Malware Families page 26 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- KDC Sponge rat
- KDC Sponge is a sophisticated remote access tool (RAT) used primarily in cyber-espionage campaigns targeting government and defense sectors.
- KEKW ransomware
- Also known as KEKW-Locker. KEKW is a ransomware family known for encrypting data on infected systems and demanding ransom payments.
- KEYHolder ransomware
- Ransomware via remote attacker. [email protected] contact address
- KEYMARBLE trojanrat
- KEYMARBLE is a Trojan that has reportedly been used by the North Korean government.
- KEYPASS ransomware
- A new distribution campaign is underway for a STOP Ransomware variant called KeyPass based on the amount of victims that have been seen.
- KEYPLUG backdoor
- Also known as KEYPLUG.LINUX, ELFSHELF. KEYPLUG is a modular backdoor written in C++, with Windows and Linux variants, that has been used by APT41 since at least June 2021.
- KGH_SPY backdoorspyware
- KGH_SPY is a modular suite of tools used by Kimsuky for reconnaissance, information stealing, and backdoor capabilities.
- KHRAT ratkeyloggerscreen-capture
- According to Unit42, KHRAT is a Trojan that registers victims using their infected machine’s username, system language and local IP address.
- KINS trojancredential-stealer
- Also known as Kasper Internet Non-Security, Maple. KINS, also known as Kasper Internet Non-Security or Maple, is a banking Trojan that primarily targets financial institutions.
- KIVARS (ELF) backdoorrat
- KIVARS (ELF) is a remote access tool (RAT) primarily used in cyber espionage operations.
- KIVARS (Windows) rat
- KIVARS is a Remote Access Trojan (RAT) commonly used in cyber espionage campaigns.
- KKK ransomware
- KKK is a ransomware malware that encrypts files on infected systems, demanding a ransom for decryption.
- KLRD ransomware
- KLRD is a ransomware family that targets government, financial, and technology sectors.
- KLogEXE keylogger
- KLogEXE is a type of keylogger malware designed to covertly capture and log keystrokes made by a user.
- KOCTOPUS loaderrat
- KOCTOPUS's batch variant is loader used by LazyScripter since 2018 to launch Octopus and Koadic and, in some cases, QuasarRAT.
- KOMPROGO ratbackdoor
- Also known as Splinter RAT. KOMPROGO is a signature backdoor used by APT32 that is capable of process, file, and registry management.
- KONNI rat
- KONNI is a remote access tool that security researchers assess has been used by North Korean cyber actors since at least 2014.
- KOPILUWAK spyware
- KOPILUWAK is a JavaScript-based reconnaissance tool that has been used for victim profiling and C2 since at least 2017.
- KPOT Stealer trojancredential-stealer
- Also known as Khalesi, Kpot. KPOT is an information-stealing Trojan horse that can steal information from infected computers.
- KRNRAT backdoorratrootkit
- According to Trend Micro, this is a rootkit with capabilities of a full-featured backdoor with various capabilities, including process…
- KRider Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- KSL0T keylogger
- KSL0T is a keylogger malware associated with the Turla group, used primarily for espionage purposes against government and defense sectors.
- KSREMOTE rat
- KSREMOTE is a sophisticated remote access trojan (RAT) used primarily for cyber espionage activities targeting government and financial…
- KTLVdoor (ELF) backdoor
- According to Trend Micro, KTLVdoor is a highly obfuscated malware that masquerades as different system utilities, allowing attackers to…
- KTLVdoor (Windows) backdoortrojan
- According to Trend Micro, KTLVdoor is a highly obfuscated malware that masquerades as different system utilities, allowing attackers to…
- KV
- KV is a largely undocumented piece of malware with little publicly available information regarding its capabilities or targets.
- Kaandsona Ransomware ransomware
- Also known as RansomTroll Ransomware, Käändsõna Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- KadNap botnet
- According to Black Lotus Labs, KadNap primarily targets Asus routers, conscripting them into a botnet that proxies malicious traffic.
- Kaden botnetddoswiper
- Kaden is a DDoS botnet that is heavily based on Bashlite/Gafgyt.
- Kaenlupuf Ransomware ransomware
- About: This is most likely to affect English speaking users, since the note is written in English.
- KageNoHitobito rat
- KageNoHitobito is a Remote Access Trojan (RAT) known for its use in cyber espionage campaigns.
- Kaiji ddos
- Surfaced in late April 2020, Intezer describes Kaiji as a DDoS malware written in Go that spreads through SSH brute force attacks.
- Kaiten backdoortrojan
- Also known as STD. According to netenrich, Kaiten is a Trojan horse that opens a back door on the compromised computer that allows it to perform other…
- Kalambur downloadertrojan
- According to EclecticIQ, Kalambur is designed to gather local system information, then download a repackaged TOR binary inside a ZIP file…
- Kali ransomware
- Kali ransomware is a malicious software that encrypts files on a victim's device, demanding a ransom for decryption.
- Kali365
- Kali365 is a Phishing-as-a-Service (PHaaS) kit first observed in April 2026 that generates victim-targeted lures across multiple operating…
- Kamasers botnetbackdoorddos
- Kamasers is a DDOS botnet. The bot has backdoor capabilities as it connects to an attacker controller C2 server. This allows it to…
- KamiKakaBot botnetcredential-stealer
- Also known as Kami. A Telegram bot with browser stealing capabilities, written using the .NET framework.
- Kamil ransomware
- Kamil is a ransomware known for encrypting files on infected systems, demanding a ransom for decryption.
- Kampret ransomware
- Kampret is a ransomware malware known for encrypting files on compromised systems and demanding a ransom for decryption.
- Kangaroo Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Kaolin RAT rat
- Also known as KaolinTea. Kaolin RAT is a complex modular RAT, with Release_TMain_x64.dll as its internal DLL name.
- Kapeka backdoor
- Also known as KnuckleTouch, ICYWELL, KNUCKLETOUCH. Kapeka is a backdoor written in C++ used against victims in Eastern Europe since at least mid-2022.
- Kappa trojanloader
- Kappa is a malware made using the OXAR builder known for its decryptable payloads.
- Karagany backdoorrat
- Also known as Karagny. Karagany is a remote access trojan (RAT) known for its capabilities to provide backdoor access.
- Karakurt ransomware
- Karakurt is a ransomware group known for targeting various industries, including healthcare and financial services.
- Kardon Loader downloaderloadercredential-stealer
- According to ASERT, Kardon Loader is a fully featured downloader, enabling the download and installation of other malware, eg.
- Karius trojan
- According to checkpoint, Karius is a banking trojan in development, borrowing code from Ramnit, Vawtrack as well as Trickbot, currently…
- Karkoff dropperspyware
- Also known as CACTUSPIPE, MailDropper, OILYFACE. Karkoff, also known by its aliases CACTUSPIPE, MailDropper, and OILYFACE, is a malware family typically used in cyber-espionage campaigns.
- Karma Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Karmen Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Karo ransomware
- Karo is a ransomware that encrypts files on the victim's system, demanding a ransom payment for the decryption key.
- KarstoRAT rat
- KarstoRAT is a remote access trojan used in cyber espionage campaigns.
- Kasidet backdoor
- Kasidet is a backdoor that has been dropped by using malicious VBA macros.
- Kasiski Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- KasperAgent backdoordownloader
- KasperAgent is a malware family known for cyber-espionage, primarily targeting the government and public sector.
- Katafrank ransomware
- Katafrank is a ransomware variant known for encrypting user data and demanding a ransom for decryption.
- Katyusha ransomware
- Katyusha is a ransomware strain known to encrypt files on victim systems, demanding a ransom for decryption keys.
- Katz Stealer credential-stealerkeylogger
- Katz Stealer is a credential-stealing malware designed to extract sensitive information such as usernames and passwords from infected…
- KawaiiLocker ransomware
- KawaiiLocker is a type of ransomware designed to encrypt files on infected systems, demanding a ransom payment for decryption.
- Kazuar backdoortrojan
- Kazuar is a fully featured, multi-platform backdoor Trojan written using the Microsoft .NET framework.
- KazyLoader loader
- According to Karsten Hahn, a straightforward loader that runs assemblies from images.
- Kazybot botnetcredential-stealer
- Kazybot is a type of malware that primarily functions as a botnet and credential-stealer, often used by cybercriminals to exfiltrate…
- KeRanger ransomware
- KeRanger is an OS X ransomware that encrypts files on macOS systems and demands a ransom for decryption.
- Kee ransomware
- Kee is a form of ransomware that encrypts files on an infected system, demanding a ransom payment for decryption.
- Kegotip trojan
- Kegotip is a trojan malware family known for targeting the financial sector and government entities to exfiltrate sensitive data.
- Kelihos botnetcredential-stealerddos
- Kelihos is a botnet known for sending spam emails, stealing sensitive information, and participating in distributed denial-of-service…
- Kelvin Security
- Kelvin Security is a cybercrime group active since at least 2013, primarily known for hacktivism, data breaches, and website defacements…
- Kematian Stealer credential-stealer
- Stealer written in Python, available as open source on Github.
- Keona ransomware
- Keona is a ransomware family that encrypts files on affected systems, demanding payment for decryption.
- Kerkoporta ransomware
- Kerkoporta is a type of ransomware designed to encrypt the files of its victims, demanding payment for decryption.
- Kerrdown downloaderspyware
- Kerrdown is a custom downloader that has been used by APT32 since at least 2018 to install spyware from a server on the victim's network.
- Kessel backdoorbotnetcredential-stealer
- Kessel is an advanced version of OpenSSH which acts as a custom backdoor, mainly acting to steal credentials and function as a bot.
- Ketrican backdoortrojan
- Ketrican is a sophisticated backdoor trojan attributed to the cyber-espionage group APT 15.
- Ketrum rat
- Intezer found this family mid May 2020, which appears to be a merger of the family Ketrican and Okrum.
- KevDroid rat
- KevDroid is a Remote Access Trojan (RAT) primarily targeting Android devices, known to collect sensitive information.
- Kevin backdoor
- Kevin is a backdoor implant written in C++ that has been used by HEXANE since at least June 2020, including in operations against…
- KeyBTC ransomware
- KeyBTC is a ransomware that encrypts files on the victim's system and demands payment in Bitcoin for the decryption key.
- KeyBase credential-stealerkeylogger
- Also known as Kibex. KeyBase is a .NET credential stealer and keylogger that first emerged in February 2015.
- KeyBoy backdoor
- Also known as TSSL. KeyBoy is malware that has been used in targeted campaigns against members of the Tibetan Parliament in 2016.
- KeyMaker ransomware
- KeyMaker is a ransomware family known for encrypting files on infected systems and demanding payment for the decryption key.
- KeyPlexer keylogger
- KeyPlexer is a malware family known for its keylogging capabilities.
- KeyRaider credential-stealerransomware
- KeyRaider is malware that steals Apple account credentials and other data from jailbroken iOS devices.
- KeySteal credential-stealer
- According to SentinelOne, KeySteal targets files with the .keychain and keychain-db file extensions in the following locations.
- Keydnap backdoorcredential-stealer
- Also known as OSX/Keydnap. This piece of malware steals the content of the user's keychain while maintaining a permanent backdoor.
- Keyhole backdoorrat
- According to Walmart Global Tech, Keyhole is a multi-functional VNC/Backconnect component used extensively by IcedID/Anubis.
- Khonsari ransomware
- A compact ransomware written in .NET and delivered as follow-up to Log4J exploitation, targeting Windows servers.
- Kikothac trojanransomware
- Kikothac is a sophisticated malware family primarily targeting the financial and government sectors.
- Kiler RAT ratcredential-stealerworm
- Also known as Njw0rm. This remote access trojan (RAT) has capabilities ranging from manipulating the registry to opening a reverse shell.
- KillAV wiper
- Also known as BURNTCIGAR. KillAV, also known as BURNTCIGAR, is a malware family designed to disable antivirus programs on infected systems.
- KillBot_Virus ransomware
- KillBot_Virus is a ransomware malware family that encrypts files on infected systems and demands a ransom payment for decryption.
- KillDisk wiperransomware
- Also known as Win32/KillDisk.NBI, Win32/KillDisk.NBH, Win32/KillDisk.NBD. KillDisk is a disk-wiping tool designed to overwrite files with random data to render the OS unbootable.
- KillDisk (Lazarus) wiper
- Also known as KillDisk.NBO. KillDisk is a destructive malware used by the Lazarus Group, known for its disk wiping capabilities.
- KillDisk Ransomware ransomwarewiper
- It’s directed to English speaking users, therefore is able to infect worldwide.
- KillDisk-Dimens ransomwarewiper
- KillDisk-Dimens is a destructive ransomware variant known for its capability to wipe data and demand ransom from various sectors.
- KillRabbit ransomware
- KillRabbit is a sophisticated ransomware strain known for encrypting victim files and demanding ransom payments in cryptocurrency.
- KillSwitch ransomware
- KillSwitch is a ransomware family known for encrypting files and demanding payment for decryption keys.
- Killdisk
- In 2015 the BlackEnergy malware contained a component called KillDisk.
- Killer RAT rat
- Killer RAT is a remote access trojan used by cybercriminals to gain unauthorized access and control over targeted systems.
- KillerLocker ransomware
- KillerLocker is a type of ransomware that encrypts user files and demands a ransom for decryption.