Malware Families page 29 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Locker-Pay ransomware
- Locker-Pay is a ransomware strain known for encrypting victims' files and demanding payment in cryptocurrency.
- LockerGoga ransomware
- LockerGoga is ransomware that was first reported in January 2019, and has been tied to various attacks on European companies, including…
- Lockify ransomware
- Lockify is a ransomware known for encrypting files on infected systems and demanding payment for decryption keys.
- Lockout ransomware
- Lockout is a type of ransomware that encrypts files on infected systems, demanding payment for decryption keys.
- Locky ransomware
- Also known as Locky-Odin, Locky-Osiris, Locky-Osiris 2016. Ransomware Affiliations with Dridex and Necurs botnets
- Locky (Decryptor) ransomware
- Locky is a widely-known ransomware family that encrypts files on the victim's system, demanding a ransom payment for decryption.
- Locky Loader loader
- For the lack of a better name, this is a VBS-based loader that was used in beginning of 2018 to deliver win.locky.
- Loda spywareratkeylogger
- Also known as LodaRAT, Nymeria. Loda is a previously undocumented AutoIT malware with a variety of capabilities for spying on victims.
- Loerbas loader
- Loader and Cleaner components used in attacks against high-performance computing centers in Europe.
- Lofy trojan
- Also known as LofyLife. Lofy, also known as LofyLife, is a trojan malware typically used for credential-stealing attacks.
- Log Collector
- LogPOS credential-stealer
- LogPOS is a type of malware designed to target point-of-sale systems in order to steal credit card information.
- Logedrut rat
- Logedrut is a Remote Access Trojan (RAT) known for its use in cyber espionage campaigns.
- Logtu trojan
- Logtu is a trojan malware that is commonly used to facilitate unauthorized access to infected systems by threat actors.
- Loki ransomware
- Loki is a ransomware that encrypts victims' files and demands a ransom for their decryption.
- Loki Password Stealer (PWS) credential-stealerkeyloggertrojan
- Also known as Burkina, Loki, LokiBot. "Loki Bot is a commodity malware sold on underground sites which is designed to steal private data from infected machines, and then submit…
- Loki RAT rat
- This RAT written in Python is an open-source fork of the Ares RAT.
- LokiTech credential-stealerkeylogger
- LokiTech is an information-stealing malware family known for targeting sensitive data such as credentials from infected systems.
- Lokibot credential-stealerbackdoor
- Lokibot is a widely distributed information stealer that was first reported in 2015.
- Lokorrito trojan
- According to ESET, this is a banking trojan that was active mainly in Mexico until the beginning of 2020, with builds for Brazil, Chile…
- LolKek ransomware
- LolKek is a ransomware family known for encrypting files on infected systems and demanding a ransom for the decryption key.
- Lolnek credential-stealertrojan
- Lolnek is a credential-stealing malware known for targeting financial services to harvest sensitive information.
- Lomix Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- LongTermMemoryLoss ransomware
- LongTermMemoryLoss is a ransomware family known for encrypting victim files and demanding a ransom payment to restore access.
- LonleyCrypt ransomware
- LonleyCrypt is a type of ransomware that encrypts files on infected systems, demanding a ransom payment in exchange for the decryption key.
- LooCipher ransomware
- LooCipher is a type of ransomware that encrypts victims' files and demands a ransom in cryptocurrency for decryption keys.
- LookBack rat
- LookBack is a remote access trojan written in C++ that was used against at least three US utility companies in July 2019.
- Lootwodniw ratspyware
- Lootwodniw is a remote access Trojan (RAT) primarily targeting financial services and government sectors.
- LordOfShadow ransomware
- LordOfShadow is a type of ransomware that encrypts victims’ files and demands a ransom for their decryption.
- Lorenz Ransomware ransomware
- Lorenz is a ransomware group that has been active since at least February 2021 and like many ransomware groups, performs double-extortion…
- Lortok ransomware
- Lortok is a ransomware known for encrypting files on compromised systems, targeting industries such as healthcare and financial services.
- Losers ransomware
- Losers is a type of ransomware that encrypts files on affected systems, demanding a ransom for decryption keys.
- Losers-Dangerous ransomware
- Losers-Dangerous is a ransomware variant that encrypts files and demands payment for decryption.
- Lost Door rat
- Also known as LostDoor. Unlike most attack tools that one can only find in cybercriminal underground markets, Lost Door is very easy to obtain.
- Lost_Files ransomware
- Lost_Files is a type of ransomware that encrypts the victim's data, demanding a ransom for decryption.
- LoudMiner cryptominer
- LoudMiner is a cryptocurrency miner which uses virtualization software to siphon system resources.
- Loup trojan
- Frank Boldewin describes Loup as a small cli-tool to cash out NCR devices (ATM).
- LoupeLoader loader
- LoupeLoader is a malicious software recognized for its capability to load additional payloads onto compromised systems.
- LoveLock Ransomware or Love2Lock Ransomware ransomware
- Also known as LoveLock, Love2Lock. It’s directed to English speaking users, therefore is able to infect worldwide.
- LoveServer Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- LowLevel04 ransomware
- LowLevel04 is a ransomware variant that modifies system files by prepending filenames.
- Lslsass credential-stealer
- Lslsass is a publicly-available tool that can dump active logon session password hashes from the lsass process.
- Lu0Bot spyware
- According to PCrisk, Lu0bot es un software malicioso.
- LuaDream rat
- Also known as DreamLand. LuaDream, also known as DreamLand, is a Remote Access Trojan (RAT) primarily used for cyber espionage.
- Luca Stealer credential-stealerscreen-capturespyware
- According to PCRisk, The Luca stealer can extract a variety of information from compromised machines.
- Lucifer cryptominerddosworm
- Lucifer is a crypto miner and DDoS hybrid malware that leverages well-known exploits to spread laterally on Windows platforms.
- LuciferCrypt ransomware
- LuciferCrypt is a ransomware known for encrypting files and demanding ransom payments for decryption.
- Lucky Ransomware ransomware
- Michael Gillespie discovered a new ransomware that renamed encrypted files to "[[email]][original].[random].lucky" and drops a ransom note…
- LuckyCat rat
- LuckyCat is a remote access tool (RAT) used for cyber espionage, targeting various sectors such as government, education, and technology.
- LuckyJoe ransomware
- LuckyJoe is a ransomware strain known for encrypting files and demanding ransoms from its victims, often targeting financial services…
- Lucy ransomware
- Lucy is a ransomware family known for encrypting files on infected machines and demanding a ransom for decryption.
- Lumar credential-stealerspyware
- Also known as PovertyStealer. This family was previously tracked as PovertyStealer until it's actual name was identified via crime forums.
- Luminosity Link ratkeyloggerscreen-capture
- Luminosity Link is a remote access trojan (RAT) that enables attackers to control infected systems, steal credentials, record keystrokes…
- Luminosity RAT rat
- Also known as LuminosityLink. Luminosity RAT, also known as LuminosityLink, is a remote access trojan that allows attackers to take control over a user's computer.
- Lumma Stealer credential-stealerspyware
- Also known as LummaStealer, LummaC2 Stealer. Lumma Stealer is an information stealer malware family in use since at least 2022.
- Luna ransomware
- Luna is a ransomware targeting ESXi servers, written in Rust programming language.
- Luna Grabber credential-stealerkeylogger
- Luna Grabber is a credential-stealing malware known for its keylogging capabilities.
- Luna Ransomware ransomware
- Luna Ransomware is a type of ransomware known for encrypting user files and demanding a ransom for decryption.
- LunaSpy backdoorspyware
- Also known as Backdoor.916. LunaSpy is a sophisticated malware primarily used for cyber espionage.
- LunarLoader loader
- LunarLoader is the loader component for the LunarWeb and LunarMail backdoors that has been used by Turla since at least 2020 including…
- LunarMail backdoor
- LunarMail is a backdoor that has been used by Turla since at least 2020 including in a compromise of a European ministry of foreign…
- LunarWeb backdoor
- LunarWeb is a backdoor that has been used by Turla since at least 2020 including in a compromise of a European ministry of foreign affairs…
- LunchMoney spyware
- LunchMoney is malicious software designed to exfiltrate files to Dropbox.
- Lurid ratspyware
- Also known as Enfal. Lurid is a malware family that has been used by several groups, including PittyTiger, in targeted attacks as far back as 2006.
- Lurk botnettrojan
- Lurk is a sophisticated botnet trojan known primarily for targeting financial institutions in Russia.
- LuxNET rat
- Just saying that this is a very badly coded RAT by the biggest skid in this world, that is XilluX.
- Luxnut ransomware
- Luxnut is a type of ransomware that encrypts victims' files and demands a ransom payment for decryption.
- Luxy ransomware
- Luxy is a type of ransomware known for encrypting the victim's data and demanding a ransom for decryption.
- Luzo
- Luzo is a malware that currently lacks a detailed public description.
- Lv
- Lv is a malware for which detailed characteristics and behaviors have not yet been fully described.
- Lyceum .NET DNS Backdoor backdoorscreen-capture
- This .NET written malware is used as backdoor using the dns protocol by a state sponsored threat actor.
- Lyceum .NET TCP Backdoor backdoorscreen-capture
- This .Net written malware is used as backdoor using the http protocol by a state sponsored threat actor.
- Lyceum Golang HTTP Backdoor backdoor
- This Golang written malware is used as backdoor using the http protocol by a state sponsored threat actor (TA).
- Lyposit ransomware
- Also known as Adneukine, Bomba Locker, Lucky Locker. Lyposit, also known as Adneukine, Bomba Locker, and Lucky Locker, is a ransomware family known for encrypting files and demanding ransoms…
- M00nD3V Logger credential-stealerkeyloggerspyware
- According Zscaler, M00nD3V Logger has the ability to steal confidential information, such as browser passwords, FTP client passwords…
- M4N1F3STO ransomware
- Ransomware Does not encrypt Unlock code=suckmydicknigga
- M4N1F3STO Ransomware (FAKE!!!!!)
- It’s directed to English speaking users, therefore is able to infect worldwide.
- M@r1a ransomware ransomware
- Also known as M@r1a, BlackHeart. M@r1a ransomware, also known as BlackHeart, is a type of ransomware that encrypts files on victim systems and demands a ransom for…
- MACAMAX rat
- MACAMAX is a sophisticated remote access trojan (RAT) primarily used in cyber-espionage campaigns targeting governmental and technological…
- MAFIA Ransomware ransomware
- Also known as Mafia. The ransomware appears to target users in Korea, and may have been developed with at least knowledge of the Korean language.
- MAGASKOSH rat
- MAGASKOSH is a sophisticated Remote Access Trojan (RAT) typically employed in cyber-espionage campaigns.
- MAILCREEP backdoor
- According to Zscaler, MAILCREEP is a Golang-based backdoor leveraging the Microsoft Graph API for its C2 communications.
- MAPIget trojancredential-stealer
- MAPIget is a trojan primarily aimed at stealing credentials through email exfiltration tactics.
- MASEPIE trojan
- MASEPIE is a trojan malware known for targeting government and healthcare sectors.
- MASOL backdoorrat
- MASOL is a remote access tool primarily used for espionage activities.
- MASS Logger credential-stealerkeyloggerloader
- MassLogger is a .NET credential stealer. It starts with a launcher that uses simple anti-debugging techniques which can be easily bypassed…
- MAYBEROBOT rat
- Also known as SIMPLEFIX. MAYBEROBOT, also known as SIMPLEFIX, is a remote access trojan used primarily for cyber espionage.
- MBR Locker ransomwarewiper
- Ransomware overwriting the system's MBR, making it impossible to boot into Windows.
- MBR-ONI ransomwarewiper
- MBR-ONI is a ransomware variant that has been used in cyber-attacks targeting local governments in Japan.
- MBRlock ransomware
- Also known as DexLocker. This ransomware modifies the master boot record of the victim's computer so that it shows a ransom note before Windows starts.
- MC Ransomware ransomware
- Supposed joke ransomware, decrypt when running an exectable with the string "Minecraft"
- MCMD rat
- MCMD is a remote access tool that provides remote command shell capability used by Dragonfly.
- MECHANICAL trojanransomware
- Also known as GoldStamp. MECHANICAL, also known as GoldStamp, is a sophisticated malware family primarily targeting the government and financial sectors.
- MEDUSA rootkit
- MEDUSA is an open-source rootkit that is capable of dynamic linker hijacking, command execution, and logging credentials.
- MESSAGETAP spyware
- MESSAGETAP is a data mining malware family deployed by APT41 into telecommunications networks to monitor and save SMS traffic from…
- METALJACK rat
- Also known as denesRAT. METALJACK, also known as denesRAT, is a Remote Access Trojan that primarily targets organizations in the financial, governmental, and…
- MILKMAID wiper
- MILKMAID is a destructive wiper malware used in targeted cyber attacks primarily against government and energy sectors.
- MINEBRIDGE backdoor
- Also known as GazGolder. MINEBRIDGE is a backdoor malware primarily distributed as part of spear-phishing campaigns targeting businesses in the financial and…
- MINI-MO ransomware
- MINI-MO is a ransomware malware known for targeting the government and defense sectors.
- MINIBIKE backdoor
- According to Mandiant, this is a custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance…