Malware Families page 3 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

AndroMut downloader
Also known as Gelup. According to Proofpoint, AndroMut is a new downloader malware written in C++ that Proofpoint researchers began observing in the wild in…
AndroRAT ratspyware
AndroRAT is an open-source remote access tool for Android devices.
Android/AdDisplay.Ashas spywaretrojan
Android/AdDisplay.Ashas is a variant of adware that has been distributed through multiple apps in the Google Play Store.
Android/Chuli.A spywaretrojan
Android/Chuli.A is Android malware that was delivered to activist groups via a spearphishing email with an attachment.
Android/SpyAgent spyware
Android/SpyAgent is a variant of spyware in the MoqHao phishing campaign primarily targeting Korean and Japanese users.
AndroidOS/MalLocker.B ransomware
AndroidOS/MalLocker.B is a variant of a ransomware family targeting Android devices.
AndroxGh0st credential-stealerwebshell
Also known as Androx, AndroxGhost. According to Laceworks, this is a SMTP cracker, which is primarily intended to scan for and parse Laravel application secrets from exposed…
Angela Merkel Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
AngleWare ransomware
AngleWare is a type of ransomware that encrypts a victim's files and demands a ransom for the decryption key.
AngryDuck Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
AngryKite ransomware
AngryKite is a type of ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
Ani-Shell webshell
Also known as anishell. Ani-Shell is a simple PHP shell with some unique features like Mass Mailer, a simple Web-Server Fuzzer, Dosser, Back Connect, Bind Shell…
AnimusLocker ransomware
AnimusLocker is a ransomware family known for encrypting files and demanding payment for decryption keys.
Annabelle ransomware
Annabelle is a ransomware that encrypts files on the victim's computer and demands a ransom for decryption.
Annabelle 2.1 ransomware
Annabelle 2.1 is a variant of ransomware that encrypts files on the victim's system and demands a ransom for decryption.
AnonCrack ransomware
AnonCrack is ransomware that encrypts victims' data and demands a ransom for decryption.
AnonPop ransomware
AnonPop is a ransomware strain known for encrypting files and demanding a ransom.
Anony ransomware
Also known as ngocanh. Anony is a ransomware variant based on the HiddenTear project.
AnteFrigus ransomware
AnteFrigus is a ransomware strain primarily targeting sectors with dominant financial transactions, such as financial services and retail.
Anti-DDos ransomware
Anti-DDos is a type of ransomware designed to encrypt files and demand payment for decryption.
Antidot credential-stealerkeyloggertrojan
The malware displays fake Google Play update pages in multiple languages, including German, French, Spanish, Russian, Portuguese…
Antihacker2017 ransomware
Antihacker2017 is a ransomware strain observed in 2017, known for encrypting users' data and demanding a ransom for decryption.
Antihacker2017 Ransomware ransomware
It’s directed to Russian speaking users, there fore is able to infect mosty the old USSR countries.
Antilam ransomware
Also known as Latinus. Antilam, also known as Latinus, is a ransomware family known for targeting critical industries such as financial services and government…
Antix Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Anubi NotBTCWare ransomware
Anubi NotBTCWare is a type of ransomware known for encrypting files on infected systems and demanding a cryptocurrency ransom for…
Anubis trojan
Anubis is Android malware that was originally used for cyber espionage, and has been retooled as a banking trojan.
Anubis (Android) credential-stealerkeyloggerransomware
Also known as BankBot, android.bankbot, android.bankspy. BleepingComputer found that Anubis will display fake phishing login forms when users open up apps for targeted platforms to steal…
Anubis (Windows) credential-stealerkeylogger
Also known as Anubis Stealer. According to Microsoft Security Intelligence, Anubis is an information stealer sold on underground forums since June 2020.
Anubis Backdoor backdoor
According to Prodaft, this is a Python-based backdoor used by the Savage Ladybug (FIN7) group is developed to provide remote access…
Anubis Loader loader
Also known as Kraken, Pepega. A loader written in Go, tracked since at least October 2021 by ZeroFox.
Anubis Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
AnubisSpy spywarerat
AnubisSpy is an advanced spyware and RAT primarily targeting Android devices in the Middle East.
AnyDesk
AnyDesk is a remote desktop program that you can run portably or install like a regular program.
Apocalipto wiper
Apocalipto is a type of wiper malware known for its destructive capabilities, erasing data on infected systems.
Apocalypse ransomware
Also known as Fabiansomeware. Ransomware [email protected] [email protected] [email protected] [email protected] [email protected]
Apocalypse-Missing ransomware
Apocalypse-Missing is a ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
ApocalypseVM ransomware
Ransomware Apocalypse ransomware version which uses VMprotect
Apollo rat
This is an implant usable with the Mythic C2 framework.
ApolloLocker ransomware
ApolloLocker is a ransomware strain that encrypts files on infected systems, demanding a ransom for decryption.
ApolloShadow spyware
According to Microsoft, ApolloShadow has the capability to install a trusted root certificate to trick devices into trusting malicious…
Apostle wiperransomware
Apostle is malware that has functioned as both a wiper and, in more recent versions, as ransomware.
AppleJeus downloaderrattrojan
AppleJeus is a family of downloaders initially discovered in 2018 embedded within trojanized cryptocurrency applications.
AppleJeus (OS X) backdoor
According to PcRisk AppleJeus is the name of backdoor malware that was distributed by the Lazarus group.
AppleJeus (Windows) trojan
AppleJeus is a sophisticated trojan attributed to North Korean actors, primarily targeting cryptocurrency exchanges and financial services.
AppleSeed backdoor
Also known as JamBog. AppleSeed is a backdoor that has been used by Kimsuky to target South Korean government, academic, and commercial targets since at least…
Arabian-Attacker RAT rat
Arabian-Attacker RAT is a remote access tool targeting organizations primarily in the Middle East, including government and financial…
ArcaneStealer credential-stealer
ArcaneStealer is a type of malware that focuses on stealing sensitive information like passwords, browser data, and cryptocurrency wallet…
Archelaus Beta rat
Archelaus Beta is a remote access tool (RAT) used for espionage activities primarily targeting government and defense sectors.
Archer RAT rat
Also known as RustyWater. Archer RAT, also known as RustyWater, is a sophisticated Remote Access Trojan used primarily for cyber-espionage.
Archivist ransomware
Archivist is a ransomware family known for encrypting files and demanding a ransom for their decryption.
Arcom rat
The malware is a Remote Access Trojan (RAT), known as Arcom RAT, and it is sold on underground forums for $2000.00.
Arctic R.A.T. rat
Also known as Artic. Arctic R.A.T. is a remote access trojan primarily used in cyber espionage campaigns. It has been employed by state-sponsored threat actors…
ArdaMax keyloggerscreen-capturespyware
According to f-secure, Ardamax is a commercial keylogger program that can be installed onto the system from the product's website.& When…
Arefty trojan
Arefty is a banking trojan known for targeting financial institutions and public sector organizations.
Ares (Python) rat
Ares is a Remote Access Trojan (RAT) written in Python.
Ares (Windows) trojancredential-stealer
A banking trojan, derived from the source code of win.kronos.
AresLoader downloaderloader
AresLoader is a new malware "downloader" that has been advertised on some Russian language Dark Web forums “RAMP and "XSS" by a threat…
ArguePatch loaderwiper
During a campaign against a Ukrainian energy provider, a new loader of a new version of CaddyWiper called "ArguePatch" was observed by…
Argus ransomware
Argus ransomware is known for encrypting files on victim systems and demanding a ransom for decryption, targeting multiple sectors with…
Aria-body backdoor
Aria-body is a custom backdoor that has been used by Naikon since approximately 2017.
Arid Gopher ratspyware
This malware is a Go written variant of Micropsia and according to DeepInstinct it is still in development.
AridHelper trojan
Helper malware associated with AridGopher, which will provide an alternative persistence mechanism in case "360 total security" is found…
Arik Keylogger keyloggercredential-stealer
Also known as Aaron Keylogger. Arik Keylogger, also known as Aaron Keylogger, is malware designed to capture keystrokes and steal credentials from infected systems.
Aris Locker ransomware
Aris Locker is a type of ransomware that encrypts files on infected systems, demanding a ransom for decryption keys.
Arkei Stealer credential-stealerspyware
Also known as ArkeiStealer. Arkei is a stealer that appeared around May 2018.
ArmaLocky ransomware
ArmaLocky is a type of ransomware that encrypts files on a victim's system and demands a ransom for decryption.
Armage ransomware
Armage is a type of ransomware that encrypts files on the victim's computer and demands a ransom for decryption.
Armageddon ransomware
Armageddon is a ransomware strain used in cyber attacks to encrypt data on victim systems, demanding a ransom for decryption.
Arp
Also known as arp.exe. Arp displays and modifies information about a system's Address Resolution Protocol (ARP) cache.
ArrowRAT rat
It is available as a service, purchasable by anyone to use in their own campaigns.
Arsium ransomware
Arsium is a type of ransomware known for encrypting files on the infected system and demanding a cryptocurrency ransom for decryption.
Artra Downloader downloader
Artra Downloader is a malware family designed to silently download and install additional malicious payloads onto an infected system.
Arvinclub ransomware
Also known as Arvin Club. Arvin Club is a popular Ransomware group with a widespread Telegram presence, which includes personal group chats, and official channels.
Asacub trojan
Also known as Trojan-SMS.AndroidOS.Smaps. Asacub is a banking trojan that attempts to steal money from victims’ bank accounts.
Asbit trojan
Asbit is a malware family primarily focused on targeting financial institutions and public sector organizations.
AscentLoader loader
AscentLoader is a type of malware commonly used to load additional malicious payloads onto compromised systems.
AshTag backdoor
AshTag is a modular .NET backdoor with multiple features that has been used by WIRTE since at least 2025.
Ashas backdoorrat
Ashas is a remote access trojan used by cyber espionage groups to target energy and government sectors, primarily in the United States and…
Ashen backdoortrojan
Also known as AshTag. According to Unit 42, Ashen / AshTag is a modular .NET toolset currently in active development, with extensive features, including file…
Asprox botnetcredential-stealerdownloader
Also known as Aseljo, BadSrc. Asprox is a botnet family known for its ability to carry out automated attacks on web applications, predominantly to steal credentials and…
Asruex trojanloader
Asruex is a trojan known for utilizing code injection techniques, often acting as a loader to further distribute other malicious payloads.
Assassin rat
Assassin is a remote access tool (RAT) used primarily for cyber espionage.
Assembly ransomware
Assembly is a ransomware that encrypts files on a victim's system, demanding a ransom for decryption.
AstarionRAT ratcredential-stealer
Also known as MIMICRAT. According to Huntress, AstarionRAT is a full-featured RAT with 24 commands, including credential theft, SOCKS5 proxy, port scanning…
Astaroth trojancredential-stealer
Also known as Guildma. Astaroth is a Trojan and information stealer known to affect companies in Europe, Brazil, and throughout Latin America.
Astasia trojancredential-stealer
Astasia is a banking trojan that spreads through phishing emails that contain an executable attachment.
Astro Locker ransomware
Ransomware
AsyncRAT rat
AsyncRAT is an open-source remote access tool originally available through the NYANxCAT Github repository that has been used in malicious…
Ataware ransomware
Ataware is a ransomware known for encrypting user data and demanding a ransom for decryption.
Atchbo ransomware
Atchbo is a type of ransomware known for encrypting a victim's files and demanding a ransom for decryption.
Atelier Web Remote Commander ratscreen-capture
Atelier Web Remote Commander is a remote access tool (RAT) that allows users to gain control over other systems for administrative purposes.
Atharvan rat
Atharvan is a remote access tool primarily used for cyber espionage, targeting government and defense sectors.
Athena backdoorrat
Part of the Mythic framework, payload in C# (.NET 6), support HTTP, Websockets, Slack, SMB for C2.
AthenaGo RAT rat
AthenaGo RAT is a remote access trojan used for cyber espionage, primarily targeting sensitive sectors.
Atlantida
Atlantida is a piece of malware with limited information available.
Atlas RAT backdoorratloader
According to Proofpoint, Atlas RAT is a modular backdoor used by the TA4922 actor, delivered in multiple stages with a core module and…
AtlasAgent rat
AtlasAgent is a remote access tool (RAT) used primarily for espionage purposes.
Atmosphere trojan
Atmosphere is a banking trojan known for targeting financial institutions.
Atomsilo ransomware
AtomSilo is a new Ransomware recently seen in September 2021 during one of their attacks by exploiting a recently revealed vulnerability…