Malware Families page 30 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- MINIBUS backdoor
- According to Mandiant, this is a custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance…
- MINOCAT trojan
- According to Google, MINOCAT is an 64-bit ELF executable for Linux that includes a custom "NSS" wrapper and an embedded, open-source Fast…
- MIRCOP ransomware
- Also known as Crypt888, MicroCop. MIRCOP, also known as Crypt888, is a ransomware that encrypts files and demands a ransom of 48.48 BTC for decryption.
- MISTCLOAK loader
- Also known as HIUPAN. Mandiant associates this with UNC4191, this malware decrypts and runs DARKDEW.
- MISTPEN backdoor
- According to Mandiant, MISTPEN is a lightweight backdoor written in C whose main functionality is to download and execute Portable…
- MISTYVEAL trojan
- MISTYVEAL is a trojan malware used for data exfiltration and credential theft.
- MLRat rat
- MLRat is a remote access Trojan that enables attackers to gain unauthorized control over infected systems.
- MM Core rat
- MM Core is a Remote Access Trojan (RAT) commonly associated with cyber espionage activities, particularly in Southeast Asia.
- MM Locker ransomware
- Also known as Booyah. MM Locker, also known as Booyah, is a ransomware that encrypts files and demands a ransom for their decryption.
- MMM ransomware
- MMM is a ransomware family known for encrypting victim files and demanding a ransom for decryption.
- MNS CryptoLocker ransomware
- MNS CryptoLocker is a ransomware family that encrypts files on an infected system and demands a ransom payment for decryption.
- MOONTAG backdoor
- The malware, potentially named "MOON_TAG" by its developer as indicated by the strings within, is derived from code shared in a Google…
- MOPSLED backdoor
- MOPSLED is a shellcode-based modular backdoor that has been used by China-nexus cyber espionage actors including UNC3886 and APT41.
- MOTD Ransomware ransomware
- About: This is most likely to affect English speaking users, since the note is written in English.
- MOUSEISLAND downloaderloader
- MOUSEISLAND is a Microsoft Word macro downloader used as the first infection stage and is delivered inside a password-protected zip…
- MOrder RAT rat
- MOrder RAT is a remote access trojan used for cyber espionage, often targeting technology and government sectors.
- MPKBot botnettrojan
- Also known as MPK. MPKBot is a malware family known for operating as a botnet and trojan.
- MQsTTang backdoor
- Also known as QMAGENT. MQsTTang, also known as QMAGENT, is a sophisticated backdoor malware attributed to Chinese-linked threat actors.
- MRA RAT rat
- MRA RAT is a remote access trojan used to gain unauthorized access to targeted systems.
- MRAC ransomware
- MRAC is a ransomware family known for encrypting files on victim systems and demanding a ransom for decryption keys.
- MS Exchange Tool webshell
- The MS Exchange Tool is a web shell often used to exploit vulnerabilities in Microsoft Exchange Servers.
- MSN CryptoLocker Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- MURKYTOP spyware
- MURKYTOP is a reconnaissance tool used by Leviathan.
- MVP Ransomware ransomware
- Siri discovered a new ransomware that is appending the .mvp extension to encrypted files.
- MXX ransomware
- MXX is a type of ransomware that encrypts files on the victim's systems, demanding payment for decryption.
- MZP ransomware
- MZP is a strain of ransomware used in cybercriminal campaigns targeting various environments, encrypting files and demanding ransom for…
- MZRevenge trojanbackdoor
- Also known as MaMo434376. MZRevenge is a sophisticated malware family known for its capability in cyber espionage.
- MaMi credential-stealer
- MaMi is a macOS malware that hijacks DNS settings on infected machines.
- Mabouia ransomware
- Mabouia is a proof-of-concept ransomware targeting OS X systems.
- MacAndChess ransomware
- MacAndChess is a ransomware variant based on the open-source HiddenTear project.
- MacDownloader trojan
- MacDownloader is a trojan malware used in targeted espionage campaigns, often attributed to Iranian threat actors.
- MacInstaller
- MacInstaller is malware targeting macOS systems, often used to distribute other malicious payloads or gain unauthorized access.
- MacMa backdoorspyware
- Also known as OSX.CDDS, DazzleSpy. MacMa is a macOS-based backdoor with a large set of functionalities to control and exfiltrate files from a compromised computer.
- MacRansom ransomware
- A basic piece of macOS ransomware, offered via a 'malware-as-a-service' model.
- MacSpy spyware
- MacSpy is a malware-as-a-service offered on the darkweb.
- MacVX spyware
- MacVX is a type of adware that primarily targets macOS systems, often categorized as spyware due to its capacity to monitor user activity.
- Macaw rattrojan
- Macaw is a remote access trojan (RAT) known for its ability to infiltrate government and technology sectors.
- Machete backdoor
- Also known as Pyark, El Machete. Machete is a cyber espionage toolset used by Machete.
- MadBit ransomware
- MadBit is a ransomware variant known for targeting financial services, healthcare, and technology sectors.
- MadMax ransomware
- MadMax is a ransomware family known for targeting energy and utility sectors, as well as government organizations.
- MadRAT rat
- MadRAT is a Remote Access Trojan (RAT) designed to provide attackers with administrative control over infected systems.
- Madafakah ransomware
- Madafakah is a type of ransomware that encrypts victims' files and demands a ransom for decryption.
- Mafalda rat
- Mafalda is a flexible interactive implant that has been used by Metador.
- MafiaWare Ransomware ransomware
- Also known as Depsex Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- Magala botnettrojan
- Magala is a trojan primarily used for click-fraud operations, generating fake advertising revenue by simulating human clicks on web…
- Maggie backdoor
- According to DCSO, this malware is written as a Extended Stored Procedure for a MSSQL server.
- Magic ransomware
- Magic is a ransomware variant based on the open-source EDA2 platform, which encrypts files and demands a ransom for their decryption.
- MagicRAT rat
- MagicRAT is a remote access tool developed in C++ and exclusively used by the Lazarus Group threat actor in operations.
- Magician ransomware
- Magician is a ransomware family known for encrypting files on compromised systems and demanding a ransom for decryption.
- Magniber ransomwareexploit-kit
- According to TXOne, The Magniber ransomware was first identified in late 2017 when it was discovered using the Magnitude Exploit Kit to…
- Magniber Ransomware ransomwareexploit-kit
- Magniber is a new ransomware being distributed by the Magnitude Exploit Kit that appears to be the successor to the Cerber Ransomware.
- Mail-O credential-stealertrojan
- Mail-O is an email-based malware primarily used to target financial services and retail sectors.
- MailSniper credential-stealer
- MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords…
- Maintools.js trojan
- Expects a parameter to run: needs to be started as 'maintools.js EzZETcSXyKAdF_e5I2i1'.
- MajikPos
- MajikPOS is a type of point-of-sale malware used to steal payment card information from infected systems.
- MakLoader loader
- MakLoader is a malware loader used to distribute additional malicious payloads onto infected systems.
- Makadocs spywaretrojan
- Makadocs is a type of malware leveraging malicious RTF documents to perform espionage by targeting government and public sector…
- Makop ransomware
- Makop is a ransomware that encrypts the victim's files and demands a ransom for the decryption key.
- Maktub ransomware
- According to PCrisk, Maktub is ransomware distributed via zipped Word documents.
- MaktubLocker ransomware
- MaktubLocker is a ransomware that encrypts files on the victim's machine and demands payment in cryptocurrency for decryption keys.
- Malabu ransomware
- Malabu is a ransomware strain known for encrypting the files of its victims and demanding a ransom for decryption.
- Mallox ransomware
- Mallox is a ransomware family known for encrypting victim files and demanding a ransom payment in exchange for decryption keys.
- MalumPOS
- MalumPOS is a type of malware designed to target point-of-sale (POS) systems.
- MalwareTech's CTF ransomware
- MalwareTech's CTF is identified as ransomware, though specific targeting details or broader industry impacts are not widely recognized.
- ManItsMe
- Mancros+AI4939 ransomware
- Mancros+AI4939 is a ransomware variant known for encrypting files on victim systems and demanding ransom for decryption keys.
- Mandrake spywarerat
- Also known as oxide, briar, ricinus. Mandrake is a sophisticated Android espionage platform that has been active in the wild since at least 2016.
- Mangit botnetcredential-stealertrojan
- First discovered by Trend Micro in June, Mangit is a new malware family being marketed on both the Dark web and open internet.
- Mango backdoor
- Mango is a first-stage backdoor written in C#/.NET that was used by OilRig during the Juicy Mix campaign.
- Mangzamel rattrojan
- Also known as junidor, mengkite, vedratve. Mangzamel is a remote access tool (RAT) that is often associated with cyber espionage activities.
- Manifestus ratspyware
- Manifestus is a Remote Access Trojan that targets government, financial services, and energy sectors.
- Manifestus Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Manjusaka rat
- Manjusaka is a Chinese-language intrusion framework, similar to Sliver and Cobalt Strike, with an ELF binary written in GoLang as the…
- Manjusaka (ELF) rat
- Cisco Talos compared this RAT to Cobalt Strike and Sliver.
- Manjusaka (Windows) rat
- Cisco Talos compared this RAT to Cobalt Strike and Sliver.
- Manuscrypt backdoorrat
- Manuscrypt is a backdoor typically associated with advanced persistent threat (APT) groups, specifically believed to be linked to North…
- Maoloa ransomware
- Maoloa is a ransomware strain known for encrypting files and demanding payment for decryption keys.
- Marap downloader
- Marap is a downloader, named after its command and control (C&C) phone home parameter "param" spelled backwards.
- Marcher
- Also known as ExoBot. Marcher is Android malware that is used for financial fraud.
- Mariposa botnetworm
- Also known as Autorun, Palevo, Rimecud. Mariposa, also known as Palevo, Autorun, or Rimecud, is a botnet malware family primarily used for data theft and distributed…
- MarkiRAT rat
- MarkiRAT is a remote access Trojan (RAT) compiled with Visual Studio that has been used by Ferocious Kitten since at least 2015.
- Marlboro Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Marozka ransomware
- Marozka is a ransomware variant known for encrypting files and demanding ransom payments.
- MarraCrypt ransomware
- MarraCrypt is a type of ransomware that encrypts files on the infected systems and demands a ransom for the decryption key.
- Mars ransomware
- Also known as MarsDecrypt. Mars is a ransomware family also known as MarsDecrypt.
- Mars Stealer credential-stealerspyware
- 3xp0rt describes Mars Stealer as an improved successor of Oski Stealer, supporting stealing from current browsers and targeting crypto…
- MarsJoke ransomware
- MarsJoke is a ransomware known for targeting government and educational sectors.
- Masad Stealer credential-stealercryptominer
- Masad Stealer is a type of information-stealing malware that primarily targets cryptocurrency wallets and account credentials.
- MaskGramStealer credential-stealerspyware
- MaskGramStealer is a malware designed to steal credentials and sensitive information from victims.
- MasterBuster Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- MasterFred trojancredential-stealer
- Also known as Brox. According to heimdal, MasterFred malware, this is designed as an Android trojan that makes use of false login overlays to target not only…
- Masuta botnet
- Also known as PureMasuta. Masuta is a variant of Mirai that targets IoT devices, primarily routers, using dictionary attacks to target weak credentials.
- Matanbuchus loader
- According to PCrisk, Matanbuchus is a loader-type malicious program offered by its developers as Malware-as-a-Service (MaaS).
- Matiex keylogger
- Matiex Keylogger is being sold in the underground forums, due to their gained popularity, and can also be used as MaaS…
- Matrix ransomware
- Also known as Malta Ransomware, Matrix Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- Matrix Banker trojancredential-stealer
- Matrix Banker is a banking trojan that aims to steal financial information from victims.
- Matrix Ransom ransomware
- Matrix is a ransomware that encrypts a victim's files and demands a ransom in cryptocurrency to decrypt them.
- Matroska ransomware
- Matroska is a sophisticated ransomware variant responsible for encrypting victim files and demanding a ransom for decryption.
- Matryosh trojan
- Matryosh is a sophisticated malware family used primarily for cyber-espionage.
- Matryoshka ratdropperloader
- Matryoshka is a malware framework used by CopyKittens that consists of a dropper, loader, and RAT.