Malware Families page 25 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

International Police Association ransomware
International Police Association is a variant of the CryptoTorLocker2015 ransomware, known for encrypting files and demanding ransom…
Invicta Stealer credential-stealerspyware
According to Cyble, The Invicta Stealer can collect system information, system hardware details, wallet data, and browser data and extract…
InvisiMole spywarebackdoor
InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013.
InvisibleFerret ratdropper
InvisibleFerret is a modular python malware that is leveraged for data exfiltration and remote access capabilities.
Invoke-PSImage credential-stealertrojan
Invoke-PSImage takes a PowerShell script and embeds the bytes of the script into the pixels of a PNG image.
IoT Reaper botnetddosworm
Also known as IoTroop, Reaper, iotreaper. IoT Reaper, also known as IoTroop or Reaper, is a botnet malware that targets IoT devices.
Iperius Remote rat
Iperius Remote is advertised with these features: Control remotely any computer with Iperius Remote Desktop Free.
Irc16 botnet
Irc16 is a malware family known for using IRC (Internet Relay Chat) to control a network of infected machines, forming a botnet.
Iron ransomware
It is currently unknown if Iron is indeed a new variant by the same creators of Maktub, or if it was simply inspired by the latter, by…
IronNetInjector dropperloaderrat
IronNetInjector is a Turla toolchain that utilizes scripts from the open-source IronPython implementation of Python with a .NET injector…
IronWind loader
IronWind is a custom loader malware that has been in use since at least 2023 by actors including WIRTE to target entities in the Middle…
IronZero trojanspyware
IronZero is an advanced spyware and trojan malware believed to target government and defense sectors.
Ironcat ransomware
Ironcat is a ransomware family known for encrypting victim files and demanding ransom payments, primarily targeting sectors such as…
IsSpace rat
Also known as NfLog RAT. IsSpace, also known as NfLog RAT, is a remote access trojan used primarily for cyber espionage.
IsaacWiper wiper
Also known as LASAINRAW. According to Recorded Future, IsaacWiper is a destructive malware that overwrites all physical disks and logical volumes on a victim’s…
Ishtar Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
IsraBye wiper
IsraBye is a malicious wiper malware that predominantly targets computer systems in the Middle East.
Ixeshe backdoorrat
Ixeshe is a malware family that has been used since at least 2009 against targets in East Asia.
J- ransomware
J- is a ransomware that encrypts victims' files and demands a ransom for decryption.
J-magic backdoor
J-magic is a custom variant of the cd00r backdoor tailored to target Juniper routers that was first observed during the J-magic Campaign…
JADESNOW downloaderbackdoor
Also known as ChainedDown. JADESNOW is a JavaScript-based downloader malware family associated with the threat cluster UNC5342.
JCage rat
JCage is a remote access trojan used for espionage activities, primarily targeting governmental and telecommunications sectors in South…
JCry ransomware
JCry is ransomware written in Go. It was identified as apart of the #OpJerusalem 2019 campaign.
JCrypt ransomware
Also known as RIP lmao, Locked, Daddycrypt. Ransomware written in C#. Fortunately, all current versions of the MafiaWare666 ransomware are decryptable. The Threat Lab from Avast has…
JHUHUGIT downloader
Also known as Trojan.Sofacy, Seduploader, JKEYSKW. JHUHUGIT is malware used by APT28. It is based on Carberp source code and serves as reconnaissance malware.
JLORAT rat
JLORAT is a Remote Access Trojan (RAT) used primarily for cyber espionage.
JNEC.a ransomware
JNEC.a is a ransomware that encrypts files and demands a ransom payment for decryption.
JPIN backdoor
JPIN is a custom-built backdoor family used by PLATINUM.
JQJSNICKER
JQJSNICKER is a malware with limited public information available.
JSOutProx loaderspyware
JSOutProx is a sophisticated attack framework built using both Javascript and .NET.
JSS Loader ratloader
JSS Loader is Remote Access Trojan (RAT) with .NET and C++ variants that has been used by FIN7 since at least 2020.
JSSLoader loader
JSSLoader is a loader-type malware primarily used to distribute additional malicious payloads.
JUMPALL dropper
According to FireEye, JUMPALL is a malware dropper that has been observed dropping HIGHNOON/ZXSHELL/SOGU.
JabaCrypter ransomware
JabaCrypter is a ransomware that encrypts files on the victim's system and demands a ransom payment for decryption.
JackPOS trojan
JackPOS is a type of point-of-sale (POS) malware used to steal credit card information from compromised systems.
JackPot Ransomware ransomware
Also known as Jack.Pot Ransomware. This is most likely to affect English speaking users, since the note is written in English.
Jackal ratspyware
According to Kaspersky Labs, this malware tool set has been used by APT group GoldenJackal, which has been observed since 2019 and which…
JadeRAT rat
JadeRAT is a remote access trojan primarily used for cyber-espionage, targeting governmental and technological sectors.
Jaff ransomwaredownloader
We recently observed several large scale email campaigns that were attempting to distribute a new variant of ransomware that has been…
Jaffe ransomware
Jaffe is a type of ransomware that encrypts files on affected systems and demands a ransom for decryption.
Jager Decryptor ransomware
Jager Decryptor is a ransomware malware variant that encrypts files on the target system, demanding a ransom for the decryption key.
JagerDecryptor ransomware
JagerDecryptor is a ransomware variant known for prepending filenames with a unique identifier.
Jaku botnetcredential-stealer
Also known as C3PRO-RACOON, EQUINOX, KCNA Infostealer. Jaku is a sophisticated botnet known for targeting specific regions and sectors for espionage purposes.
James ransomware
James is a ransomware variant that encrypts files and demands a ransom payment.
JanelaRAT rat
According to Zscaler, JanelaRAT is a heavily modified variant of BX RAT.
Janeleiro trojan
Janeleiro is a banking trojan primarily targeting financial institutions in Brazil.
Janicab trojan
Janicab is an OS X trojan that relied on a valid developer ID and oblivious users to install it.
Janicab (OS X) spywaretrojan
According to Patrick Wardle, this malware persists a python script as a cron job.
Janicab (VBScript) spywaretrojan
Janicab is a VBScript-based malware family known for its espionage capabilities, including capturing screenshots and stealing sensitive…
JapanLocker Ransomware ransomware
Also known as SHC Ransomware, SHCLocker, SyNcryption. This is most likely to affect English speaking users, since the note is written in English.
JasperLoader loader
JasperLoader is a malware loader typically distributed via malicious email campaigns.
Jasus rat
Jasus is a remote access tool used primarily in espionage campaigns targeting government and technology sectors in Hong Kong and Macau.
Java NotDharma ransomware
Java NotDharma is a ransomware variant that encrypts victim files and demands payment for decryption.
JavaDispCash trojan
JavaDispCash is a piece of malware designed for ATMs.
JavaLocker ransomware
Also known as JavaEncrypt Ransomware. JavaLocker, also known as JavaEncrypt Ransomware, is a ransomware family that encrypts victims' files and demands payment for decryption.
Javali trojan
Javali is a banking trojan that has targeted Portuguese and Spanish-speaking countries since 2017, primarily focusing on customers of…
JeepersCrypt ransomware
JeepersCrypt is a ransomware known for encrypting files on the victim's system and demanding payment for the decryption key.
Jeff the Ransomware ransomware
Looks to be in-development as it does not encrypt.
Jeiphoos ransomware
Also known as Encryptor RaaS, Sarento. Ransomware Windows, Linux. Campaign stopped. Actor claimed he deleted the master key.
JelusRAT rat
JelusRAT is a remote access trojan known for targeting Southeast Asian regions, particularly Vietnam, Thailand, and Cambodia.
Jemd ransomware
Jemd is a ransomware strain known for targeting various sectors including financial services, healthcare, and public sector organizations.
JenX ddosbotnet
JenX is a Mirai-based botnet primarily used to perform distributed denial-of-service (DDoS) attacks.
Jeniva trojan
Jeniva is a sophisticated trojan malware targeting primarily government and telecommunications sectors.
Jeno ransomware
Also known as Jest, Valeria. Jeno, also known as Jest or Valeria, is a ransomware family that encrypts files on infected systems and demands a ransom payment for…
JessieConTea rattrojan
JessieConTea is a remote access trojan that uses HTTP(S) for communication.
JesusCrypt ransomware
JesusCrypt is a type of ransomware known for encrypting victims' files and demanding payment for decryption.
Jetriz trojan
Jetriz is a relatively lesser-known trojan malware family primarily used for targeted cyber espionage campaigns.
Jfect trojan
Jfect is a malware family that operates primarily as a trojan.
Jhon Woddy ransomware
Ransomware Same codebase as DNRansomware Lock screen password is M3VZ>5BwGGVH
JhoneRAT rat
Cisco Talos identified JhoneRAT in January 2020.
Jigsaw ransomware
Also known as CryptoHitMan, Jigsaw Original. Jigsaw is a ransomware with a graphical user interface that encrypts the victim's files and demands ransom.
Jimmy ransomware
Jimmy is a ransomware known for targeting financial services and government sectors.
JinxLoader loader
JinxLoader is a malware variant that primarily functions as a loader, used by threat actors to download additional payloads onto…
JoJoCrypter ransomware
JoJoCrypter is a ransomware known for encrypting a victim's files and demanding cryptocurrency payment for recovery.
Joanap botnetrat
Joanap is a remote access tool (RAT) commonly associated with North Korean threat actors such as the Lazarus Group.
Joao botnet
Joao is a botnet malware that targets Internet of Things (IoT) devices.
Job Crypter ransomware
Also known as JobCrypter. Ransomware Based on HiddenTear, but uses TripleDES, decrypter is PoC
JoeGo ransomware
JoeGo is a ransomware strain employed by cybercriminals to encrypt victims' data, demanding a ransom payment for decryption.
JohnBorn ransomware
JohnBorn is a ransomware that encrypts files on infected systems, demanding a ransom for their decryption.
JohnyCryptor ransomware
JohnyCryptor is a ransomware family known for encrypting files on infected machines and demanding a ransom for decryption.
Joker Korean ransomware
Joker Korean is a ransomware family known for encrypting files and demanding payment from victims, primarily targeting sectors such as…
JokerSpy trojanspyware
JokerSpy is a sophisticated piece of malware targeting Android devices, primarily designed to steal sensitive information such as contact…
Jokeroo ransomware
Also known as Fake GandCrab. A new Ransomware-as-a-Service called Jokeroo is being promoted on underground hacking sites and via Twitter that allows affiliates to…
Jolly Roger ransomware
Jolly Roger is a ransomware family known for encrypting victim files and demanding a ransom for decryption.
Jolob backdoor
Jolob is a backdoor malware typically used by advanced persistent threat groups to conduct cyber-espionage operations.
JosepCrypt ransomware
JosepCrypt is a type of ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
JripBot botnettrojan
JripBot is a malicious botnet and trojan primarily known for targeting financial services and retail sectors.
Judge ransomware
Judge is a type of malware that encrypts files on a victim's system, demanding a ransom for decryption.
Judy spyware
Judy is auto-clicking adware that was distributed through multiple apps in the Google Play Store.
JuicyPotato exploit-kit
As described on the Github repository page, "A sugared version of RottenPotatoNG, with a bit of juice, i.e.
JumbledPath spyware
JumbledPath is a custom-built utility written in GO that has been used by Salt Typhoon since at least 2024 for packet capture on remote…
JungleSec ransomware
Uses http://ccrypt.sourceforge.net/ encryption program
Jupiter rat
Also known as EarlyRAT. Jupiter, also known as EarlyRAT, is a remote access tool primarily used for cyber espionage.
Justice_Blade rat
Justice_Blade is a remote access trojan (RAT) primarily targeting government and defense sectors.
Juwon ransomware
Juwon is a type of ransomware that encrypts files on the victim's system and demands a ransom for decryption.
KANDYKORN trojanrat
KANDYKORN is a malicious Trojan and Remote Access Trojan (RAT) utilized in cyber-espionage campaigns, targeting governmental and…
KARAE backdoor
KARAE is a backdoor typically used by APT37 as first-stage malware.
KAgent ratbackdoor
KAgent is a remote access trojan (RAT) used primarily for cyber espionage.
KCTF Locker ransomware
KCTF Locker is a type of ransomware that encrypts victims' files, demanding a ransom for decryption.
KCW ransomware
KCW is a type of ransomware designed to encrypt files on a victim's system and demand a ransom in exchange for decryption.