Malware Families page 28 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Lador rat
- Lador is a remote access trojan (RAT) used for cyber-espionage activities, primarily targeting financial, government, and technology…
- Lady ransomware
- Lady is a ransomware family known to target financial institutions and government entities.
- Lalabitch_ransomware ransomware
- Lalabitch_ransomware is a type of ransomware designed to encrypt files and demand a ransom for decryption keys.
- LambLoad downloader
- Also known as OfficeCertTea. According to Microsoft, this is a downloader used in a supply chain attack involving a malicious variant of an application developed by…
- LambdaLocker Ransomware ransomware
- It’s directed to English and Chinese speaking users, therefore is able to infect worldwide.
- Lambert (OS X) backdoor
- Also known as GreenLambert. Lambert (OS X), also known as GreenLambert, is a sophisticated backdoor used by advanced persistent threat actors.
- Lambert (Windows) backdoorrat
- Also known as Plexor. Lambert, also known as Plexor, is a highly advanced cyber-espionage toolkit used by nation-state attackers.
- Lamdelin backdoortrojanransomware
- Lamdelin is a sophisticated malware family known for its modular design, allowing it to conduct various cyber espionage tasks.
- LanRan ransomware
- Ransomware Variant of open-source MyLittleRansomware
- LandSlide ransomware
- LandSlide is a form of ransomware that encrypts files on the victim's system and demands payment in cryptocurrency for the decryption key.
- Lanfiltrator backdoortrojan
- Backdoor.Lanfiltrator is a backdoor Trojan that gives an attacker unauthorized access to a compromised computer.
- Laoshu rat
- Laoshu is a Remote Access Trojan (RAT) used primarily for cyber espionage.
- Laplas (Reverseshell) rat
- According to Seqrite, this is a TLS-based reverse shell.
- LaplasClipper trojan
- LaplasClipper is a type of malware that monitors the clipboard of an infected system to detect and alter cryptocurrency wallet addresses.
- Lapsus$
- Lapsus$ is a cyber extortion group first observed in late 2021, known for high-profile breaches and data theft campaigns against major…
- LatentBot botnetwiperdropper
- FireEye describes this malware as a highly obfuscated bot that has been in the wild since mid-2013.
- Latrodectus downloaderloader
- Also known as IceNova, Unidentified 111, BLACKWIDOW. Latrodectus is a Windows malware downloader that has been used since at least 2023 to download and execute additional payloads and modules.
- Laturo Stealer credential-stealer
- Laturo Stealer is a credential-stealing malware targeting sensitive information such as login credentials from infected systems.
- LazagneCrypt ransomware
- LazagneCrypt is ransomware known for encrypting victims' files and demanding a ransom for decryption.
- LazarDoor backdoorrat
- LazarDoor is a backdoor associated with the Lazarus Group, known for its use in cyber-espionage campaigns targeting various sectors…
- LazarLoader loader
- LazarLoader is a malicious loader used by threat actors to download and execute additional payloads on compromised systems.
- Laziok downloader
- Laziok is a malware family primarily acting as a downloader used to target the energy sector, particularly in the Middle East.
- LazyCat ratspyware
- LazyCat is a sophisticated remote access Trojan (RAT) often linked to state-sponsored espionage campaigns.
- LazyWiper wiper
- LazyWiper is a destructive malware observed targeting a manufacturing sector company during the 2025 Poland Wiper Attacks.
- Lazyscripter downloaderrat
- Lazyscripter is a threat actor group known for targeting governmental sectors, primarily utilizing downloader and RAT techniques.
- LeChiffre ransomware
- Ransomware Encrypts first 0x2000 and last 0x2000 bytes.
- LeGeNd backdoorrat
- LeGeNd is a sophisticated backdoor and RAT utilized by nation-state actors primarily for cyber espionage.
- Leakthemall ransomware
- ransomware
- Leash rat
- Leash is a remote access tool (RAT) known for targeting government and financial sectors.
- Lechiket
- No description available.
- LeetHozer trojanbotnet
- LeetHozer is a sophisticated trojan malware known for its capabilities in creating botnets for distributed attacks.
- Lemon Duck cryptominerworm
- Lemon Duck is a monerocrypto-mining malware with capabilitiy to spread rapidly across the entire network.
- Leouncia rat
- Also known as shoco. Leouncia, also known as shoco, is a remote access Trojan (RAT) known for its use in cyber espionage campaigns.
- Leslieloader loader
- Leslieloader is a loader written in Golang, named after the observed AES decryption key referencing deceased actor, Leslie Cheung.
- LetMeOut
- LetMeOut is a type of malware for which detailed information is not available.
- Lethic botnet
- Lethic is a spambot dating back to 2008. It is known to be distributing low-level pharmaceutical spam.
- Leverage rat
- Leverage is a sophisticated Remote Access Tool (RAT) used primarily for cyber espionage targeting financial services and government sectors.
- LgoogLoader loaderdropper
- LgoogLoader is an installer that drops three files: a batch file, an AutoIt interpreter, and an AutoIt script.
- LiLock ransomware
- Also known as Lilocked, Lilu. LiLock, also known as Lilocked or Lilu, is a ransomware family that primarily targets web servers and encrypts files, demanding ransom for…
- Lick ransomware
- Lick is a ransomware variant of Kirk, known for encrypting victims' files and demanding payment in cryptocurrency for decryption.
- LickyAgent ransomware
- LickyAgent is a ransomware known for targeting critical industries such as financial services and healthcare.
- Liderc backdoorrat
- Also known as LEMPO. Liderc, also known as LEMPO, is a sophisticated remote access tool used by advanced persistent threat groups for espionage activities.
- Light ransomware
- Light is a ransomware that encrypts files on the victim's machine, demanding payment for decryption.
- LightBot
- According to Bleeping Computer and Vitali Kremez, LightBot is a compact reconnaissance tool suspected to be used to identify high-value…
- LightNeuron backdoor
- Also known as NETTRANS, XTRANS. LightNeuron is a sophisticated backdoor that has targeted Microsoft Exchange servers since at least 2014.
- LightSpy spywarecredential-stealerdownloader
- First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to…
- LightlessCan rat
- Also known as SIDESHOW. LightlessCan is a complex HTTP(S) RAT, that is a successor of the Lazarus RAT named BlindingCan.
- Lightning Framework rootkitbackdoor
- Lightning Framework is a sophisticated, modular malware primarily targeting Linux systems.
- Lightning Stealer credential-stealerspyware
- Lightning stealer can target 30+ Firefox and Chromium-based browsers and steal crypto wallets, Telegram data, Discord tokens, and Steam…
- LightningCrypt ransomware
- LightningCrypt is a ransomware strain known for encrypting files and demanding a cryptocurrency payment in exchange for decryption keys.
- Ligsterac trojancredential-stealer
- Ligsterac is a malicious software that primarily functions as a credential-stealer.
- Lilith ransomware
- Lilith is a ransomware family known for targeting large organizations, particularly within the government and financial services sectors.
- Lime ransomware
- Lime is a type of ransomware that encrypts victim files and demands a ransom for decryption.
- LimePad ransomware
- LimePad is a ransomware family that primarily targets financial services and government sectors.
- LimeRAT ratransomwarecryptominer
- ## Description Simple yet powerful RAT for Windows machines.
- Limitail backdoortrojan
- Limitail is a sophisticated malware family primarily used for cyber espionage activities targeting government and technology sectors.
- Line Dancer loader
- Line Dancer is a memory-only Lua-based shellcode loader associated with the ArcaneDoor campaign.
- Line Runner backdoorwebshell
- Line Runner is a persistent backdoor and web shell allowing threat actors to upload and execute arbitrary Lua scripts.
- Linfo rootkittrojan
- Linfo is a rootkit trojan used by Elderwood to open a backdoor on compromised hosts.
- LinkPro rootkit
- According to Synacktiv, LinkPro targets the GNU/Linux systems and is developed in Golang.
- Linodas rat
- Also known as DinodasRAT, XDealer. Linodas, also known as DinodasRAT and XDealer, is a remote access trojan (RAT) used for espionage and data exfiltration targeting…
- LinseningSvr rat
- LinseningSvr is a remote access trojan associated with cyber espionage activities.
- Linux Rabbit cryptominer
- Linux Rabbit is malware that targeted Linux servers and IoT devices in a campaign lasting from August to October 2018.
- Linux.Encoder ransomware
- Also known as Linux.Encoder.{0,3}. Linux.Encoder is a ransomware family targeting Linux systems.
- LiquorBot botnetcryptominer
- BitDefender tracked the development of a Mirai-inspired botnet, dubbed LiquorBot, which seems to be actively in development and has…
- Listrix backdoortrojan
- Listrix is a sophisticated backdoor trojan used primarily against government and financial institutions.
- LiteDuke backdoor
- LiteDuke is a third stage backdoor that was used by APT29, primarily in 2014-2015.
- LiteHTTP botnetdownloader
- According to AlienVault, LiteHTTP bot is a new HTTP bot programmed in C#.
- LiteManager rat
- LiteManager is another remote access program, and it's strikingly similar to Remote Utilities, which I explain on the first page of this…
- LitePower downloader
- LitePower is a downloader and second stage malware that has been used by WIRTE since at least 2021.
- Litra ransomware
- Litra is a type of ransomware known for encrypting files and demanding payment for the decryption key.
- LitterDrifter trojan
- LitterDrifter is a sophisticated trojan primarily used for cyber espionage, targeting governmental and financial sectors.
- LittleDaemon downloader
- According to ESET Research, LittleDaemon is the first stage deployed on the victim’s machine through hijacked updates.
- LittleFinger ransomware
- LittleFinger is a ransomware family known for encrypting users' files and demanding a ransom for decryption keys.
- LittleLooter ratspyware
- LittleLooter is a remote access tool (RAT) designed to exfiltrate sensitive information from compromised systems.
- Lizar ratloader
- Also known as Tirion, Icebot, DiceLoader. Lizar is a modular remote access tool written using the .NET Framework that shares structural similarities to Carbanak.
- LoFiSe spyware
- LoFiSe has been used by ToddyCat since at least 2023 to identify and collect files of interest on targeted systems.
- LoJax rootkit
- LoJax is a UEFI rootkit used by APT28 to persist remote access software on targeted systems.
- LocalOlive webshell
- According to Microsoft, this is a web shell, written in ASPX supporting C#, carrying sufficient yet rudimentary functionality to support…
- Lock2017 Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Lock93 Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- LockBit ransomware
- Also known as ABCD ransomware. LockBit operators tend to be very indiscriminate and opportunistic in their targeting.
- LockBit (ELF) ransomware
- LockBit (ELF) is a ransomware variant targeting Linux systems, chiefly associated with multinational operations and extensive extortion…
- LockBit (OS X) ransomware
- LockBit (OS X) is a ransomware variant targeting macOS systems.
- LockBit (Windows) ransomware
- Also known as ABCD Ransomware. LockBit is a ransomware family known for targeting various industries globally, encrypting files and demanding ransom payments.
- LockBit 2.0 ransomware
- LockBit 2.0 is an affiliate-based Ransomware-as-a-Service (RaaS) that has been in use since at least June 2021 as the successor to LockBit…
- LockBit 3.0 ransomware
- Also known as LockBit Black. LockBit 3.0 is an evolution of the LockBit Ransomware-as-a-Service (RaaS) offering with similarities to BlackMatter and BlackCat ransomware.
- LockBox ransomware
- LockBox is a sophisticated ransomware family known for encrypting victim files and demanding cryptocurrency payments in exchange for…
- LockCrypt ransomware
- LockCrypt is an example of yet another simple ransomware created and used by unsophisticated attackers.
- LockFile ransomware
- LockFile is a ransomware that emerged in July 2021, known for encrypting files and demanding ransom payments.
- LockLock ransomware
- LockLock is a ransomware family that encrypts files on a victim's computer and demands payment for decryption.
- LockMe ransomware
- LockMe is a ransomware family that encrypts files on an infected system, demanding payment from the victim to restore access.
- LockOn ransomware
- LockOn is a type of ransomware that encrypts files on a victim's system, demanding a ransom for decryption keys.
- LockPOS trojan
- LockPOS is a point-of-sale malware family designed to steal payment card data from compromised systems.
- Lockbit3 ransomware
- Lockbit3 is a notorious ransomware family known for its ransomware-as-a-service model and double extortion tactics.
- Locked-In Ransomware or NoValid Ransomware ransomware
- Also known as Locked-In Ransomware, NoValid Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- LockedByte ransomware
- LockedByte is a ransomware strain that encrypts files on infected systems, demanding a ransom for decryption.
- Locked_File ransomware
- Locked_File is a ransomware that encrypts files on the infected system, demanding a ransom payment in exchange for a decryption key.
- Lockedv1 ransomware
- Lockedv1 is a ransomware variant known for encrypting files on the infected system and demanding a ransom for decryption.
- Locker ransomware
- Locker is a type of ransomware that features a graphical user interface, making the attack more user-friendly for the perpetrators.