Malware Families page 26 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

KDC Sponge rat
KDC Sponge is a sophisticated remote access tool (RAT) used primarily in cyber-espionage campaigns targeting government and defense sectors.
KEKW ransomware
Also known as KEKW-Locker. KEKW is a ransomware family known for encrypting data on infected systems and demanding ransom payments.
KEYHolder ransomware
Ransomware via remote attacker. [email protected] contact address
KEYMARBLE trojanrat
KEYMARBLE is a Trojan that has reportedly been used by the North Korean government.
KEYPASS ransomware
A new distribution campaign is underway for a STOP Ransomware variant called KeyPass based on the amount of victims that have been seen.
KEYPLUG backdoor
Also known as KEYPLUG.LINUX, ELFSHELF. KEYPLUG is a modular backdoor written in C++, with Windows and Linux variants, that has been used by APT41 since at least June 2021.
KGH_SPY backdoorspyware
KGH_SPY is a modular suite of tools used by Kimsuky for reconnaissance, information stealing, and backdoor capabilities.
KHRAT ratkeyloggerscreen-capture
According to Unit42, KHRAT is a Trojan that registers victims using their infected machine’s username, system language and local IP address.
KINS trojancredential-stealer
Also known as Kasper Internet Non-Security, Maple. KINS, also known as Kasper Internet Non-Security or Maple, is a banking Trojan that primarily targets financial institutions.
KIVARS (ELF) backdoorrat
KIVARS (ELF) is a remote access tool (RAT) primarily used in cyber espionage operations.
KIVARS (Windows) rat
KIVARS is a Remote Access Trojan (RAT) commonly used in cyber espionage campaigns.
KKK ransomware
KKK is a ransomware malware that encrypts files on infected systems, demanding a ransom for decryption.
KLRD ransomware
KLRD is a ransomware family that targets government, financial, and technology sectors.
KLogEXE keylogger
KLogEXE is a type of keylogger malware designed to covertly capture and log keystrokes made by a user.
KOCTOPUS loaderrat
KOCTOPUS's batch variant is loader used by LazyScripter since 2018 to launch Octopus and Koadic and, in some cases, QuasarRAT.
KOMPROGO ratbackdoor
Also known as Splinter RAT. KOMPROGO is a signature backdoor used by APT32 that is capable of process, file, and registry management.
KONNI rat
KONNI is a remote access tool that security researchers assess has been used by North Korean cyber actors since at least 2014.
KOPILUWAK spyware
KOPILUWAK is a JavaScript-based reconnaissance tool that has been used for victim profiling and C2 since at least 2017.
KPOT Stealer trojancredential-stealer
Also known as Khalesi, Kpot. KPOT is an information-stealing Trojan horse that can steal information from infected computers.
KRNRAT backdoorratrootkit
According to Trend Micro, this is a rootkit with capabilities of a full-featured backdoor with various capabilities, including process…
KRider Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
KSL0T keylogger
KSL0T is a keylogger malware associated with the Turla group, used primarily for espionage purposes against government and defense sectors.
KSREMOTE rat
KSREMOTE is a sophisticated remote access trojan (RAT) used primarily for cyber espionage activities targeting government and financial…
KTLVdoor (ELF) backdoor
According to Trend Micro, KTLVdoor is a highly obfuscated malware that masquerades as different system utilities, allowing attackers to…
KTLVdoor (Windows) backdoortrojan
According to Trend Micro, KTLVdoor is a highly obfuscated malware that masquerades as different system utilities, allowing attackers to…
KV
KV is a largely undocumented piece of malware with little publicly available information regarding its capabilities or targets.
Kaandsona Ransomware ransomware
Also known as RansomTroll Ransomware, Käändsõna Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
KadNap botnet
According to Black Lotus Labs, KadNap primarily targets Asus routers, conscripting them into a botnet that proxies malicious traffic.
Kaden botnetddoswiper
Kaden is a DDoS botnet that is heavily based on Bashlite/Gafgyt.
Kaenlupuf Ransomware ransomware
About: This is most likely to affect English speaking users, since the note is written in English.
KageNoHitobito rat
KageNoHitobito is a Remote Access Trojan (RAT) known for its use in cyber espionage campaigns.
Kaiji ddos
Surfaced in late April 2020, Intezer describes Kaiji as a DDoS malware written in Go that spreads through SSH brute force attacks.
Kaiten backdoortrojan
Also known as STD. According to netenrich, Kaiten is a Trojan horse that opens a back door on the compromised computer that allows it to perform other…
Kalambur downloadertrojan
According to EclecticIQ, Kalambur is designed to gather local system information, then download a repackaged TOR binary inside a ZIP file…
Kali ransomware
Kali ransomware is a malicious software that encrypts files on a victim's device, demanding a ransom for decryption.
Kali365
Kali365 is a Phishing-as-a-Service (PHaaS) kit first observed in April 2026 that generates victim-targeted lures across multiple operating…
Kamasers botnetbackdoorddos
Kamasers is a DDOS botnet. The bot has backdoor capabilities as it connects to an attacker controller C2 server. This allows it to…
KamiKakaBot botnetcredential-stealer
Also known as Kami. A Telegram bot with browser stealing capabilities, written using the .NET framework.
Kamil ransomware
Kamil is a ransomware known for encrypting files on infected systems, demanding a ransom for decryption.
Kampret ransomware
Kampret is a ransomware malware known for encrypting files on compromised systems and demanding a ransom for decryption.
Kangaroo Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Kaolin RAT rat
Also known as KaolinTea. Kaolin RAT is a complex modular RAT, with Release_TMain_x64.dll as its internal DLL name.
Kapeka backdoor
Also known as KnuckleTouch, ICYWELL, KNUCKLETOUCH. Kapeka is a backdoor written in C++ used against victims in Eastern Europe since at least mid-2022.
Kappa trojanloader
Kappa is a malware made using the OXAR builder known for its decryptable payloads.
Karagany backdoorrat
Also known as Karagny. Karagany is a remote access trojan (RAT) known for its capabilities to provide backdoor access.
Karakurt ransomware
Karakurt is a ransomware group known for targeting various industries, including healthcare and financial services.
Kardon Loader downloaderloadercredential-stealer
According to ASERT, Kardon Loader is a fully featured downloader, enabling the download and installation of other malware, eg.
Karius trojan
According to checkpoint, Karius is a banking trojan in development, borrowing code from Ramnit, Vawtrack as well as Trickbot, currently…
Karkoff dropperspyware
Also known as CACTUSPIPE, MailDropper, OILYFACE. Karkoff, also known by its aliases CACTUSPIPE, MailDropper, and OILYFACE, is a malware family typically used in cyber-espionage campaigns.
Karma Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Karmen Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Karo ransomware
Karo is a ransomware that encrypts files on the victim's system, demanding a ransom payment for the decryption key.
KarstoRAT rat
KarstoRAT is a remote access trojan used in cyber espionage campaigns.
Kasidet backdoor
Kasidet is a backdoor that has been dropped by using malicious VBA macros.
Kasiski Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
KasperAgent backdoordownloader
KasperAgent is a malware family known for cyber-espionage, primarily targeting the government and public sector.
Katafrank ransomware
Katafrank is a ransomware variant known for encrypting user data and demanding a ransom for decryption.
Katyusha ransomware
Katyusha is a ransomware strain known to encrypt files on victim systems, demanding a ransom for decryption keys.
Katz Stealer credential-stealerkeylogger
Katz Stealer is a credential-stealing malware designed to extract sensitive information such as usernames and passwords from infected…
KawaiiLocker ransomware
KawaiiLocker is a type of ransomware designed to encrypt files on infected systems, demanding a ransom payment for decryption.
Kazuar backdoortrojan
Kazuar is a fully featured, multi-platform backdoor Trojan written using the Microsoft .NET framework.
KazyLoader loader
According to Karsten Hahn, a straightforward loader that runs assemblies from images.
Kazybot botnetcredential-stealer
Kazybot is a type of malware that primarily functions as a botnet and credential-stealer, often used by cybercriminals to exfiltrate…
KeRanger ransomware
KeRanger is an OS X ransomware that encrypts files on macOS systems and demands a ransom for decryption.
Kee ransomware
Kee is a form of ransomware that encrypts files on an infected system, demanding a ransom payment for decryption.
Kegotip trojan
Kegotip is a trojan malware family known for targeting the financial sector and government entities to exfiltrate sensitive data.
Kelihos botnetcredential-stealerddos
Kelihos is a botnet known for sending spam emails, stealing sensitive information, and participating in distributed denial-of-service…
Kelvin Security
Kelvin Security is a cybercrime group active since at least 2013, primarily known for hacktivism, data breaches, and website defacements…
Kematian Stealer credential-stealer
Stealer written in Python, available as open source on Github.
Keona ransomware
Keona is a ransomware family that encrypts files on affected systems, demanding payment for decryption.
Kerkoporta ransomware
Kerkoporta is a type of ransomware designed to encrypt the files of its victims, demanding payment for decryption.
Kerrdown downloaderspyware
Kerrdown is a custom downloader that has been used by APT32 since at least 2018 to install spyware from a server on the victim's network.
Kessel backdoorbotnetcredential-stealer
Kessel is an advanced version of OpenSSH which acts as a custom backdoor, mainly acting to steal credentials and function as a bot.
Ketrican backdoortrojan
Ketrican is a sophisticated backdoor trojan attributed to the cyber-espionage group APT 15.
Ketrum rat
Intezer found this family mid May 2020, which appears to be a merger of the family Ketrican and Okrum.
KevDroid rat
KevDroid is a Remote Access Trojan (RAT) primarily targeting Android devices, known to collect sensitive information.
Kevin backdoor
Kevin is a backdoor implant written in C++ that has been used by HEXANE since at least June 2020, including in operations against…
KeyBTC ransomware
KeyBTC is a ransomware that encrypts files on the victim's system and demands payment in Bitcoin for the decryption key.
KeyBase credential-stealerkeylogger
Also known as Kibex. KeyBase is a .NET credential stealer and keylogger that first emerged in February 2015.
KeyBoy backdoor
Also known as TSSL. KeyBoy is malware that has been used in targeted campaigns against members of the Tibetan Parliament in 2016.
KeyMaker ransomware
KeyMaker is a ransomware family known for encrypting files on infected systems and demanding payment for the decryption key.
KeyPlexer keylogger
KeyPlexer is a malware family known for its keylogging capabilities.
KeyRaider credential-stealerransomware
KeyRaider is malware that steals Apple account credentials and other data from jailbroken iOS devices.
KeySteal credential-stealer
According to SentinelOne, KeySteal targets files with the .keychain and keychain-db file extensions in the following locations.
Keydnap backdoorcredential-stealer
Also known as OSX/Keydnap. This piece of malware steals the content of the user's keychain while maintaining a permanent backdoor.
Keyhole backdoorrat
According to Walmart Global Tech, Keyhole is a multi-functional VNC/Backconnect component used extensively by IcedID/Anubis.
Khonsari ransomware
A compact ransomware written in .NET and delivered as follow-up to Log4J exploitation, targeting Windows servers.
Kikothac trojanransomware
Kikothac is a sophisticated malware family primarily targeting the financial and government sectors.
Kiler RAT ratcredential-stealerworm
Also known as Njw0rm. This remote access trojan (RAT) has capabilities ranging from manipulating the registry to opening a reverse shell.
KillAV wiper
Also known as BURNTCIGAR. KillAV, also known as BURNTCIGAR, is a malware family designed to disable antivirus programs on infected systems.
KillBot_Virus ransomware
KillBot_Virus is a ransomware malware family that encrypts files on infected systems and demands a ransom payment for decryption.
KillDisk wiperransomware
Also known as Win32/KillDisk.NBI, Win32/KillDisk.NBH, Win32/KillDisk.NBD. KillDisk is a disk-wiping tool designed to overwrite files with random data to render the OS unbootable.
KillDisk (Lazarus) wiper
Also known as KillDisk.NBO. KillDisk is a destructive malware used by the Lazarus Group, known for its disk wiping capabilities.
KillDisk Ransomware ransomwarewiper
It’s directed to English speaking users, therefore is able to infect worldwide.
KillDisk-Dimens ransomwarewiper
KillDisk-Dimens is a destructive ransomware variant known for its capability to wipe data and demand ransom from various sectors.
KillRabbit ransomware
KillRabbit is a sophisticated ransomware strain known for encrypting victim files and demanding ransom payments in cryptocurrency.
KillSwitch ransomware
KillSwitch is a ransomware family known for encrypting files and demanding payment for decryption keys.
Killdisk
In 2015 the BlackEnergy malware contained a component called KillDisk.
Killer RAT rat
Killer RAT is a remote access trojan used by cybercriminals to gain unauthorized access and control over targeted systems.
KillerLocker ransomware
KillerLocker is a type of ransomware that encrypts user files and demands a ransom for decryption.