Malware Families page 3 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- AndroMut downloader
- Also known as Gelup. According to Proofpoint, AndroMut is a new downloader malware written in C++ that Proofpoint researchers began observing in the wild in…
- AndroRAT ratspyware
- AndroRAT is an open-source remote access tool for Android devices.
- Android/AdDisplay.Ashas spywaretrojan
- Android/AdDisplay.Ashas is a variant of adware that has been distributed through multiple apps in the Google Play Store.
- Android/Chuli.A spywaretrojan
- Android/Chuli.A is Android malware that was delivered to activist groups via a spearphishing email with an attachment.
- Android/SpyAgent spyware
- Android/SpyAgent is a variant of spyware in the MoqHao phishing campaign primarily targeting Korean and Japanese users.
- AndroidOS/MalLocker.B ransomware
- AndroidOS/MalLocker.B is a variant of a ransomware family targeting Android devices.
- AndroxGh0st credential-stealerwebshell
- Also known as Androx, AndroxGhost. According to Laceworks, this is a SMTP cracker, which is primarily intended to scan for and parse Laravel application secrets from exposed…
- Angela Merkel Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- AngleWare ransomware
- AngleWare is a type of ransomware that encrypts a victim's files and demands a ransom for the decryption key.
- AngryDuck Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- AngryKite ransomware
- AngryKite is a type of ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
- Ani-Shell webshell
- Also known as anishell. Ani-Shell is a simple PHP shell with some unique features like Mass Mailer, a simple Web-Server Fuzzer, Dosser, Back Connect, Bind Shell…
- AnimusLocker ransomware
- AnimusLocker is a ransomware family known for encrypting files and demanding payment for decryption keys.
- Annabelle ransomware
- Annabelle is a ransomware that encrypts files on the victim's computer and demands a ransom for decryption.
- Annabelle 2.1 ransomware
- Annabelle 2.1 is a variant of ransomware that encrypts files on the victim's system and demands a ransom for decryption.
- AnonCrack ransomware
- AnonCrack is ransomware that encrypts victims' data and demands a ransom for decryption.
- AnonPop ransomware
- AnonPop is a ransomware strain known for encrypting files and demanding a ransom.
- Anony ransomware
- Also known as ngocanh. Anony is a ransomware variant based on the HiddenTear project.
- AnteFrigus ransomware
- AnteFrigus is a ransomware strain primarily targeting sectors with dominant financial transactions, such as financial services and retail.
- Anti-DDos ransomware
- Anti-DDos is a type of ransomware designed to encrypt files and demand payment for decryption.
- Antidot credential-stealerkeyloggertrojan
- The malware displays fake Google Play update pages in multiple languages, including German, French, Spanish, Russian, Portuguese…
- Antihacker2017 ransomware
- Antihacker2017 is a ransomware strain observed in 2017, known for encrypting users' data and demanding a ransom for decryption.
- Antihacker2017 Ransomware ransomware
- It’s directed to Russian speaking users, there fore is able to infect mosty the old USSR countries.
- Antilam ransomware
- Also known as Latinus. Antilam, also known as Latinus, is a ransomware family known for targeting critical industries such as financial services and government…
- Antix Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Anubi NotBTCWare ransomware
- Anubi NotBTCWare is a type of ransomware known for encrypting files on infected systems and demanding a cryptocurrency ransom for…
- Anubis trojan
- Anubis is Android malware that was originally used for cyber espionage, and has been retooled as a banking trojan.
- Anubis (Android) credential-stealerkeyloggerransomware
- Also known as BankBot, android.bankbot, android.bankspy. BleepingComputer found that Anubis will display fake phishing login forms when users open up apps for targeted platforms to steal…
- Anubis (Windows) credential-stealerkeylogger
- Also known as Anubis Stealer. According to Microsoft Security Intelligence, Anubis is an information stealer sold on underground forums since June 2020.
- Anubis Backdoor backdoor
- According to Prodaft, this is a Python-based backdoor used by the Savage Ladybug (FIN7) group is developed to provide remote access…
- Anubis Loader loader
- Also known as Kraken, Pepega. A loader written in Go, tracked since at least October 2021 by ZeroFox.
- Anubis Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- AnubisSpy spywarerat
- AnubisSpy is an advanced spyware and RAT primarily targeting Android devices in the Middle East.
- AnyDesk
- AnyDesk is a remote desktop program that you can run portably or install like a regular program.
- Apocalipto wiper
- Apocalipto is a type of wiper malware known for its destructive capabilities, erasing data on infected systems.
- Apocalypse ransomware
- Also known as Fabiansomeware. Ransomware [email protected] [email protected] [email protected] [email protected] [email protected]
- Apocalypse-Missing ransomware
- Apocalypse-Missing is a ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
- ApocalypseVM ransomware
- Ransomware Apocalypse ransomware version which uses VMprotect
- Apollo rat
- This is an implant usable with the Mythic C2 framework.
- ApolloLocker ransomware
- ApolloLocker is a ransomware strain that encrypts files on infected systems, demanding a ransom for decryption.
- ApolloShadow spyware
- According to Microsoft, ApolloShadow has the capability to install a trusted root certificate to trick devices into trusting malicious…
- Apostle wiperransomware
- Apostle is malware that has functioned as both a wiper and, in more recent versions, as ransomware.
- AppleJeus downloaderrattrojan
- AppleJeus is a family of downloaders initially discovered in 2018 embedded within trojanized cryptocurrency applications.
- AppleJeus (OS X) backdoor
- According to PcRisk AppleJeus is the name of backdoor malware that was distributed by the Lazarus group.
- AppleJeus (Windows) trojan
- AppleJeus is a sophisticated trojan attributed to North Korean actors, primarily targeting cryptocurrency exchanges and financial services.
- AppleSeed backdoor
- Also known as JamBog. AppleSeed is a backdoor that has been used by Kimsuky to target South Korean government, academic, and commercial targets since at least…
- Arabian-Attacker RAT rat
- Arabian-Attacker RAT is a remote access tool targeting organizations primarily in the Middle East, including government and financial…
- ArcaneStealer credential-stealer
- ArcaneStealer is a type of malware that focuses on stealing sensitive information like passwords, browser data, and cryptocurrency wallet…
- Archelaus Beta rat
- Archelaus Beta is a remote access tool (RAT) used for espionage activities primarily targeting government and defense sectors.
- Archer RAT rat
- Also known as RustyWater. Archer RAT, also known as RustyWater, is a sophisticated Remote Access Trojan used primarily for cyber-espionage.
- Archivist ransomware
- Archivist is a ransomware family known for encrypting files and demanding a ransom for their decryption.
- Arcom rat
- The malware is a Remote Access Trojan (RAT), known as Arcom RAT, and it is sold on underground forums for $2000.00.
- Arctic R.A.T. rat
- Also known as Artic. Arctic R.A.T. is a remote access trojan primarily used in cyber espionage campaigns. It has been employed by state-sponsored threat actors…
- ArdaMax keyloggerscreen-capturespyware
- According to f-secure, Ardamax is a commercial keylogger program that can be installed onto the system from the product's website.& When…
- Arefty trojan
- Arefty is a banking trojan known for targeting financial institutions and public sector organizations.
- Ares (Python) rat
- Ares is a Remote Access Trojan (RAT) written in Python.
- Ares (Windows) trojancredential-stealer
- A banking trojan, derived from the source code of win.kronos.
- AresLoader downloaderloader
- AresLoader is a new malware "downloader" that has been advertised on some Russian language Dark Web forums “RAMP and "XSS" by a threat…
- ArguePatch loaderwiper
- During a campaign against a Ukrainian energy provider, a new loader of a new version of CaddyWiper called "ArguePatch" was observed by…
- Argus ransomware
- Argus ransomware is known for encrypting files on victim systems and demanding a ransom for decryption, targeting multiple sectors with…
- Aria-body backdoor
- Aria-body is a custom backdoor that has been used by Naikon since approximately 2017.
- Arid Gopher ratspyware
- This malware is a Go written variant of Micropsia and according to DeepInstinct it is still in development.
- AridHelper trojan
- Helper malware associated with AridGopher, which will provide an alternative persistence mechanism in case "360 total security" is found…
- Arik Keylogger keyloggercredential-stealer
- Also known as Aaron Keylogger. Arik Keylogger, also known as Aaron Keylogger, is malware designed to capture keystrokes and steal credentials from infected systems.
- Aris Locker ransomware
- Aris Locker is a type of ransomware that encrypts files on infected systems, demanding a ransom for decryption keys.
- Arkei Stealer credential-stealerspyware
- Also known as ArkeiStealer. Arkei is a stealer that appeared around May 2018.
- ArmaLocky ransomware
- ArmaLocky is a type of ransomware that encrypts files on a victim's system and demands a ransom for decryption.
- Armage ransomware
- Armage is a type of ransomware that encrypts files on the victim's computer and demands a ransom for decryption.
- Armageddon ransomware
- Armageddon is a ransomware strain used in cyber attacks to encrypt data on victim systems, demanding a ransom for decryption.
- Arp
- Also known as arp.exe. Arp displays and modifies information about a system's Address Resolution Protocol (ARP) cache.
- ArrowRAT rat
- It is available as a service, purchasable by anyone to use in their own campaigns.
- Arsium ransomware
- Arsium is a type of ransomware known for encrypting files on the infected system and demanding a cryptocurrency ransom for decryption.
- Artra Downloader downloader
- Artra Downloader is a malware family designed to silently download and install additional malicious payloads onto an infected system.
- Arvinclub ransomware
- Also known as Arvin Club. Arvin Club is a popular Ransomware group with a widespread Telegram presence, which includes personal group chats, and official channels.
- Asacub trojan
- Also known as Trojan-SMS.AndroidOS.Smaps. Asacub is a banking trojan that attempts to steal money from victims’ bank accounts.
- Asbit trojan
- Asbit is a malware family primarily focused on targeting financial institutions and public sector organizations.
- AscentLoader loader
- AscentLoader is a type of malware commonly used to load additional malicious payloads onto compromised systems.
- AshTag backdoor
- AshTag is a modular .NET backdoor with multiple features that has been used by WIRTE since at least 2025.
- Ashas backdoorrat
- Ashas is a remote access trojan used by cyber espionage groups to target energy and government sectors, primarily in the United States and…
- Ashen backdoortrojan
- Also known as AshTag. According to Unit 42, Ashen / AshTag is a modular .NET toolset currently in active development, with extensive features, including file…
- Asprox botnetcredential-stealerdownloader
- Also known as Aseljo, BadSrc. Asprox is a botnet family known for its ability to carry out automated attacks on web applications, predominantly to steal credentials and…
- Asruex trojanloader
- Asruex is a trojan known for utilizing code injection techniques, often acting as a loader to further distribute other malicious payloads.
- Assassin rat
- Assassin is a remote access tool (RAT) used primarily for cyber espionage.
- Assembly ransomware
- Assembly is a ransomware that encrypts files on a victim's system, demanding a ransom for decryption.
- AstarionRAT ratcredential-stealer
- Also known as MIMICRAT. According to Huntress, AstarionRAT is a full-featured RAT with 24 commands, including credential theft, SOCKS5 proxy, port scanning…
- Astaroth trojancredential-stealer
- Also known as Guildma. Astaroth is a Trojan and information stealer known to affect companies in Europe, Brazil, and throughout Latin America.
- Astasia trojancredential-stealer
- Astasia is a banking trojan that spreads through phishing emails that contain an executable attachment.
- Astro Locker ransomware
- Ransomware
- AsyncRAT rat
- AsyncRAT is an open-source remote access tool originally available through the NYANxCAT Github repository that has been used in malicious…
- Ataware ransomware
- Ataware is a ransomware known for encrypting user data and demanding a ransom for decryption.
- Atchbo ransomware
- Atchbo is a type of ransomware known for encrypting a victim's files and demanding a ransom for decryption.
- Atelier Web Remote Commander ratscreen-capture
- Atelier Web Remote Commander is a remote access tool (RAT) that allows users to gain control over other systems for administrative purposes.
- Atharvan rat
- Atharvan is a remote access tool primarily used for cyber espionage, targeting government and defense sectors.
- Athena backdoorrat
- Part of the Mythic framework, payload in C# (.NET 6), support HTTP, Websockets, Slack, SMB for C2.
- AthenaGo RAT rat
- AthenaGo RAT is a remote access trojan used for cyber espionage, primarily targeting sensitive sectors.
- Atlantida
- Atlantida is a piece of malware with limited information available.
- Atlas RAT backdoorratloader
- According to Proofpoint, Atlas RAT is a modular backdoor used by the TA4922 actor, delivered in multiple stages with a core module and…
- AtlasAgent rat
- AtlasAgent is a remote access tool (RAT) used primarily for espionage purposes.
- Atmosphere trojan
- Atmosphere is a banking trojan known for targeting financial institutions.
- Atomsilo ransomware
- AtomSilo is a new Ransomware recently seen in September 2021 during one of their attacks by exploiting a recently revealed vulnerability…