Malware Families page 27 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- KilllSomeOne
- KimJongRat rat
- KimJongRat is a remote access trojan associated with cyber-espionage campaigns linked to North Korean threat actors.
- KimcilWare ransomware
- KimcilWare is a ransomware that primarily targets websites, encrypting their files and demanding a ransom for decryption.
- Kimsuky spywarebackdoor
- Kimsuky is a cyber espionage group known to target South Korean entities, particularly in the government and media sectors.
- Kimwolf botnetddos
- KIMWOLF is an android based malware which uses compromised systems to relay malicious and abusive Internet traffic, as well as…
- Kindest ransomware
- ransomware
- KingOuroboros ransomware
- This crypto-extortioner encrypts user data using AES, and then requires a $ 30- $ 50- $ 80 buy- back to BTC to return the files.
- Kingminer botnetcryptominerddos
- According to Sophis, the botnet has been active since 2018, initially, the botmasters operated DDoS tools and backdoors, but later moved…
- Kinsing cryptominerworm
- Also known as h2miner. Kinsing is Golang-based malware that runs a cryptocurrency miner and attempts to spread itself to other hosts in the victim environment.
- Kirk Ransomware & Spock Decryptor ransomware
- Also known as Kirk & Spock Decryptor. This is most likely to affect English speaking users, since the note is written in English.
- Kitmos ratspyware
- Also known as KitM. Kitmos, also known as KitM, is a remote access trojan (RAT) that allows attackers to gain control over infected systems.
- Kivars rat
- Kivars is a modular remote access tool (RAT), derived from the Bifrost RAT, that was used by BlackTech in a 2010 campaign.
- KiwiStealer trojan
- According to Threatray, KiwiStealer is a simple file stealer first discovered in late 2024.
- KjW0rm wormtrojan
- KjW0rm is a malware known for its worm-like behavior and capabilities to propagate through networks.
- Klackring dropper
- Microsoft describes that threat actor ZINC is using Klackring as a malware dropped by ComeBacker, both being used to target security…
- KleptoParasite Stealer credential-stealerloader
- Also known as Joglog, Parasite. KleptoParasite Stealer is advertised on Hackforums as a noob-friendly stealer.
- KlingonRAT rat
- KlingonRAT is a remote access tool used primarily for cyber espionage activities.
- KnSpy spywarerat
- KnSpy is a sophisticated malware family used in cyber espionage campaigns targeting government and technology sectors, primarily in East…
- Knot ransomware
- Knot is a type of ransomware designed to encrypt files on a victim's device, demanding a ransom for their decryption.
- KoKoKrypt Ransomware ransomware
- Also known as KokoLocker Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- KoSpy spywarescreen-capture
- According to Lookout, this spyware was first observed in March 2022 and remains active with new samples still publicly hosted.
- Koadic rat
- Koadic is a Windows post-exploitation framework and penetration testing tool that is publicly available on GitHub.
- Kobalos backdoor
- Kobalos is a multi-platform backdoor that can be used against Linux, FreeBSD, and Solaris.
- Koi Loader loader
- Koi Loader is a malware primarily designed to serve as a loader for other malicious payloads.
- Koi Stealer credential-stealertrojan
- Koi Stealer is a trojan designed to capture and exfiltrate sensitive information, primarily targeting credentials from browsers and other…
- KoiVM loader
- KoiVM is a .NET virtualization and obfuscation tool commonly used to protect malware and hinder reverse-engineering efforts.
- KokoKrypt ransomware
- KokoKrypt is a ransomware family known for encrypting files and demanding payment in cryptocurrency.
- Koler ransomware
- Koler is a type of mobile ransomware that primarily targets Android devices.
- Kolobo Ransomware ransomware
- Also known as Kolobocheg Ransomware. This is most likely to affect English speaking users, since the note is written in English.
- Komplex backdoor
- Also known as JHUHUGIT, JKEYSKW, SedUploader. Komplex is a backdoor that has been used by APT28 on OS X and appears to be developed in a similar manner to XAgentOSX.
- KongTuke downloaderloadertrojan
- Also known as TAG-124, js.LandUpdate808. Kongtuke is a sophisticated TDS system that was initially discovered around May 2024.
- Konni (Android) backdoorrat
- Konni is a remote access trojan (RAT) primarily targeting Android devices.
- Konni (Windows) rat
- Konni is a remote administration tool, observed in the wild since early 2014.
- KoobFace wormbotnet
- KoobFace is a worm and botnet targeting users of social media platforms such as Facebook, MySpace, and Twitter.
- Koolova Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Korean ransomware
- Korean is a ransomware variant based on the HiddenTear open-source project.
- Korlia ratbackdoor
- Also known as Bisonal. Korlia, also known as Bisonal, is a remote access trojan primarily used by threat actors for cyber espionage.
- Kostya Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Kovter ransomware
- Kovter is a fileless malware family initially identified as ransomware.
- Kozy.Jozy ransomware
- Also known as QC. Ransomware Potential Kit [email protected] [email protected] [email protected]
- KrBanker trojancredential-stealer
- Also known as BlackMoon. ThreatPost describes KRBanker (Blackmoon) as a banking Trojan designed to steal user credentials from various South Korean banking…
- KrDownloader downloader
- KrDownloader is a malware downloader known for distributing additional malicious payloads.
- Krachulka trojancredential-stealer
- According to ESET, this malware family is a banking trojan and was active in Brazil until the middle of 2019.
- Kraken Cryptor Ransomware ransomware
- The Kraken Cryptor Ransomware is a newer ransomware that was released in August 2018.
- Kraken Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- KrakenKeylogger credential-stealerkeylogger
- KrakenKeylogger is a .NET based Infostealer malware sold in Underground hacking forums
- Krasue RAT rat
- Krasue RAT is a remote access tool designed to provide unauthorized access to compromised systems.
- KratosCrypt ransomware
- KratosCrypt is a type of ransomware that encrypts files on the victim's system and demands a ransom payment.
- Kriptovor ransomware
- Kriptovor is a ransomware that encrypts files on infected systems, demanding payment for the decryption key.
- Kronos trojancredential-stealerkeylogger
- Also known as Osiris. Kronos malware is a sophisticated banking Trojan that first emerged in 2014.
- KrustyLoader downloaderloader
- ELF x64 Rust downloader first discovered on Ivanti Connect Secure VPN after the exploitation of CVE-2024-21887 and CVE-2023-46805.
- Krypte ransomware
- Krypte is a ransomware type malware that encrypts files on victim systems, demanding a ransom for decryption keys.
- KryptoCibule cryptominercredential-stealerspyware
- KryptoCibule is a malware family that focuses on infecting systems to mine cryptocurrencies and steal sensitive information.
- KryptoLocker ransomware
- Ransomware Based on HiddenTear
- Krypton ransomware
- Krypton is a type of ransomware that encrypts files on affected systems and demands a ransom for decryption.
- Kryptonite RBY ransomware
- Kryptonite RBY is a malicious ransomware that encrypts files on the infected system and demands a ransom for decryption.
- Kryptonite Snake ransomware
- Kryptonite Snake is a ransomware strain known for encrypting files on compromised systems.
- Kuaibu trojan
- Also known as Barys, Gofot, Kuaibpy. Kuaibu, also referred to as Barys or Gofot, is a trojan malware family known to target financial-services and technology sectors.
- Kubo Injector loader
- According to the author if this open source project, this is a library for injecting a shared library into a Linux, Windows and MacOS…
- KugelBlitz loader
- According to Threatray, KugelBlitz is a shellcode loader discovered in late 2024.
- Kuiper (ELF) trojanbackdoor
- Kuiper is an ELF-based malware known for targeting Linux systems.
- Kuiper (OS X) backdoor
- Kuiper (OS X) is a malware strain that operates primarily as a backdoor for macOS systems.
- Kuiper (Windows) backdoorrat
- Kuiper is a sophisticated Windows-based malware that primarily functions as a remote access tool (RAT).
- Kuluoz droppercredential-stealer
- Kuluoz is a malware family primarily used as a dropper in spam campaigns targeting financial services and other industries.
- Kupidon ransomware
- Kupidon is a ransomware variant that encrypts files and demands a ransom payment to restore access.
- Kurton trojan
- Kurton is a banking Trojan primarily targeting financial services and government sectors.
- Kutaki backdoorcredential-stealertrojan
- Cofense characterizes Kutaki as a data stealer that uses old-school techniques to detect sandboxes and debugging.
- Kwampirs backdoortrojan
- Kwampirs is a backdoor Trojan used by Orangeworm.
- L0rdix ratcredential-stealercryptominer
- Also known as lordix. L0rdix is a multipurpose .NET remote access tool (RAT) first discovered being sold on underground forums in November 2018.
- L33TAF Locker Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- LALALA Stealer credential-stealer
- LALALA Stealer is a credential-stealing malware primarily targeting financial services and technology sectors.
- LAMEHUG credential-stealerspyware
- Also known as PROMPTSTEAL. LAMEHUG is Python-based information stealer first identified in July 2025 by Ukraine's Computer Emergency Response Team (CERT-UA) in…
- LANDFALL wiper
- LANDFALL is a destructive piece of malware known for its wiper capabilities targeting critical infrastructure sectors.
- LCPDot trojan
- LCPDot is a trojan used primarily in cyber-espionage campaigns targeting government and financial sectors.
- LCRYX trojanransomware
- LCRYX is a sophisticated trojan often used in ransomware attacks against financial services and government sectors.
- LDR4 backdoor
- A further branch of the URSNIF collection of malware families.
- LIGHTBUNNY backdoor
- LIGHTBUNNY is a sophisticated malware used in targeted attacks against government and financial sectors.
- LIGHTRAIL trojan
- According to Mandiant, this is a tunneler, likely based on an open-source Socks4a proxy, that communicates using Azure cloud infrastructure.
- LIGHTWIRE webshell
- LIGHTWIRE is a web shell written in Perl that was used during Cutting Edge to maintain access and enable command execution by imbedding…
- LIGHTWORK wiper
- According to Mandiant, LIGHTWORK is a disruption tool written in C++ that implements the IEC-104 protocol to modify the state of RTUs over…
- LIGMA ransomware
- LIGMA is a form of ransomware that encrypts files on the infected system, demanding a ransom for file decryption.
- LIONTAIL rat
- LIONTAIL is a remote access trojan primarily used for cyber espionage activities.
- LITTLELAMB.WOOLTEA backdoor
- LITTLELAMB.WOOLTEA is a backdoor that was used by UNC5325 during Cutting Edge to deploy malware on targeted Ivanti Connect Secure VPNs and…
- LK Encryption ransomware
- LK Encryption is a ransomware based on the HiddenTear open-source project, used to encrypt files and demand a ransom payment for decryption.
- LLTP Locker ransomware
- LLTP Locker is a ransomware targeting Spanish speaking victims.
- LMAOxUS ransomware
- LMAOxUS is a ransomware strain that encrypts files on infected systems, demanding payment to decrypt the data.
- LNKR trojan
- The LNKR trojan is a malicious browser extension that will monitor the websites visited by the user, looking for pages with administrative…
- LOBSHOT trojancredential-stealer
- According to PCrisk, LOBSHOT is a type of malware with a feature called hVNC (Hidden Virtual Network Computing) that allows attackers to…
- LODEINFO backdoor
- LODEINFO is a fileless backdoor malware first identified in 2020 that has been used by actors including MirrorFace, primarily against…
- LOLSnif credential-stealer
- LOLSnif is a credential-stealing malware that targets financial sectors.
- LONGWATCH keylogger
- The primary function of LONGWATCH is a keylogger that outputs keystrokes to a log.txt file in the Windows temp folder.
- LOSTKEYS spywaretrojan
- According to Google, LOSTKEYS is capable of stealing files from a hard-coded list of extensions and directories, along with sending system…
- LOWBALL backdoor
- LOWBALL is malware used by admin@338. It was used in August 2015 in email messages targeting Hong Kong-based media organizations.
- LOWKEY backdoor
- Also known as PortReuse. LOWKEY, also known as PortReuse, is a modular backdoor designed to evade standard detection mechanisms by leveraging existing legitimate…
- LOWZERO backdoorrat
- LOWZERO is a sophisticated backdoor often used by state-sponsored threat actors.
- LP-Notes credential-stealer
- LP-Notes is a C/C++ Windows credential stealer used by MuddyWater.
- LPEClient downloader
- Also known as LPEClientTea. LPEClient is an HTTP(S) downloader that expects two command line parameters: an encrypted string containing two URLs (a primary and a…
- LZRD botnetddos
- According to Akamai, a Mirai variant exploiting GeoVision IoT devices, (possibly CVE-2024-6047 and/or CVE-2024-11120).
- LaZagne credential-stealer
- LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system.
- Ladon ransomware
- Ladon is a ransomware that encrypts files on the victim's system, demanding a ransom to restore access.