Malware Families page 28 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Lador rat
Lador is a remote access trojan (RAT) used for cyber-espionage activities, primarily targeting financial, government, and technology…
Lady ransomware
Lady is a ransomware family known to target financial institutions and government entities.
Lalabitch_ransomware ransomware
Lalabitch_ransomware is a type of ransomware designed to encrypt files and demand a ransom for decryption keys.
LambLoad downloader
Also known as OfficeCertTea. According to Microsoft, this is a downloader used in a supply chain attack involving a malicious variant of an application developed by…
LambdaLocker Ransomware ransomware
It’s directed to English and Chinese speaking users, therefore is able to infect worldwide.
Lambert (OS X) backdoor
Also known as GreenLambert. Lambert (OS X), also known as GreenLambert, is a sophisticated backdoor used by advanced persistent threat actors.
Lambert (Windows) backdoorrat
Also known as Plexor. Lambert, also known as Plexor, is a highly advanced cyber-espionage toolkit used by nation-state attackers.
Lamdelin backdoortrojanransomware
Lamdelin is a sophisticated malware family known for its modular design, allowing it to conduct various cyber espionage tasks.
LanRan ransomware
Ransomware Variant of open-source MyLittleRansomware
LandSlide ransomware
LandSlide is a form of ransomware that encrypts files on the victim's system and demands payment in cryptocurrency for the decryption key.
Lanfiltrator backdoortrojan
Backdoor.Lanfiltrator is a backdoor Trojan that gives an attacker unauthorized access to a compromised computer.
Laoshu rat
Laoshu is a Remote Access Trojan (RAT) used primarily for cyber espionage.
Laplas (Reverseshell) rat
According to Seqrite, this is a TLS-based reverse shell.
LaplasClipper trojan
LaplasClipper is a type of malware that monitors the clipboard of an infected system to detect and alter cryptocurrency wallet addresses.
Lapsus$
Lapsus$ is a cyber extortion group first observed in late 2021, known for high-profile breaches and data theft campaigns against major…
LatentBot botnetwiperdropper
FireEye describes this malware as a highly obfuscated bot that has been in the wild since mid-2013.
Latrodectus downloaderloader
Also known as IceNova, Unidentified 111, BLACKWIDOW. Latrodectus is a Windows malware downloader that has been used since at least 2023 to download and execute additional payloads and modules.
Laturo Stealer credential-stealer
Laturo Stealer is a credential-stealing malware targeting sensitive information such as login credentials from infected systems.
LazagneCrypt ransomware
LazagneCrypt is ransomware known for encrypting victims' files and demanding a ransom for decryption.
LazarDoor backdoorrat
LazarDoor is a backdoor associated with the Lazarus Group, known for its use in cyber-espionage campaigns targeting various sectors…
LazarLoader loader
LazarLoader is a malicious loader used by threat actors to download and execute additional payloads on compromised systems.
Laziok downloader
Laziok is a malware family primarily acting as a downloader used to target the energy sector, particularly in the Middle East.
LazyCat ratspyware
LazyCat is a sophisticated remote access Trojan (RAT) often linked to state-sponsored espionage campaigns.
LazyWiper wiper
LazyWiper is a destructive malware observed targeting a manufacturing sector company during the 2025 Poland Wiper Attacks.
Lazyscripter downloaderrat
Lazyscripter is a threat actor group known for targeting governmental sectors, primarily utilizing downloader and RAT techniques.
LeChiffre ransomware
Ransomware Encrypts first 0x2000 and last 0x2000 bytes.
LeGeNd backdoorrat
LeGeNd is a sophisticated backdoor and RAT utilized by nation-state actors primarily for cyber espionage.
Leakthemall ransomware
ransomware
Leash rat
Leash is a remote access tool (RAT) known for targeting government and financial sectors.
Lechiket
No description available.
LeetHozer trojanbotnet
LeetHozer is a sophisticated trojan malware known for its capabilities in creating botnets for distributed attacks.
Lemon Duck cryptominerworm
Lemon Duck is a monerocrypto-mining malware with capabilitiy to spread rapidly across the entire network.
Leouncia rat
Also known as shoco. Leouncia, also known as shoco, is a remote access Trojan (RAT) known for its use in cyber espionage campaigns.
Leslieloader loader
Leslieloader is a loader written in Golang, named after the observed AES decryption key referencing deceased actor, Leslie Cheung.
LetMeOut
LetMeOut is a type of malware for which detailed information is not available.
Lethic botnet
Lethic is a spambot dating back to 2008. It is known to be distributing low-level pharmaceutical spam.
Leverage rat
Leverage is a sophisticated Remote Access Tool (RAT) used primarily for cyber espionage targeting financial services and government sectors.
LgoogLoader loaderdropper
LgoogLoader is an installer that drops three files: a batch file, an AutoIt interpreter, and an AutoIt script.
LiLock ransomware
Also known as Lilocked, Lilu. LiLock, also known as Lilocked or Lilu, is a ransomware family that primarily targets web servers and encrypts files, demanding ransom for…
Lick ransomware
Lick is a ransomware variant of Kirk, known for encrypting victims' files and demanding payment in cryptocurrency for decryption.
LickyAgent ransomware
LickyAgent is a ransomware known for targeting critical industries such as financial services and healthcare.
Liderc backdoorrat
Also known as LEMPO. Liderc, also known as LEMPO, is a sophisticated remote access tool used by advanced persistent threat groups for espionage activities.
Light ransomware
Light is a ransomware that encrypts files on the victim's machine, demanding payment for decryption.
LightBot
According to Bleeping Computer and Vitali Kremez, LightBot is a compact reconnaissance tool suspected to be used to identify high-value…
LightNeuron backdoor
Also known as NETTRANS, XTRANS. LightNeuron is a sophisticated backdoor that has targeted Microsoft Exchange servers since at least 2014.
LightSpy spywarecredential-stealerdownloader
First observed in 2018, LightSpy is a modular malware family that initially targeted iOS devices in Southern Asia before expanding to…
LightlessCan rat
Also known as SIDESHOW. LightlessCan is a complex HTTP(S) RAT, that is a successor of the Lazarus RAT named BlindingCan.
Lightning Framework rootkitbackdoor
Lightning Framework is a sophisticated, modular malware primarily targeting Linux systems.
Lightning Stealer credential-stealerspyware
Lightning stealer can target 30+ Firefox and Chromium-based browsers and steal crypto wallets, Telegram data, Discord tokens, and Steam…
LightningCrypt ransomware
LightningCrypt is a ransomware strain known for encrypting files and demanding a cryptocurrency payment in exchange for decryption keys.
Ligsterac trojancredential-stealer
Ligsterac is a malicious software that primarily functions as a credential-stealer.
Lilith ransomware
Lilith is a ransomware family known for targeting large organizations, particularly within the government and financial services sectors.
Lime ransomware
Lime is a type of ransomware that encrypts victim files and demands a ransom for decryption.
LimePad ransomware
LimePad is a ransomware family that primarily targets financial services and government sectors.
LimeRAT ratransomwarecryptominer
## Description Simple yet powerful RAT for Windows machines.
Limitail backdoortrojan
Limitail is a sophisticated malware family primarily used for cyber espionage activities targeting government and technology sectors.
Line Dancer loader
Line Dancer is a memory-only Lua-based shellcode loader associated with the ArcaneDoor campaign.
Line Runner backdoorwebshell
Line Runner is a persistent backdoor and web shell allowing threat actors to upload and execute arbitrary Lua scripts.
Linfo rootkittrojan
Linfo is a rootkit trojan used by Elderwood to open a backdoor on compromised hosts.
LinkPro rootkit
According to Synacktiv, LinkPro targets the GNU/Linux systems and is developed in Golang.
Linodas rat
Also known as DinodasRAT, XDealer. Linodas, also known as DinodasRAT and XDealer, is a remote access trojan (RAT) used for espionage and data exfiltration targeting…
LinseningSvr rat
LinseningSvr is a remote access trojan associated with cyber espionage activities.
Linux Rabbit cryptominer
Linux Rabbit is malware that targeted Linux servers and IoT devices in a campaign lasting from August to October 2018.
Linux.Encoder ransomware
Also known as Linux.Encoder.{0,3}. Linux.Encoder is a ransomware family targeting Linux systems.
LiquorBot botnetcryptominer
BitDefender tracked the development of a Mirai-inspired botnet, dubbed LiquorBot, which seems to be actively in development and has…
Listrix backdoortrojan
Listrix is a sophisticated backdoor trojan used primarily against government and financial institutions.
LiteDuke backdoor
LiteDuke is a third stage backdoor that was used by APT29, primarily in 2014-2015.
LiteHTTP botnetdownloader
According to AlienVault, LiteHTTP bot is a new HTTP bot programmed in C#.
LiteManager rat
LiteManager is another remote access program, and it's strikingly similar to Remote Utilities, which I explain on the first page of this…
LitePower downloader
LitePower is a downloader and second stage malware that has been used by WIRTE since at least 2021.
Litra ransomware
Litra is a type of ransomware known for encrypting files and demanding payment for the decryption key.
LitterDrifter trojan
LitterDrifter is a sophisticated trojan primarily used for cyber espionage, targeting governmental and financial sectors.
LittleDaemon downloader
According to ESET Research, LittleDaemon is the first stage deployed on the victim’s machine through hijacked updates.
LittleFinger ransomware
LittleFinger is a ransomware family known for encrypting users' files and demanding a ransom for decryption keys.
LittleLooter ratspyware
LittleLooter is a remote access tool (RAT) designed to exfiltrate sensitive information from compromised systems.
Lizar ratloader
Also known as Tirion, Icebot, DiceLoader. Lizar is a modular remote access tool written using the .NET Framework that shares structural similarities to Carbanak.
LoFiSe spyware
LoFiSe has been used by ToddyCat since at least 2023 to identify and collect files of interest on targeted systems.
LoJax rootkit
LoJax is a UEFI rootkit used by APT28 to persist remote access software on targeted systems.
LocalOlive webshell
According to Microsoft, this is a web shell, written in ASPX supporting C#, carrying sufficient yet rudimentary functionality to support…
Lock2017 Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Lock93 Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
LockBit ransomware
Also known as ABCD ransomware. LockBit operators tend to be very indiscriminate and opportunistic in their targeting.
LockBit (ELF) ransomware
LockBit (ELF) is a ransomware variant targeting Linux systems, chiefly associated with multinational operations and extensive extortion…
LockBit (OS X) ransomware
LockBit (OS X) is a ransomware variant targeting macOS systems.
LockBit (Windows) ransomware
Also known as ABCD Ransomware. LockBit is a ransomware family known for targeting various industries globally, encrypting files and demanding ransom payments.
LockBit 2.0 ransomware
LockBit 2.0 is an affiliate-based Ransomware-as-a-Service (RaaS) that has been in use since at least June 2021 as the successor to LockBit…
LockBit 3.0 ransomware
Also known as LockBit Black. LockBit 3.0 is an evolution of the LockBit Ransomware-as-a-Service (RaaS) offering with similarities to BlackMatter and BlackCat ransomware.
LockBox ransomware
LockBox is a sophisticated ransomware family known for encrypting victim files and demanding cryptocurrency payments in exchange for…
LockCrypt ransomware
LockCrypt is an example of yet another simple ransomware created and used by unsophisticated attackers.
LockFile ransomware
LockFile is a ransomware that emerged in July 2021, known for encrypting files and demanding ransom payments.
LockLock ransomware
LockLock is a ransomware family that encrypts files on a victim's computer and demands payment for decryption.
LockMe ransomware
LockMe is a ransomware family that encrypts files on an infected system, demanding payment from the victim to restore access.
LockOn ransomware
LockOn is a type of ransomware that encrypts files on a victim's system, demanding a ransom for decryption keys.
LockPOS trojan
LockPOS is a point-of-sale malware family designed to steal payment card data from compromised systems.
Lockbit3 ransomware
Lockbit3 is a notorious ransomware family known for its ransomware-as-a-service model and double extortion tactics.
Locked-In Ransomware or NoValid Ransomware ransomware
Also known as Locked-In Ransomware, NoValid Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
LockedByte ransomware
LockedByte is a ransomware strain that encrypts files on infected systems, demanding a ransom for decryption.
Locked_File ransomware
Locked_File is a ransomware that encrypts files on the infected system, demanding a ransom payment in exchange for a decryption key.
Lockedv1 ransomware
Lockedv1 is a ransomware variant known for encrypting files on the infected system and demanding a ransom for decryption.
Locker ransomware
Locker is a type of ransomware that features a graphical user interface, making the attack more user-friendly for the perpetrators.