Malware Families page 31 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Matryoshka RAT rat
- Matryoshka RAT is a remote access trojan primarily used for cyber-espionage.
- Matsnu trojanbotnet
- Matsnu is a type of Trojan malware known for creating a botnet by infecting computers.
- Maudi loader
- Maudi is a specialized loader for the PoisonIvy RAT, typically used to gain initial access and deploy subsequent payloads.
- Maui ransomware ransomware
- Maui ransomware stand out because of a lack of several key features commonly seen with tooling from RaaS providers, such as an embedded…
- MauriGo ransomware
- MauriGo is a ransomware strain known for encrypting files and demanding a ransom for their decryption.
- MaxiCrypt ransomware
- MaxiCrypt is a ransomware family known for encrypting files and demanding a ransom for their release.
- Maxtrilha trojancredential-stealer
- Banking trojan written in Delphi, targeting customers of European and South American banks.
- Maykolin ransomware
- Maykolin is a ransomware family known for encrypting files on infected systems, demanding a ransom in cryptocurrency for decryption.
- Maysomware ransomware
- Maysomware is a ransomware family known for encrypting data on infected systems, demanding payment for decryption keys.
- MazarBOT trojanbotnet
- MazarBOT is Android malware that was distributed via SMS in Denmark in 2016.
- Maze ransomware
- Also known as ChaCha. Maze ransomware, previously known as "ChaCha", was discovered in May 2019.
- Mbc loaderbackdoor
- Mbc is a sophisticated loader malware often used to deploy additional payloads.
- Mebromi rootkittrojan
- Also known as MyBios. Mebromi, also known as MyBios, is a BIOS rootkit that modifies the BIOS of a computer, facilitating persistent infections.
- MechaFlounder rat
- MechaFlounder is a python-based remote access tool (RAT) that has been used by APT39.
- MediaPI spywaretrojan
- Also known as Eyeglass. MediaPI, also known as Eyeglass, is a sophisticated spyware used to perform cyber-espionage, primarily targeting the media and…
- Medre backdoorrat
- Medre is a cyber-espionage tool primarily utilized for intelligence gathering.
- Medusa (Android) trojan
- Also known as Gorgona. According to ThreatFabric, this is an Android banking trojan under active development as of July 2020.
- Medusa (Windows) ransomware
- According to Unit 42, Medusa surfaced as a ransomware-as-a-service (RaaS) platform in late 2022 and gained notoriety in early 2023…
- Medusa Ransomware ransomware
- Medusa Ransomware has been utilized in attacks since at least 2021.
- MedusaHTTP botnetddos
- Medusa is a DDoS bot written in .NET 2.0.
- MedusaLocker ransomware
- Also known as AKO Doxware, AKO Ransomware, MedusaReborn. Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilities in Remote Desktop Protocol (RDP) to access…
- Meduza ransomware
- Meduza is a ransomware that encrypts victims' files and demands a ransom payment for decryption.
- Meduza Stealer credential-stealer
- Meduza Stealer is a malware family specialized in stealing credentials from infected systems.
- Mega trojan
- Mega is a known trojan malware family typically used for stealing personal and financial information.
- MegaCortex ransomware
- MegaCortex is ransomware that first appeared in May 2019.
- MegaCreep rattrojan
- MegaCreep is a remote access trojan primarily targeting governmental and technological sectors.
- MegaLocker ransomware
- MegaLocker is a ransomware family known for encrypting files and demanding ransom payments in cryptocurrency.
- MegaTrojan trojan
- MegaTrojan is a trojan malware written in Visual Basic.
- Megazord ransomware
- Megazord is a Rust-based variant of Akira ransomware that has been in use since at least August 2023 to target Windows environments.
- MeguminTrojan ddoscryptominerloader
- Megumin Trojan, is a malware focused on multiple fields (DDoS, Miner, Loader, Clipper).
- Meister ransomware
- Meister is a ransomware family that specifically targets victims in France.
- Mekotio trojan
- Mekotio is a banking trojan that mainly targets Latin American countries, particularly Brazil, Chile, and Mexico.
- Melcoz trojan
- Melcoz is a banking trojan family built from the open source tool Remote Access PC.
- Melofee backdoorrat
- Also known as Mélofée. Melofee, also known as Mélofée, is a remote access trojan possibly linked to state-sponsored activity.
- MeltingClaw rat
- MeltingClaw is a remote access trojan primarily used for cyber espionage targeting government and defense sectors.
- MercurialGrabber credential-stealerkeylogger
- MercurialGrabber is a type of credential-stealing malware that captures sensitive information like passwords and keystrokes.
- Mercury Ransomware ransomware
- extension ".Mercury", note "!!!READ_IT!!!.txt" with 4 different 64-char hex as ID, 3 of which have dashes.
- Merdoor backdoor
- Merdoor is a backdoor primarily used for cyber espionage, providing persistent access to target systems.
- Merlin ratbackdoor
- Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
- Merry Christmas ransomware
- Also known as Merry X-Mas, MRCR. It’s directed to English and Italian speaking users, therefore is able to infect worldwide.
- MetaStealer credential-stealerspyware
- On March 7, 2022, KELA observed a threat actor named _META_ announcing the launch of META – a new information-stealing malware, available…
- MetadataBin ransomware
- Also known as Ransomware32. MetadataBin, also known as Ransomware32, is a type of ransomware that encrypts user files and demands a ransom for decryption.
- Metamorfo trojan
- Also known as Casbaneiro. Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018.
- Meteor wiper
- Meteor is a wiper that was used against Iranian government organizations, including Iranian Railways, the Ministry of Roads, and Urban…
- Meteoritan ransomware
- Meteoritan is a ransomware that encrypts files on the victim's system, demanding payment for decryption.
- Meterpreter (Android) backdoorrat
- Meterpreter for Android is a post-exploitation framework that provides an attacker with control over compromised devices.
- Meterpreter (Windows) rattrojan
- Meterpreter is a versatile payload part of the Metasploit Framework, known for its capability to provide dynamic and stealthy remote…
- Mevade botnet
- Also known as SBC, Sefnit. Mevade, also known as SBC or Sefnit, is a botnet that utilized Tor .onion links to obscure its command and control communications, making…
- Mew767 ransomware
- Mew767 is a type of ransomware that encrypts files on infected devices and demands a ransom payment for file decryption.
- Mewsei ratspyware
- Mewsei is a Remote Access Trojan (RAT) primarily used in espionage campaigns targeting government and financial sectors.
- MgBot backdoorbotnetspyware
- Also known as BLame, MgmBot, POCOSTICK. MgBot is a modular malware framework exclusively associated with Daggerfly operations since at least 2012.
- MiKey backdoortrojan
- MiKey is a backdoor trojan known for its use in espionage campaigns targeting financial and government sectors.
- Miancha ratspyware
- Miancha is a remote access tool (RAT) primarily used for espionage purposes.
- Micrass backdoor
- Micrass is a malware family primarily used for cyber-espionage targeting government and technology sectors.
- MicroBackdoor backdoor
- Open-source lightweight backdoor for C2 communication.
- Microcin rat
- Microcin is a Remote Access Trojan (RAT) primarily used in cyber-espionage campaigns.
- Micropsia rat
- Micropsia is a remote access tool written in Delphi.
- Midas ransomware
- This malware written in C# is a variant of the Thanos ransomware family and emerged in October 2021 and is obfuscated using SmartAssembly.
- Midrashim virus
- A x64 ELF file infector with non-destructive payload.
- Mijnal ransomware
- Mijnal is a type of ransomware known to encrypt files and demand a ransom in exchange for decryption keys.
- Mike NotSTOP ransomware
- Mike NotSTOP is a ransomware family that encrypts files on a victim's system, demanding payment for decryption keys.
- Mikoponi trojandownloader
- Mikoponi is a trojan malware family that primarily targets financial services and government sectors.
- Mikoyan ransomware
- Mikoyan is a ransomware strain that encrypts files on infected systems and demands ransom payment for decryption keys.
- Milan backdoor
- Also known as James. Milan is a backdoor implant based on DanBot that was written in Visual C++ and .NET.
- MilkmanVictory ransomware
- MilkmanVictory is a ransomware that encrypts victim's data to demand ransom payments.
- Milum rat
- In August 2019, Kaspersky Labs discovered a malware they dubbed Milum (naming based on internal file name fragments) when investigating an…
- MimiPenguin credential-stealer
- MimiPenguin is a credential dumper, similar to Mimikatz, designed specifically for Linux platforms.
- Mimic Ransomware ransomware
- According to PCrisk, Mimic is a ransomware-type program.
- Mimikatz credential-stealer
- Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that…
- MindLost ransomware
- MindLost is a ransomware that encrypts files on compromised systems, demanding a ransom payment for decryption.
- MindSystem ransomware
- MindSystem is a ransomware that encrypts sensitive data on infected systems, targeting sectors such as financial services, healthcare, and…
- Mineping ddos
- Mineping is a malicious tool designed to launch DDoS attacks specifically targeting Minecraft servers, aiming to disrupt gameplay and…
- Miner-C cryptominer
- Miner-C is malware that mines victims for the Monero cryptocurrency.
- Mini ransomware
- Mini ransomware is a type of malware that encrypts data on a victim's system, demanding a ransom for decryption.
- Mini Shai-Hulud
- Mini Shai-Hulud is a credential stealer and self-replicating supply chain worm, derived from Shai-Hulud, that has been used by TeamPCP to…
- MiniASP webshell
- MiniASP is a malware identified as a webshell, often used to maintain unauthorized access on compromised web servers.
- MiniBrowse trojanspyware
- MiniBrowse is a trojan and spyware malware family often associated with cyber espionage activities targeting government and public sector…
- MiniDuke downloaderbackdoorloader
- MiniDuke is malware that was used by APT29 from 2010 to 2015.
- MiniJS backdoor
- MiniJS is a very simple JavaScript-based first-stage backdoor.
- MiniJunk
- MiniJunk is a malware with limited publicly available information.
- MiniPocket trojan
- MiniPocket is a Trojan malware that primarily functions as a lightweight espionage tool.
- MiniStealer credential-stealer
- MiniStealer is a credential-stealing malware family known for targeting sensitive information such as login credentials.
- Minimo trojan
- Minimo is a malware trojan often used in cyber espionage campaigns.
- Minodo backdoor
- Since late February 2023, Minodo Backdoor campaigns have been employed to deliver either the Project Nemesis information stealer or more…
- Minotaur ransomware
- Minotaur is a strain of ransomware known for encrypting files on compromised systems and demanding ransom payments to unlock them.
- MintStealer credential-stealertrojan
- MintStealer is a credential-stealing malware family primarily targeting financial services.
- MintsLoader loaderratcredential-stealer
- According to Orange Cyberdefense, MintsLoader is a little-known, multi-stage malware loader that has been used since at least February 2023.
- Mirage rat
- Mirage is a Remote Access Trojan (RAT) primarily used for cyber espionage by threat actors.
- MirageFox rat
- MirageFox is a remote access tool used against Windows systems.
- Mirai (ELF) botnetddostrojan
- Also known as Katana. Mirai is one of the first significant botnets targeting exposed networking devices running Linux.
- Mirai (Windows) botnetddos
- Mirai is a malware that primarily targets Internet of Things (IoT) devices to form large botnets used for distributed denial-of-service…
- MireWare ransomware
- MireWare is a type of ransomware derived from the HiddenTear open-source project.
- MirrorBlast trojandownloader
- According to Minerva Labs, MirrorBlast malware is a trojan that is known for attacking users’ browsers.
- MirrorKey loader
- According to Trend Micro, this is a loader for win.transbox, used by threat actor Earth Yako.
- MirrorStealer credential-stealer
- MirrorStealer is a credential stealer that has been used by MirrorFace since at least 2022 to steal credentials from various applications…
- Mis-Type backdoor
- Mis-Type is a backdoor hybrid that was used in Operation Dust Storm by 2012.
- Mischa ransomware
- Also known as "Petya's little brother", Misha, Petya+Mischa. Ransomware Packaged with Petya PDFBewerbungsmappe.exe
- Misdat backdoor
- Misdat is a backdoor that was used in Operation Dust Storm from 2010 to 2011.
- Misfox trojanbackdoor
- Also known as Dromedan, MixFox, ModPack. Misfox, also known as Dromedan, MixFox, and ModPack, is a malware family that provides backdoor access to victim systems.
- Misha credential-stealer
- Undocumented information stealer targeting multiple browsers and cryptocurrences.