdoorrat
- HyperBro is a custom in-memory backdoor used by Threat Group-3390.
- HyperSSL (ELF) rat
- Also known as SysUpdate. HyperSSL, also known as SysUpdate, is a Linux-based remote access tool (RAT) targeting specific sectors in Asia.
- HyperStack backdoor
- HyperStack is a RPC-based backdoor used by Turla since at least 2018.
- I2PRAT ratcredential-stealer
- Also known as I2Parcae. According to Cofense, this malware is notable for having several unique tactics, techniques, and procedures (TTPs), such as Secure Email…
- IClickFix downloaderloader
- IClickFix is a malicious JavaScript framework deployed on compromised WordPress sites to deliver further malware using the ClickFix social…
- IDKEY credential-stealerkeylogger
- IDKEY is a credential-stealing malware often used to capture sensitive information such as passwords and usernames.
- IFN643 Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- IGotYou ransomware
- IGotYou is a type of ransomware that encrypts files on infected systems and demands a ransom payment for the decryption key.
- IISniff credential-stealerspyware
- IISniff is a specialized malware targeting Microsoft IIS servers, designed to intercept and exfiltrate sensitive information from HTTP…
- IISpy webshellspyware
- Also known as BadIIS. IISpy, also known as BadIIS, is a sophisticated webshell and spyware that targets IIS web servers.
- ILElection2020 ransomware
- ILElection2020 is a ransomware type of malware known to target sectors involved with government and media, focusing on disrupting critical…
- IMAPLoader loader
- IMAPLoader is a .NET-based loader malware exclusively associated with CURIUM operations since at least 2022.
- INC
- INC Ransomware ransomware
- INC Ransomware is a ransomware strain that has been used by the INC Ransom group since at least 2023 against multiple industry sectors…
- INCONTROLLER exploit-kit
- Also known as PIPEDREAM. INCONTROLLER is custom malware that includes multiple modules tailored towards ICS devices and technologies, including Schneider Electric…
- INPIVX ransomware
- INPIVX is a type of ransomware that encrypts files on a victim's system and demands a ransom payment in exchange for a decryption key.
- INSOMNIA spyware
- INSOMNIA is spyware that has been used by the group Evil Eye.
- IPA ransomware
- IPA is a type of ransomware that encrypts the victim's files and demands a ransom for decryption.
- IPStorm (Android) botnetbackdoor
- Also known as InterPlanetary Storm. Android variant of IPStorm (InterPlanetary Storm).
- IPStorm (ELF) botnetworm
- Also known as InterPlanetary Storm. IPStorm, also known as InterPlanetary Storm, is a botnet malware leveraging peer-to-peer communication for its operations.
- IPStorm (Windows) botnet
- IPStorm, also known as InterPlanetary Storm, is a Windows-targeted botnet leveraging Peer-to-Peer networking.
- IPsec Helper rat
- IPsec Helper is a post-exploitation remote access tool linked to Agrius operations.
- IRATA rattrojan
- According to redpiranha, IRATA (Iranian Remote Access Trojan) Android Malware is a new malware detected in the wild.
- IRONHALO downloader
- IRONHALO is a downloader that uses the HTTP protocol to retrieve a Base64 encoded payload from a hard-coded command-and-control (CnC)…
- IRRat rat
- IRRat is a remote access trojan (RAT) known for allowing attackers to remotely control infected devices.
- ISFB trojancredential-stealer
- Also known as Gozi ISFB, IAP, Pandemyia. 2006 Gozi v1.0, Gozi CRM, CRM, Papras 2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) In September 2010, the source code of a particular…
- ISMAgent spyware
- ISMAgent is a piece of spying software designed to exfiltrate data from infected systems.
- ISMDoor rat
- ISMDoor is a remote access tool primarily used for espionage activities.
- ISMInjector trojandropper
- ISMInjector is a Trojan used to install another OilRig backdoor, ISMAgent.
- ISR Stealer credential-stealer
- ISR Stealer is a modified version of the Hackhound Stealer.
- IT.Books ransomware
- IT.Books is a ransomware family known for targeting various sectors including education, government, and healthcare.
- IXWare ransomware
- IXWare is a ransomware family known for encrypting files on affected systems and demanding a ransom for decryption.
- IZ1H9 botnetddos
- ccording to Fortinet, this is a Mirai-based DDoS botnet.
- Icarus credential-stealerrootkit
- Icarus is a modular stealer software, written in .NET.
- Ice IX botnettrojancredential-stealer
- The ICE IX bot is a banking trojan derived of the Zeus botnet because it uses significant parts of Zeus’s source code.
- IceApple webshellexploit-kit
- IceApple is a modular Internet Information Services (IIS) post-exploitation framework, that has been used since at least 2021 against the…
- IceCache backdoorwebshell
- According to nao_sec, this malware is an IIS backdoor.
- IceEvent backdoor
- According to nao_sec, this malware is a simple passive-mode backdoor that is installed as a service.
- IceRat credential-stealercryptominer
- According to Karsten Hahn, this malware is actually written in JPHP, but can be treated similar to .class files produced by Java.
- IcedID trojancredential-stealerbotnet
- Also known as BokBot, IceID. IcedID is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017.
- IcedID Downloader downloadertrojan
- IcedID is a financial malware that functions primarily as a downloader.
- Icefire ransomware
- Icefire is a ransomware family known for targeting specific industries, primarily focusing on technology and critical infrastructure…
- Icefog rattrojan
- Also known as Fucobha. Icefog, also known as Fucobha, is a cyber espionage malware family primarily targeting the supply chain in sectors such as defense…
- Icesword webshell
- Icesword is a type of webshell known for providing attackers with remote access to compromised web servers.
- Icnanker trojanbackdoor
- Icnanker is a sophisticated Trojan primarily targeting the financial sector.
- IconDown backdoordropper
- IconDown is a backdoor malware used in targeted espionage campaigns, primarily against government and financial sectors.
- IconicStealer credential-stealerspyware
- Follow-up payload in 3CX supply chain incident, which according to Volexity is an infostealer collecting information about the system and…
- IcyHeart trojanbackdoor
- Also known as Troxen. IcyHeart, also known as Troxen, is a sophisticated piece of malware primarily used for cyber-espionage.
- Iloveyou wormvirus
- Also known as Love Bug, LoveLetter. Iloveyou is a computer worm that spread rapidly via email in 2000.
- ImSorry ransomware
- ImSorry is a type of ransomware designed to encrypt files on the infected system, demanding a ransom for decryption keys.
- Imecab rat
- Imecab is a Remote Access Trojan (RAT) known for targeting Japanese entities, particularly in the government and technology sectors.
- Imminent Monitor rat
- Imminent Monitor was a commodity remote access tool (RAT) offered for sale from 2012 until 2019, when an operation was conducted to take…
- Imminent Monitor RAT rat
- MITRE describes Imminent Monitor as a commodity remote access tool (RAT) offered for sale from 2012 until 2019, when an operation was…
- Immortal Stealer credential-stealerspyware
- ZScaler describes Immortal Stealer as a windows malware written in .NET designed to steal sensitive information from an infected machine.
- Immuni ransomware
- Immuni is ransomware designed to encrypt files on the infected systems, demanding a ransom payment for decryption.
- Impacket credential-stealerexploit-kitspyware
- Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols.
- ImprudentCook downloader
- ImprudentCook is an HTTP(S) downloader. It was delivered in the Operation DreamJob type of activity targeting aerospace and defense…
- Ims00ry ransomware
- Ims00ry is a ransomware that encrypts files on infected systems and demands a ransom for decryption.
- Incanto ransomware
- Incanto is a type of ransomware known for encrypting victim data and demanding a ransom for its decryption.
- Incubator keylogger
- Keylogger written in Visual Basic dating back to at least 2012.
- Indetectables RAT rat
- Indetectables RAT is a remote access tool that offers stealth capabilities and is often used in cybercrime activities.
- IndigoDrop dropper
- IndigoDrop is a piece of malware primarily used as a dropper to deploy additional payloads.
- Indrik ransomware
- Indrik is a type of ransomware that encrypts victim's files and demands a ransom for decryption.
- InducVirus ransomware
- InducVirus is a type of ransomware that encrypts files and demands payment for decryption.
- Industrial Spy ransomware
- Industrial Spy is a ransomware that emerged in April 2022.
- Industroyer
- Also known as CRASHOVERRIDE. Industroyer is a sophisticated piece of malware designed to cause an Impact to the working processes of Industrial Control Systems (ICS)…
- Industroyer wiper
- Also known as CRASHOVERRIDE, Win32/Industroyer, Crash. Industroyer is a sophisticated malware framework designed to cause an impact to the working processes of Industrial Control Systems (ICS)…
- Industroyer2 trojan
- Industroyer2 is a compiled and static piece of malware that has the ability to communicate over the IEC-104 protocol.
- Inferno
- No description available.
- InfinityLock ransomware
- InfinityLock is a ransomware family known for encrypting files on infected systems and demanding payment for decryption keys.
- InfoDot ransomware
- InfoDot is a ransomware strain that encrypts the victim's files and demands payment for the decryption key.
- Infy spyware
- Also known as Foudre. Infy, also known as Foudre, is an advanced spyware used primarily for cyber espionage.
- Inlock ransomware
- Inlock is a ransomware family that primarily targets financial services and government sectors.
- InnaputRAT rat
- InnaputRAT is a remote access tool that can exfiltrate files from a victim’s machine.
- InnfiRAT ratscreen-capture
- new RAT called InnfiRAT, which is written in .NET and designed to perform specific tasks from an infected machine
- InsaneCrypt ransomware
- InsaneCrypt is a type of ransomware that encrypts files on infected systems, demanding a ransom payment in exchange for decryption.
- InsidiousGh0st (ELF) rat
- RAT. Functionality like ExecShell, GetFileList/SendFile/DownloadFile, Socks5, PortmapManager/GetConn/SendConn. Transport also supports…
- InsidiousGh0st (OS X) rat
- RAT. Functionality like ExecShell, GetFileList/SendFile/DownloadFile, Socks5, PortmapManager/GetConn/SendConn. Transport also supports…
- InstallPay ransomware
- InstallPay is a type of ransomware that encrypts data on infected systems, demanding payment for decryption.
- Interception (OS X) spywaretrojan
- Interception is a macOS spyware that focuses on data exfiltration and system surveillance.
- Interception (Windows) rat
- ESET noticed attacks against aerospace and military companies in Europe and the Middle East that took place between September and December…
- Interlock (ELF) ransomware
- According to Sekoia, this is the ransomware used by the Interlock ransomware intrusion set, which was first observed in September 2024…
- Interlock (Windows) ransomware
- According to Sekoia, this is the ransomware used by the Interlock ransomware intrusion set, which was first observed in September 2024…