Malware Families page 30 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

MINIBUS backdoor
According to Mandiant, this is a custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance…
MINOCAT trojan
According to Google, MINOCAT is an 64-bit ELF executable for Linux that includes a custom "NSS" wrapper and an embedded, open-source Fast…
MIRCOP ransomware
Also known as Crypt888, MicroCop. MIRCOP, also known as Crypt888, is a ransomware that encrypts files and demands a ransom of 48.48 BTC for decryption.
MISTCLOAK loader
Also known as HIUPAN. Mandiant associates this with UNC4191, this malware decrypts and runs DARKDEW.
MISTPEN backdoor
According to Mandiant, MISTPEN is a lightweight backdoor written in C whose main functionality is to download and execute Portable…
MISTYVEAL trojan
MISTYVEAL is a trojan malware used for data exfiltration and credential theft.
MLRat rat
MLRat is a remote access Trojan that enables attackers to gain unauthorized control over infected systems.
MM Core rat
MM Core is a Remote Access Trojan (RAT) commonly associated with cyber espionage activities, particularly in Southeast Asia.
MM Locker ransomware
Also known as Booyah. MM Locker, also known as Booyah, is a ransomware that encrypts files and demands a ransom for their decryption.
MMM ransomware
MMM is a ransomware family known for encrypting victim files and demanding a ransom for decryption.
MNS CryptoLocker ransomware
MNS CryptoLocker is a ransomware family that encrypts files on an infected system and demands a ransom payment for decryption.
MOONTAG backdoor
The malware, potentially named "MOON_TAG" by its developer as indicated by the strings within, is derived from code shared in a Google…
MOPSLED backdoor
MOPSLED is a shellcode-based modular backdoor that has been used by China-nexus cyber espionage actors including UNC3886 and APT41.
MOTD Ransomware ransomware
About: This is most likely to affect English speaking users, since the note is written in English.
MOUSEISLAND downloaderloader
MOUSEISLAND is a Microsoft Word macro downloader used as the first infection stage and is delivered inside a password-protected zip…
MOrder RAT rat
MOrder RAT is a remote access trojan used for cyber espionage, often targeting technology and government sectors.
MPKBot botnettrojan
Also known as MPK. MPKBot is a malware family known for operating as a botnet and trojan.
MQsTTang backdoor
Also known as QMAGENT. MQsTTang, also known as QMAGENT, is a sophisticated backdoor malware attributed to Chinese-linked threat actors.
MRA RAT rat
MRA RAT is a remote access trojan used to gain unauthorized access to targeted systems.
MRAC ransomware
MRAC is a ransomware family known for encrypting files on victim systems and demanding a ransom for decryption keys.
MS Exchange Tool webshell
The MS Exchange Tool is a web shell often used to exploit vulnerabilities in Microsoft Exchange Servers.
MSN CryptoLocker Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
MURKYTOP spyware
MURKYTOP is a reconnaissance tool used by Leviathan.
MVP Ransomware ransomware
Siri discovered a new ransomware that is appending the .mvp extension to encrypted files.
MXX ransomware
MXX is a type of ransomware that encrypts files on the victim's systems, demanding payment for decryption.
MZP ransomware
MZP is a strain of ransomware used in cybercriminal campaigns targeting various environments, encrypting files and demanding ransom for…
MZRevenge trojanbackdoor
Also known as MaMo434376. MZRevenge is a sophisticated malware family known for its capability in cyber espionage.
MaMi credential-stealer
MaMi is a macOS malware that hijacks DNS settings on infected machines.
Mabouia ransomware
Mabouia is a proof-of-concept ransomware targeting OS X systems.
MacAndChess ransomware
MacAndChess is a ransomware variant based on the open-source HiddenTear project.
MacDownloader trojan
MacDownloader is a trojan malware used in targeted espionage campaigns, often attributed to Iranian threat actors.
MacInstaller
MacInstaller is malware targeting macOS systems, often used to distribute other malicious payloads or gain unauthorized access.
MacMa backdoorspyware
Also known as OSX.CDDS, DazzleSpy. MacMa is a macOS-based backdoor with a large set of functionalities to control and exfiltrate files from a compromised computer.
MacRansom ransomware
A basic piece of macOS ransomware, offered via a 'malware-as-a-service' model.
MacSpy spyware
MacSpy is a malware-as-a-service offered on the darkweb.
MacVX spyware
MacVX is a type of adware that primarily targets macOS systems, often categorized as spyware due to its capacity to monitor user activity.
Macaw rattrojan
Macaw is a remote access trojan (RAT) known for its ability to infiltrate government and technology sectors.
Machete backdoor
Also known as Pyark, El Machete. Machete is a cyber espionage toolset used by Machete.
MadBit ransomware
MadBit is a ransomware variant known for targeting financial services, healthcare, and technology sectors.
MadMax ransomware
MadMax is a ransomware family known for targeting energy and utility sectors, as well as government organizations.
MadRAT rat
MadRAT is a Remote Access Trojan (RAT) designed to provide attackers with administrative control over infected systems.
Madafakah ransomware
Madafakah is a type of ransomware that encrypts victims' files and demands a ransom for decryption.
Mafalda rat
Mafalda is a flexible interactive implant that has been used by Metador.
MafiaWare Ransomware ransomware
Also known as Depsex Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
Magala botnettrojan
Magala is a trojan primarily used for click-fraud operations, generating fake advertising revenue by simulating human clicks on web…
Maggie backdoor
According to DCSO, this malware is written as a Extended Stored Procedure for a MSSQL server.
Magic ransomware
Magic is a ransomware variant based on the open-source EDA2 platform, which encrypts files and demands a ransom for their decryption.
MagicRAT rat
MagicRAT is a remote access tool developed in C++ and exclusively used by the Lazarus Group threat actor in operations.
Magician ransomware
Magician is a ransomware family known for encrypting files on compromised systems and demanding a ransom for decryption.
Magniber ransomwareexploit-kit
According to TXOne, The Magniber ransomware was first identified in late 2017 when it was discovered using the Magnitude Exploit Kit to…
Magniber Ransomware ransomwareexploit-kit
Magniber is a new ransomware being distributed by the Magnitude Exploit Kit that appears to be the successor to the Cerber Ransomware.
Mail-O credential-stealertrojan
Mail-O is an email-based malware primarily used to target financial services and retail sectors.
MailSniper credential-stealer
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords…
Maintools.js trojan
Expects a parameter to run: needs to be started as 'maintools.js EzZETcSXyKAdF_e5I2i1'.
MajikPos
MajikPOS is a type of point-of-sale malware used to steal payment card information from infected systems.
MakLoader loader
MakLoader is a malware loader used to distribute additional malicious payloads onto infected systems.
Makadocs spywaretrojan
Makadocs is a type of malware leveraging malicious RTF documents to perform espionage by targeting government and public sector…
Makop ransomware
Makop is a ransomware that encrypts the victim's files and demands a ransom for the decryption key.
Maktub ransomware
According to PCrisk, Maktub is ransomware distributed via zipped Word documents.
MaktubLocker ransomware
MaktubLocker is a ransomware that encrypts files on the victim's machine and demands payment in cryptocurrency for decryption keys.
Malabu ransomware
Malabu is a ransomware strain known for encrypting the files of its victims and demanding a ransom for decryption.
Mallox ransomware
Mallox is a ransomware family known for encrypting victim files and demanding a ransom payment in exchange for decryption keys.
MalumPOS
MalumPOS is a type of malware designed to target point-of-sale (POS) systems.
MalwareTech's CTF ransomware
MalwareTech's CTF is identified as ransomware, though specific targeting details or broader industry impacts are not widely recognized.
ManItsMe
Mancros+AI4939 ransomware
Mancros+AI4939 is a ransomware variant known for encrypting files on victim systems and demanding ransom for decryption keys.
Mandrake spywarerat
Also known as oxide, briar, ricinus. Mandrake is a sophisticated Android espionage platform that has been active in the wild since at least 2016.
Mangit botnetcredential-stealertrojan
First discovered by Trend Micro in June, Mangit is a new malware family being marketed on both the Dark web and open internet.
Mango backdoor
Mango is a first-stage backdoor written in C#/.NET that was used by OilRig during the Juicy Mix campaign.
Mangzamel rattrojan
Also known as junidor, mengkite, vedratve. Mangzamel is a remote access tool (RAT) that is often associated with cyber espionage activities.
Manifestus ratspyware
Manifestus is a Remote Access Trojan that targets government, financial services, and energy sectors.
Manifestus Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Manjusaka rat
Manjusaka is a Chinese-language intrusion framework, similar to Sliver and Cobalt Strike, with an ELF binary written in GoLang as the…
Manjusaka (ELF) rat
Cisco Talos compared this RAT to Cobalt Strike and Sliver.
Manjusaka (Windows) rat
Cisco Talos compared this RAT to Cobalt Strike and Sliver.
Manuscrypt backdoorrat
Manuscrypt is a backdoor typically associated with advanced persistent threat (APT) groups, specifically believed to be linked to North…
Maoloa ransomware
Maoloa is a ransomware strain known for encrypting files and demanding payment for decryption keys.
Marap downloader
Marap is a downloader, named after its command and control (C&C) phone home parameter "param" spelled backwards.
Marcher
Also known as ExoBot. Marcher is Android malware that is used for financial fraud.
Mariposa botnetworm
Also known as Autorun, Palevo, Rimecud. Mariposa, also known as Palevo, Autorun, or Rimecud, is a botnet malware family primarily used for data theft and distributed…
MarkiRAT rat
MarkiRAT is a remote access Trojan (RAT) compiled with Visual Studio that has been used by Ferocious Kitten since at least 2015.
Marlboro Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Marozka ransomware
Marozka is a ransomware variant known for encrypting files and demanding ransom payments.
MarraCrypt ransomware
MarraCrypt is a type of ransomware that encrypts files on the infected systems and demands a ransom for the decryption key.
Mars ransomware
Also known as MarsDecrypt. Mars is a ransomware family also known as MarsDecrypt.
Mars Stealer credential-stealerspyware
3xp0rt describes Mars Stealer as an improved successor of Oski Stealer, supporting stealing from current browsers and targeting crypto…
MarsJoke ransomware
MarsJoke is a ransomware known for targeting government and educational sectors.
Masad Stealer credential-stealercryptominer
Masad Stealer is a type of information-stealing malware that primarily targets cryptocurrency wallets and account credentials.
MaskGramStealer credential-stealerspyware
MaskGramStealer is a malware designed to steal credentials and sensitive information from victims.
MasterBuster Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
MasterFred trojancredential-stealer
Also known as Brox. According to heimdal, MasterFred malware, this is designed as an Android trojan that makes use of false login overlays to target not only…
Masuta botnet
Also known as PureMasuta. Masuta is a variant of Mirai that targets IoT devices, primarily routers, using dictionary attacks to target weak credentials.
Matanbuchus loader
According to PCrisk, Matanbuchus is a loader-type malicious program offered by its developers as Malware-as-a-Service (MaaS).
Matiex keylogger
Matiex Keylogger is being sold in the underground forums, due to their gained popularity, and can also be used as MaaS…
Matrix ransomware
Also known as Malta Ransomware, Matrix Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
Matrix Banker trojancredential-stealer
Matrix Banker is a banking trojan that aims to steal financial information from victims.
Matrix Ransom ransomware
Matrix is a ransomware that encrypts a victim's files and demands a ransom in cryptocurrency to decrypt them.
Matroska ransomware
Matroska is a sophisticated ransomware variant responsible for encrypting victim files and demanding a ransom for decryption.
Matryosh trojan
Matryosh is a sophisticated malware family used primarily for cyber-espionage.
Matryoshka ratdropperloader
Matryoshka is a malware framework used by CopyKittens that consists of a dropper, loader, and RAT.