Malware Families page 29 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Locker-Pay ransomware
Locker-Pay is a ransomware strain known for encrypting victims' files and demanding payment in cryptocurrency.
LockerGoga ransomware
LockerGoga is ransomware that was first reported in January 2019, and has been tied to various attacks on European companies, including…
Lockify ransomware
Lockify is a ransomware known for encrypting files on infected systems and demanding payment for decryption keys.
Lockout ransomware
Lockout is a type of ransomware that encrypts files on infected systems, demanding payment for decryption keys.
Locky ransomware
Also known as Locky-Odin, Locky-Osiris, Locky-Osiris 2016. Ransomware Affiliations with Dridex and Necurs botnets
Locky (Decryptor) ransomware
Locky is a widely-known ransomware family that encrypts files on the victim's system, demanding a ransom payment for decryption.
Locky Loader loader
For the lack of a better name, this is a VBS-based loader that was used in beginning of 2018 to deliver win.locky.
Loda spywareratkeylogger
Also known as LodaRAT, Nymeria. Loda is a previously undocumented AutoIT malware with a variety of capabilities for spying on victims.
Loerbas loader
Loader and Cleaner components used in attacks against high-performance computing centers in Europe.
Lofy trojan
Also known as LofyLife. Lofy, also known as LofyLife, is a trojan malware typically used for credential-stealing attacks.
Log Collector
LogPOS credential-stealer
LogPOS is a type of malware designed to target point-of-sale systems in order to steal credit card information.
Logedrut rat
Logedrut is a Remote Access Trojan (RAT) known for its use in cyber espionage campaigns.
Logtu trojan
Logtu is a trojan malware that is commonly used to facilitate unauthorized access to infected systems by threat actors.
Loki ransomware
Loki is a ransomware that encrypts victims' files and demands a ransom for their decryption.
Loki Password Stealer (PWS) credential-stealerkeyloggertrojan
Also known as Burkina, Loki, LokiBot. "Loki Bot is a commodity malware sold on underground sites which is designed to steal private data from infected machines, and then submit…
Loki RAT rat
This RAT written in Python is an open-source fork of the Ares RAT.
LokiTech credential-stealerkeylogger
LokiTech is an information-stealing malware family known for targeting sensitive data such as credentials from infected systems.
Lokibot credential-stealerbackdoor
Lokibot is a widely distributed information stealer that was first reported in 2015.
Lokorrito trojan
According to ESET, this is a banking trojan that was active mainly in Mexico until the beginning of 2020, with builds for Brazil, Chile…
LolKek ransomware
LolKek is a ransomware family known for encrypting files on infected systems and demanding a ransom for the decryption key.
Lolnek credential-stealertrojan
Lolnek is a credential-stealing malware known for targeting financial services to harvest sensitive information.
Lomix Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
LongTermMemoryLoss ransomware
LongTermMemoryLoss is a ransomware family known for encrypting victim files and demanding a ransom payment to restore access.
LonleyCrypt ransomware
LonleyCrypt is a type of ransomware that encrypts files on infected systems, demanding a ransom payment in exchange for the decryption key.
LooCipher ransomware
LooCipher is a type of ransomware that encrypts victims' files and demands a ransom in cryptocurrency for decryption keys.
LookBack rat
LookBack is a remote access trojan written in C++ that was used against at least three US utility companies in July 2019.
Lootwodniw ratspyware
Lootwodniw is a remote access Trojan (RAT) primarily targeting financial services and government sectors.
LordOfShadow ransomware
LordOfShadow is a type of ransomware that encrypts victims’ files and demands a ransom for their decryption.
Lorenz Ransomware ransomware
Lorenz is a ransomware group that has been active since at least February 2021 and like many ransomware groups, performs double-extortion…
Lortok ransomware
Lortok is a ransomware known for encrypting files on compromised systems, targeting industries such as healthcare and financial services.
Losers ransomware
Losers is a type of ransomware that encrypts files on affected systems, demanding a ransom for decryption keys.
Losers-Dangerous ransomware
Losers-Dangerous is a ransomware variant that encrypts files and demands payment for decryption.
Lost Door rat
Also known as LostDoor. Unlike most attack tools that one can only find in cybercriminal underground markets, Lost Door is very easy to obtain.
Lost_Files ransomware
Lost_Files is a type of ransomware that encrypts the victim's data, demanding a ransom for decryption.
LoudMiner cryptominer
LoudMiner is a cryptocurrency miner which uses virtualization software to siphon system resources.
Loup trojan
Frank Boldewin describes Loup as a small cli-tool to cash out NCR devices (ATM).
LoupeLoader loader
LoupeLoader is a malicious software recognized for its capability to load additional payloads onto compromised systems.
LoveLock Ransomware or Love2Lock Ransomware ransomware
Also known as LoveLock, Love2Lock. It’s directed to English speaking users, therefore is able to infect worldwide.
LoveServer Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
LowLevel04 ransomware
LowLevel04 is a ransomware variant that modifies system files by prepending filenames.
Lslsass credential-stealer
Lslsass is a publicly-available tool that can dump active logon session password hashes from the lsass process.
Lu0Bot spyware
According to PCrisk, Lu0bot es un software malicioso.
LuaDream rat
Also known as DreamLand. LuaDream, also known as DreamLand, is a Remote Access Trojan (RAT) primarily used for cyber espionage.
Luca Stealer credential-stealerscreen-capturespyware
According to PCRisk, The Luca stealer can extract a variety of information from compromised machines.
Lucifer cryptominerddosworm
Lucifer is a crypto miner and DDoS hybrid malware that leverages well-known exploits to spread laterally on Windows platforms.
LuciferCrypt ransomware
LuciferCrypt is a ransomware known for encrypting files and demanding ransom payments for decryption.
Lucky Ransomware ransomware
Michael Gillespie discovered a new ransomware that renamed encrypted files to "[[email]][original].[random].lucky" and drops a ransom note…
LuckyCat rat
LuckyCat is a remote access tool (RAT) used for cyber espionage, targeting various sectors such as government, education, and technology.
LuckyJoe ransomware
LuckyJoe is a ransomware strain known for encrypting files and demanding ransoms from its victims, often targeting financial services…
Lucy ransomware
Lucy is a ransomware family known for encrypting files on infected machines and demanding a ransom for decryption.
Lumar credential-stealerspyware
Also known as PovertyStealer. This family was previously tracked as PovertyStealer until it's actual name was identified via crime forums.
Luminosity Link ratkeyloggerscreen-capture
Luminosity Link is a remote access trojan (RAT) that enables attackers to control infected systems, steal credentials, record keystrokes…
Luminosity RAT rat
Also known as LuminosityLink. Luminosity RAT, also known as LuminosityLink, is a remote access trojan that allows attackers to take control over a user's computer.
Lumma Stealer credential-stealerspyware
Also known as LummaStealer, LummaC2 Stealer. Lumma Stealer is an information stealer malware family in use since at least 2022.
Luna ransomware
Luna is a ransomware targeting ESXi servers, written in Rust programming language.
Luna Grabber credential-stealerkeylogger
Luna Grabber is a credential-stealing malware known for its keylogging capabilities.
Luna Ransomware ransomware
Luna Ransomware is a type of ransomware known for encrypting user files and demanding a ransom for decryption.
LunaSpy backdoorspyware
Also known as Backdoor.916. LunaSpy is a sophisticated malware primarily used for cyber espionage.
LunarLoader loader
LunarLoader is the loader component for the LunarWeb and LunarMail backdoors that has been used by Turla since at least 2020 including…
LunarMail backdoor
LunarMail is a backdoor that has been used by Turla since at least 2020 including in a compromise of a European ministry of foreign…
LunarWeb backdoor
LunarWeb is a backdoor that has been used by Turla since at least 2020 including in a compromise of a European ministry of foreign affairs…
LunchMoney spyware
LunchMoney is malicious software designed to exfiltrate files to Dropbox.
Lurid ratspyware
Also known as Enfal. Lurid is a malware family that has been used by several groups, including PittyTiger, in targeted attacks as far back as 2006.
Lurk botnettrojan
Lurk is a sophisticated botnet trojan known primarily for targeting financial institutions in Russia.
LuxNET rat
Just saying that this is a very badly coded RAT by the biggest skid in this world, that is XilluX.
Luxnut ransomware
Luxnut is a type of ransomware that encrypts victims' files and demands a ransom payment for decryption.
Luxy ransomware
Luxy is a type of ransomware known for encrypting the victim's data and demanding a ransom for decryption.
Luzo
Luzo is a malware that currently lacks a detailed public description.
Lv
Lv is a malware for which detailed characteristics and behaviors have not yet been fully described.
Lyceum .NET DNS Backdoor backdoorscreen-capture
This .NET written malware is used as backdoor using the dns protocol by a state sponsored threat actor.
Lyceum .NET TCP Backdoor backdoorscreen-capture
This .Net written malware is used as backdoor using the http protocol by a state sponsored threat actor.
Lyceum Golang HTTP Backdoor backdoor
This Golang written malware is used as backdoor using the http protocol by a state sponsored threat actor (TA).
Lyposit ransomware
Also known as Adneukine, Bomba Locker, Lucky Locker. Lyposit, also known as Adneukine, Bomba Locker, and Lucky Locker, is a ransomware family known for encrypting files and demanding ransoms…
M00nD3V Logger credential-stealerkeyloggerspyware
According Zscaler, M00nD3V Logger has the ability to steal confidential information, such as browser passwords, FTP client passwords…
M4N1F3STO ransomware
Ransomware Does not encrypt Unlock code=suckmydicknigga
M4N1F3STO Ransomware (FAKE!!!!!)
It’s directed to English speaking users, therefore is able to infect worldwide.
M@r1a ransomware ransomware
Also known as M@r1a, BlackHeart. M@r1a ransomware, also known as BlackHeart, is a type of ransomware that encrypts files on victim systems and demands a ransom for…
MACAMAX rat
MACAMAX is a sophisticated remote access trojan (RAT) primarily used in cyber-espionage campaigns targeting governmental and technological…
MAFIA Ransomware ransomware
Also known as Mafia. The ransomware appears to target users in Korea, and may have been developed with at least knowledge of the Korean language.
MAGASKOSH rat
MAGASKOSH is a sophisticated Remote Access Trojan (RAT) typically employed in cyber-espionage campaigns.
MAILCREEP backdoor
According to Zscaler, MAILCREEP is a Golang-based backdoor leveraging the Microsoft Graph API for its C2 communications.
MAPIget trojancredential-stealer
MAPIget is a trojan primarily aimed at stealing credentials through email exfiltration tactics.
MASEPIE trojan
MASEPIE is a trojan malware known for targeting government and healthcare sectors.
MASOL backdoorrat
MASOL is a remote access tool primarily used for espionage activities.
MASS Logger credential-stealerkeyloggerloader
MassLogger is a .NET credential stealer. It starts with a launcher that uses simple anti-debugging techniques which can be easily bypassed…
MAYBEROBOT rat
Also known as SIMPLEFIX. MAYBEROBOT, also known as SIMPLEFIX, is a remote access trojan used primarily for cyber espionage.
MBR Locker ransomwarewiper
Ransomware overwriting the system's MBR, making it impossible to boot into Windows.
MBR-ONI ransomwarewiper
MBR-ONI is a ransomware variant that has been used in cyber-attacks targeting local governments in Japan.
MBRlock ransomware
Also known as DexLocker. This ransomware modifies the master boot record of the victim's computer so that it shows a ransom note before Windows starts.
MC Ransomware ransomware
Supposed joke ransomware, decrypt when running an exectable with the string "Minecraft"
MCMD rat
MCMD is a remote access tool that provides remote command shell capability used by Dragonfly.
MECHANICAL trojanransomware
Also known as GoldStamp. MECHANICAL, also known as GoldStamp, is a sophisticated malware family primarily targeting the government and financial sectors.
MEDUSA rootkit
MEDUSA is an open-source rootkit that is capable of dynamic linker hijacking, command execution, and logging credentials.
MESSAGETAP spyware
MESSAGETAP is a data mining malware family deployed by APT41 into telecommunications networks to monitor and save SMS traffic from…
METALJACK rat
Also known as denesRAT. METALJACK, also known as denesRAT, is a Remote Access Trojan that primarily targets organizations in the financial, governmental, and…
MILKMAID wiper
MILKMAID is a destructive wiper malware used in targeted cyber attacks primarily against government and energy sectors.
MINEBRIDGE backdoor
Also known as GazGolder. MINEBRIDGE is a backdoor malware primarily distributed as part of spear-phishing campaigns targeting businesses in the financial and…
MINI-MO ransomware
MINI-MO is a ransomware malware known for targeting the government and defense sectors.
MINIBIKE backdoor
According to Mandiant, this is a custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance…