Malware Families page 25 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- International Police Association ransomware
- International Police Association is a variant of the CryptoTorLocker2015 ransomware, known for encrypting files and demanding ransom…
- Invicta Stealer credential-stealerspyware
- According to Cyble, The Invicta Stealer can collect system information, system hardware details, wallet data, and browser data and extract…
- InvisiMole spywarebackdoor
- InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013.
- InvisibleFerret ratdropper
- InvisibleFerret is a modular python malware that is leveraged for data exfiltration and remote access capabilities.
- Invoke-PSImage credential-stealertrojan
- Invoke-PSImage takes a PowerShell script and embeds the bytes of the script into the pixels of a PNG image.
- IoT Reaper botnetddosworm
- Also known as IoTroop, Reaper, iotreaper. IoT Reaper, also known as IoTroop or Reaper, is a botnet malware that targets IoT devices.
- Iperius Remote rat
- Iperius Remote is advertised with these features: Control remotely any computer with Iperius Remote Desktop Free.
- Irc16 botnet
- Irc16 is a malware family known for using IRC (Internet Relay Chat) to control a network of infected machines, forming a botnet.
- Iron ransomware
- It is currently unknown if Iron is indeed a new variant by the same creators of Maktub, or if it was simply inspired by the latter, by…
- IronNetInjector dropperloaderrat
- IronNetInjector is a Turla toolchain that utilizes scripts from the open-source IronPython implementation of Python with a .NET injector…
- IronWind loader
- IronWind is a custom loader malware that has been in use since at least 2023 by actors including WIRTE to target entities in the Middle…
- IronZero trojanspyware
- IronZero is an advanced spyware and trojan malware believed to target government and defense sectors.
- Ironcat ransomware
- Ironcat is a ransomware family known for encrypting victim files and demanding ransom payments, primarily targeting sectors such as…
- IsSpace rat
- Also known as NfLog RAT. IsSpace, also known as NfLog RAT, is a remote access trojan used primarily for cyber espionage.
- IsaacWiper wiper
- Also known as LASAINRAW. According to Recorded Future, IsaacWiper is a destructive malware that overwrites all physical disks and logical volumes on a victim’s…
- Ishtar Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- IsraBye wiper
- IsraBye is a malicious wiper malware that predominantly targets computer systems in the Middle East.
- Ixeshe backdoorrat
- Ixeshe is a malware family that has been used since at least 2009 against targets in East Asia.
- J- ransomware
- J- is a ransomware that encrypts victims' files and demands a ransom for decryption.
- J-magic backdoor
- J-magic is a custom variant of the cd00r backdoor tailored to target Juniper routers that was first observed during the J-magic Campaign…
- JADESNOW downloaderbackdoor
- Also known as ChainedDown. JADESNOW is a JavaScript-based downloader malware family associated with the threat cluster UNC5342.
- JCage rat
- JCage is a remote access trojan used for espionage activities, primarily targeting governmental and telecommunications sectors in South…
- JCry ransomware
- JCry is ransomware written in Go. It was identified as apart of the #OpJerusalem 2019 campaign.
- JCrypt ransomware
- Also known as RIP lmao, Locked, Daddycrypt. Ransomware written in C#. Fortunately, all current versions of the MafiaWare666 ransomware are decryptable. The Threat Lab from Avast has…
- JHUHUGIT downloader
- Also known as Trojan.Sofacy, Seduploader, JKEYSKW. JHUHUGIT is malware used by APT28. It is based on Carberp source code and serves as reconnaissance malware.
- JLORAT rat
- JLORAT is a Remote Access Trojan (RAT) used primarily for cyber espionage.
- JNEC.a ransomware
- JNEC.a is a ransomware that encrypts files and demands a ransom payment for decryption.
- JPIN backdoor
- JPIN is a custom-built backdoor family used by PLATINUM.
- JQJSNICKER
- JQJSNICKER is a malware with limited public information available.
- JSOutProx loaderspyware
- JSOutProx is a sophisticated attack framework built using both Javascript and .NET.
- JSS Loader ratloader
- JSS Loader is Remote Access Trojan (RAT) with .NET and C++ variants that has been used by FIN7 since at least 2020.
- JSSLoader loader
- JSSLoader is a loader-type malware primarily used to distribute additional malicious payloads.
- JUMPALL dropper
- According to FireEye, JUMPALL is a malware dropper that has been observed dropping HIGHNOON/ZXSHELL/SOGU.
- JabaCrypter ransomware
- JabaCrypter is a ransomware that encrypts files on the victim's system and demands a ransom payment for decryption.
- JackPOS trojan
- JackPOS is a type of point-of-sale (POS) malware used to steal credit card information from compromised systems.
- JackPot Ransomware ransomware
- Also known as Jack.Pot Ransomware. This is most likely to affect English speaking users, since the note is written in English.
- Jackal ratspyware
- According to Kaspersky Labs, this malware tool set has been used by APT group GoldenJackal, which has been observed since 2019 and which…
- JadeRAT rat
- JadeRAT is a remote access trojan primarily used for cyber-espionage, targeting governmental and technological sectors.
- Jaff ransomwaredownloader
- We recently observed several large scale email campaigns that were attempting to distribute a new variant of ransomware that has been…
- Jaffe ransomware
- Jaffe is a type of ransomware that encrypts files on affected systems and demands a ransom for decryption.
- Jager Decryptor ransomware
- Jager Decryptor is a ransomware malware variant that encrypts files on the target system, demanding a ransom for the decryption key.
- JagerDecryptor ransomware
- JagerDecryptor is a ransomware variant known for prepending filenames with a unique identifier.
- Jaku botnetcredential-stealer
- Also known as C3PRO-RACOON, EQUINOX, KCNA Infostealer. Jaku is a sophisticated botnet known for targeting specific regions and sectors for espionage purposes.
- James ransomware
- James is a ransomware variant that encrypts files and demands a ransom payment.
- JanelaRAT rat
- According to Zscaler, JanelaRAT is a heavily modified variant of BX RAT.
- Janeleiro trojan
- Janeleiro is a banking trojan primarily targeting financial institutions in Brazil.
- Janicab trojan
- Janicab is an OS X trojan that relied on a valid developer ID and oblivious users to install it.
- Janicab (OS X) spywaretrojan
- According to Patrick Wardle, this malware persists a python script as a cron job.
- Janicab (VBScript) spywaretrojan
- Janicab is a VBScript-based malware family known for its espionage capabilities, including capturing screenshots and stealing sensitive…
- JapanLocker Ransomware ransomware
- Also known as SHC Ransomware, SHCLocker, SyNcryption. This is most likely to affect English speaking users, since the note is written in English.
- JasperLoader loader
- JasperLoader is a malware loader typically distributed via malicious email campaigns.
- Jasus rat
- Jasus is a remote access tool used primarily in espionage campaigns targeting government and technology sectors in Hong Kong and Macau.
- Java NotDharma ransomware
- Java NotDharma is a ransomware variant that encrypts victim files and demands payment for decryption.
- JavaDispCash trojan
- JavaDispCash is a piece of malware designed for ATMs.
- JavaLocker ransomware
- Also known as JavaEncrypt Ransomware. JavaLocker, also known as JavaEncrypt Ransomware, is a ransomware family that encrypts victims' files and demands payment for decryption.
- Javali trojan
- Javali is a banking trojan that has targeted Portuguese and Spanish-speaking countries since 2017, primarily focusing on customers of…
- JeepersCrypt ransomware
- JeepersCrypt is a ransomware known for encrypting files on the victim's system and demanding payment for the decryption key.
- Jeff the Ransomware ransomware
- Looks to be in-development as it does not encrypt.
- Jeiphoos ransomware
- Also known as Encryptor RaaS, Sarento. Ransomware Windows, Linux. Campaign stopped. Actor claimed he deleted the master key.
- JelusRAT rat
- JelusRAT is a remote access trojan known for targeting Southeast Asian regions, particularly Vietnam, Thailand, and Cambodia.
- Jemd ransomware
- Jemd is a ransomware strain known for targeting various sectors including financial services, healthcare, and public sector organizations.
- JenX ddosbotnet
- JenX is a Mirai-based botnet primarily used to perform distributed denial-of-service (DDoS) attacks.
- Jeniva trojan
- Jeniva is a sophisticated trojan malware targeting primarily government and telecommunications sectors.
- Jeno ransomware
- Also known as Jest, Valeria. Jeno, also known as Jest or Valeria, is a ransomware family that encrypts files on infected systems and demands a ransom payment for…
- JessieConTea rattrojan
- JessieConTea is a remote access trojan that uses HTTP(S) for communication.
- JesusCrypt ransomware
- JesusCrypt is a type of ransomware known for encrypting victims' files and demanding payment for decryption.
- Jetriz trojan
- Jetriz is a relatively lesser-known trojan malware family primarily used for targeted cyber espionage campaigns.
- Jfect trojan
- Jfect is a malware family that operates primarily as a trojan.
- Jhon Woddy ransomware
- Ransomware Same codebase as DNRansomware Lock screen password is M3VZ>5BwGGVH
- JhoneRAT rat
- Cisco Talos identified JhoneRAT in January 2020.
- Jigsaw ransomware
- Also known as CryptoHitMan, Jigsaw Original. Jigsaw is a ransomware with a graphical user interface that encrypts the victim's files and demands ransom.
- Jimmy ransomware
- Jimmy is a ransomware known for targeting financial services and government sectors.
- JinxLoader loader
- JinxLoader is a malware variant that primarily functions as a loader, used by threat actors to download additional payloads onto…
- JoJoCrypter ransomware
- JoJoCrypter is a ransomware known for encrypting a victim's files and demanding cryptocurrency payment for recovery.
- Joanap botnetrat
- Joanap is a remote access tool (RAT) commonly associated with North Korean threat actors such as the Lazarus Group.
- Joao botnet
- Joao is a botnet malware that targets Internet of Things (IoT) devices.
- Job Crypter ransomware
- Also known as JobCrypter. Ransomware Based on HiddenTear, but uses TripleDES, decrypter is PoC
- JoeGo ransomware
- JoeGo is a ransomware strain employed by cybercriminals to encrypt victims' data, demanding a ransom payment for decryption.
- JohnBorn ransomware
- JohnBorn is a ransomware that encrypts files on infected systems, demanding a ransom for their decryption.
- JohnyCryptor ransomware
- JohnyCryptor is a ransomware family known for encrypting files on infected machines and demanding a ransom for decryption.
- Joker Korean ransomware
- Joker Korean is a ransomware family known for encrypting files and demanding payment from victims, primarily targeting sectors such as…
- JokerSpy trojanspyware
- JokerSpy is a sophisticated piece of malware targeting Android devices, primarily designed to steal sensitive information such as contact…
- Jokeroo ransomware
- Also known as Fake GandCrab. A new Ransomware-as-a-Service called Jokeroo is being promoted on underground hacking sites and via Twitter that allows affiliates to…
- Jolly Roger ransomware
- Jolly Roger is a ransomware family known for encrypting victim files and demanding a ransom for decryption.
- Jolob backdoor
- Jolob is a backdoor malware typically used by advanced persistent threat groups to conduct cyber-espionage operations.
- JosepCrypt ransomware
- JosepCrypt is a type of ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
- JripBot botnettrojan
- JripBot is a malicious botnet and trojan primarily known for targeting financial services and retail sectors.
- Judge ransomware
- Judge is a type of malware that encrypts files on a victim's system, demanding a ransom for decryption.
- Judy spyware
- Judy is auto-clicking adware that was distributed through multiple apps in the Google Play Store.
- JuicyPotato exploit-kit
- As described on the Github repository page, "A sugared version of RottenPotatoNG, with a bit of juice, i.e.
- JumbledPath spyware
- JumbledPath is a custom-built utility written in GO that has been used by Salt Typhoon since at least 2024 for packet capture on remote…
- JungleSec ransomware
- Uses http://ccrypt.sourceforge.net/ encryption program
- Jupiter rat
- Also known as EarlyRAT. Jupiter, also known as EarlyRAT, is a remote access tool primarily used for cyber espionage.
- Justice_Blade rat
- Justice_Blade is a remote access trojan (RAT) primarily targeting government and defense sectors.
- Juwon ransomware
- Juwon is a type of ransomware that encrypts files on the victim's system and demands a ransom for decryption.
- KANDYKORN trojanrat
- KANDYKORN is a malicious Trojan and Remote Access Trojan (RAT) utilized in cyber-espionage campaigns, targeting governmental and…
- KARAE backdoor
- KARAE is a backdoor typically used by APT37 as first-stage malware.
- KAgent ratbackdoor
- KAgent is a remote access trojan (RAT) used primarily for cyber espionage.
- KCTF Locker ransomware
- KCTF Locker is a type of ransomware that encrypts victims' files, demanding a ransom for decryption.
- KCW ransomware
- KCW is a type of ransomware designed to encrypt files on a victim's system and demand a ransom in exchange for decryption.