Malware Families page 27 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

KilllSomeOne
KimJongRat rat
KimJongRat is a remote access trojan associated with cyber-espionage campaigns linked to North Korean threat actors.
KimcilWare ransomware
KimcilWare is a ransomware that primarily targets websites, encrypting their files and demanding a ransom for decryption.
Kimsuky spywarebackdoor
Kimsuky is a cyber espionage group known to target South Korean entities, particularly in the government and media sectors.
Kimwolf botnetddos
KIMWOLF is an android based malware which uses compromised systems to relay malicious and abusive Internet traffic, as well as…
Kindest ransomware
ransomware
KingOuroboros ransomware
This crypto-extortioner encrypts user data using AES, and then requires a $ 30- $ 50- $ 80 buy- back to BTC to return the files.
Kingminer botnetcryptominerddos
According to Sophis, the botnet has been active since 2018, initially, the botmasters operated DDoS tools and backdoors, but later moved…
Kinsing cryptominerworm
Also known as h2miner. Kinsing is Golang-based malware that runs a cryptocurrency miner and attempts to spread itself to other hosts in the victim environment.
Kirk Ransomware & Spock Decryptor ransomware
Also known as Kirk & Spock Decryptor. This is most likely to affect English speaking users, since the note is written in English.
Kitmos ratspyware
Also known as KitM. Kitmos, also known as KitM, is a remote access trojan (RAT) that allows attackers to gain control over infected systems.
Kivars rat
Kivars is a modular remote access tool (RAT), derived from the Bifrost RAT, that was used by BlackTech in a 2010 campaign.
KiwiStealer trojan
According to Threatray, KiwiStealer is a simple file stealer first discovered in late 2024.
KjW0rm wormtrojan
KjW0rm is a malware known for its worm-like behavior and capabilities to propagate through networks.
Klackring dropper
Microsoft describes that threat actor ZINC is using Klackring as a malware dropped by ComeBacker, both being used to target security…
KleptoParasite Stealer credential-stealerloader
Also known as Joglog, Parasite. KleptoParasite Stealer is advertised on Hackforums as a noob-friendly stealer.
KlingonRAT rat
KlingonRAT is a remote access tool used primarily for cyber espionage activities.
KnSpy spywarerat
KnSpy is a sophisticated malware family used in cyber espionage campaigns targeting government and technology sectors, primarily in East…
Knot ransomware
Knot is a type of ransomware designed to encrypt files on a victim's device, demanding a ransom for their decryption.
KoKoKrypt Ransomware ransomware
Also known as KokoLocker Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
KoSpy spywarescreen-capture
According to Lookout, this spyware was first observed in March 2022 and remains active with new samples still publicly hosted.
Koadic rat
Koadic is a Windows post-exploitation framework and penetration testing tool that is publicly available on GitHub.
Kobalos backdoor
Kobalos is a multi-platform backdoor that can be used against Linux, FreeBSD, and Solaris.
Koi Loader loader
Koi Loader is a malware primarily designed to serve as a loader for other malicious payloads.
Koi Stealer credential-stealertrojan
Koi Stealer is a trojan designed to capture and exfiltrate sensitive information, primarily targeting credentials from browsers and other…
KoiVM loader
KoiVM is a .NET virtualization and obfuscation tool commonly used to protect malware and hinder reverse-engineering efforts.
KokoKrypt ransomware
KokoKrypt is a ransomware family known for encrypting files and demanding payment in cryptocurrency.
Koler ransomware
Koler is a type of mobile ransomware that primarily targets Android devices.
Kolobo Ransomware ransomware
Also known as Kolobocheg Ransomware. This is most likely to affect English speaking users, since the note is written in English.
Komplex backdoor
Also known as JHUHUGIT, JKEYSKW, SedUploader. Komplex is a backdoor that has been used by APT28 on OS X and appears to be developed in a similar manner to XAgentOSX.
KongTuke downloaderloadertrojan
Also known as TAG-124, js.LandUpdate808. Kongtuke is a sophisticated TDS system that was initially discovered around May 2024.
Konni (Android) backdoorrat
Konni is a remote access trojan (RAT) primarily targeting Android devices.
Konni (Windows) rat
Konni is a remote administration tool, observed in the wild since early 2014.
KoobFace wormbotnet
KoobFace is a worm and botnet targeting users of social media platforms such as Facebook, MySpace, and Twitter.
Koolova Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Korean ransomware
Korean is a ransomware variant based on the HiddenTear open-source project.
Korlia ratbackdoor
Also known as Bisonal. Korlia, also known as Bisonal, is a remote access trojan primarily used by threat actors for cyber espionage.
Kostya Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Kovter ransomware
Kovter is a fileless malware family initially identified as ransomware.
Kozy.Jozy ransomware
Also known as QC. Ransomware Potential Kit [email protected] [email protected] [email protected]
KrBanker trojancredential-stealer
Also known as BlackMoon. ThreatPost describes KRBanker (Blackmoon) as a banking Trojan designed to steal user credentials from various South Korean banking…
KrDownloader downloader
KrDownloader is a malware downloader known for distributing additional malicious payloads.
Krachulka trojancredential-stealer
According to ESET, this malware family is a banking trojan and was active in Brazil until the middle of 2019.
Kraken Cryptor Ransomware ransomware
The Kraken Cryptor Ransomware is a newer ransomware that was released in August 2018.
Kraken Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
KrakenKeylogger credential-stealerkeylogger
KrakenKeylogger is a .NET based Infostealer malware sold in Underground hacking forums
Krasue RAT rat
Krasue RAT is a remote access tool designed to provide unauthorized access to compromised systems.
KratosCrypt ransomware
KratosCrypt is a type of ransomware that encrypts files on the victim's system and demands a ransom payment.
Kriptovor ransomware
Kriptovor is a ransomware that encrypts files on infected systems, demanding payment for the decryption key.
Kronos trojancredential-stealerkeylogger
Also known as Osiris. Kronos malware is a sophisticated banking Trojan that first emerged in 2014.
KrustyLoader downloaderloader
ELF x64 Rust downloader first discovered on Ivanti Connect Secure VPN after the exploitation of CVE-2024-21887 and CVE-2023-46805.
Krypte ransomware
Krypte is a ransomware type malware that encrypts files on victim systems, demanding a ransom for decryption keys.
KryptoCibule cryptominercredential-stealerspyware
KryptoCibule is a malware family that focuses on infecting systems to mine cryptocurrencies and steal sensitive information.
KryptoLocker ransomware
Ransomware Based on HiddenTear
Krypton ransomware
Krypton is a type of ransomware that encrypts files on affected systems and demands a ransom for decryption.
Kryptonite RBY ransomware
Kryptonite RBY is a malicious ransomware that encrypts files on the infected system and demands a ransom for decryption.
Kryptonite Snake ransomware
Kryptonite Snake is a ransomware strain known for encrypting files on compromised systems.
Kuaibu trojan
Also known as Barys, Gofot, Kuaibpy. Kuaibu, also referred to as Barys or Gofot, is a trojan malware family known to target financial-services and technology sectors.
Kubo Injector loader
According to the author if this open source project, this is a library for injecting a shared library into a Linux, Windows and MacOS…
KugelBlitz loader
According to Threatray, KugelBlitz is a shellcode loader discovered in late 2024.
Kuiper (ELF) trojanbackdoor
Kuiper is an ELF-based malware known for targeting Linux systems.
Kuiper (OS X) backdoor
Kuiper (OS X) is a malware strain that operates primarily as a backdoor for macOS systems.
Kuiper (Windows) backdoorrat
Kuiper is a sophisticated Windows-based malware that primarily functions as a remote access tool (RAT).
Kuluoz droppercredential-stealer
Kuluoz is a malware family primarily used as a dropper in spam campaigns targeting financial services and other industries.
Kupidon ransomware
Kupidon is a ransomware variant that encrypts files and demands a ransom payment to restore access.
Kurton trojan
Kurton is a banking Trojan primarily targeting financial services and government sectors.
Kutaki backdoorcredential-stealertrojan
Cofense characterizes Kutaki as a data stealer that uses old-school techniques to detect sandboxes and debugging.
Kwampirs backdoortrojan
Kwampirs is a backdoor Trojan used by Orangeworm.
L0rdix ratcredential-stealercryptominer
Also known as lordix. L0rdix is a multipurpose .NET remote access tool (RAT) first discovered being sold on underground forums in November 2018.
L33TAF Locker Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
LALALA Stealer credential-stealer
LALALA Stealer is a credential-stealing malware primarily targeting financial services and technology sectors.
LAMEHUG credential-stealerspyware
Also known as PROMPTSTEAL. LAMEHUG is Python-based information stealer first identified in July 2025 by Ukraine's Computer Emergency Response Team (CERT-UA) in…
LANDFALL wiper
LANDFALL is a destructive piece of malware known for its wiper capabilities targeting critical infrastructure sectors.
LCPDot trojan
LCPDot is a trojan used primarily in cyber-espionage campaigns targeting government and financial sectors.
LCRYX trojanransomware
LCRYX is a sophisticated trojan often used in ransomware attacks against financial services and government sectors.
LDR4 backdoor
A further branch of the URSNIF collection of malware families.
LIGHTBUNNY backdoor
LIGHTBUNNY is a sophisticated malware used in targeted attacks against government and financial sectors.
LIGHTRAIL trojan
According to Mandiant, this is a tunneler, likely based on an open-source Socks4a proxy, that communicates using Azure cloud infrastructure.
LIGHTWIRE webshell
LIGHTWIRE is a web shell written in Perl that was used during Cutting Edge to maintain access and enable command execution by imbedding…
LIGHTWORK wiper
According to Mandiant, LIGHTWORK is a disruption tool written in C++ that implements the IEC-104 protocol to modify the state of RTUs over…
LIGMA ransomware
LIGMA is a form of ransomware that encrypts files on the infected system, demanding a ransom for file decryption.
LIONTAIL rat
LIONTAIL is a remote access trojan primarily used for cyber espionage activities.
LITTLELAMB.WOOLTEA backdoor
LITTLELAMB.WOOLTEA is a backdoor that was used by UNC5325 during Cutting Edge to deploy malware on targeted Ivanti Connect Secure VPNs and…
LK Encryption ransomware
LK Encryption is a ransomware based on the HiddenTear open-source project, used to encrypt files and demand a ransom payment for decryption.
LLTP Locker ransomware
LLTP Locker is a ransomware targeting Spanish speaking victims.
LMAOxUS ransomware
LMAOxUS is a ransomware strain that encrypts files on infected systems, demanding payment to decrypt the data.
LNKR trojan
The LNKR trojan is a malicious browser extension that will monitor the websites visited by the user, looking for pages with administrative…
LOBSHOT trojancredential-stealer
According to PCrisk, LOBSHOT is a type of malware with a feature called hVNC (Hidden Virtual Network Computing) that allows attackers to…
LODEINFO backdoor
LODEINFO is a fileless backdoor malware first identified in 2020 that has been used by actors including MirrorFace, primarily against…
LOLSnif credential-stealer
LOLSnif is a credential-stealing malware that targets financial sectors.
LONGWATCH keylogger
The primary function of LONGWATCH is a keylogger that outputs keystrokes to a log.txt file in the Windows temp folder.
LOSTKEYS spywaretrojan
According to Google, LOSTKEYS is capable of stealing files from a hard-coded list of extensions and directories, along with sending system…
LOWBALL backdoor
LOWBALL is malware used by admin@338. It was used in August 2015 in email messages targeting Hong Kong-based media organizations.
LOWKEY backdoor
Also known as PortReuse. LOWKEY, also known as PortReuse, is a modular backdoor designed to evade standard detection mechanisms by leveraging existing legitimate…
LOWZERO backdoorrat
LOWZERO is a sophisticated backdoor often used by state-sponsored threat actors.
LP-Notes credential-stealer
LP-Notes is a C/C++ Windows credential stealer used by MuddyWater.
LPEClient downloader
Also known as LPEClientTea. LPEClient is an HTTP(S) downloader that expects two command line parameters: an encrypted string containing two URLs (a primary and a…
LZRD botnetddos
According to Akamai, a Mirai variant exploiting GeoVision IoT devices, (possibly CVE-2024-6047 and/or CVE-2024-11120).
LaZagne credential-stealer
LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system.
Ladon ransomware
Ladon is a ransomware that encrypts files on the victim's system, demanding a ransom to restore access.