Malware Families page 31 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Matryoshka RAT rat
Matryoshka RAT is a remote access trojan primarily used for cyber-espionage.
Matsnu trojanbotnet
Matsnu is a type of Trojan malware known for creating a botnet by infecting computers.
Maudi loader
Maudi is a specialized loader for the PoisonIvy RAT, typically used to gain initial access and deploy subsequent payloads.
Maui ransomware ransomware
Maui ransomware stand out because of a lack of several key features commonly seen with tooling from RaaS providers, such as an embedded…
MauriGo ransomware
MauriGo is a ransomware strain known for encrypting files and demanding a ransom for their decryption.
MaxiCrypt ransomware
MaxiCrypt is a ransomware family known for encrypting files and demanding a ransom for their release.
Maxtrilha trojancredential-stealer
Banking trojan written in Delphi, targeting customers of European and South American banks.
Maykolin ransomware
Maykolin is a ransomware family known for encrypting files on infected systems, demanding a ransom in cryptocurrency for decryption.
Maysomware ransomware
Maysomware is a ransomware family known for encrypting data on infected systems, demanding payment for decryption keys.
MazarBOT trojanbotnet
MazarBOT is Android malware that was distributed via SMS in Denmark in 2016.
Maze ransomware
Also known as ChaCha. Maze ransomware, previously known as "ChaCha", was discovered in May 2019.
Mbc loaderbackdoor
Mbc is a sophisticated loader malware often used to deploy additional payloads.
Mebromi rootkittrojan
Also known as MyBios. Mebromi, also known as MyBios, is a BIOS rootkit that modifies the BIOS of a computer, facilitating persistent infections.
MechaFlounder rat
MechaFlounder is a python-based remote access tool (RAT) that has been used by APT39.
MediaPI spywaretrojan
Also known as Eyeglass. MediaPI, also known as Eyeglass, is a sophisticated spyware used to perform cyber-espionage, primarily targeting the media and…
Medre backdoorrat
Medre is a cyber-espionage tool primarily utilized for intelligence gathering.
Medusa (Android) trojan
Also known as Gorgona. According to ThreatFabric, this is an Android banking trojan under active development as of July 2020.
Medusa (Windows) ransomware
According to Unit 42, Medusa surfaced as a ransomware-as-a-service (RaaS) platform in late 2022 and gained notoriety in early 2023…
Medusa Ransomware ransomware
Medusa Ransomware has been utilized in attacks since at least 2021.
MedusaHTTP botnetddos
Medusa is a DDoS bot written in .NET 2.0.
MedusaLocker ransomware
Also known as AKO Doxware, AKO Ransomware, MedusaReborn. Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilities in Remote Desktop Protocol (RDP) to access…
Meduza ransomware
Meduza is a ransomware that encrypts victims' files and demands a ransom payment for decryption.
Meduza Stealer credential-stealer
Meduza Stealer is a malware family specialized in stealing credentials from infected systems.
Mega trojan
Mega is a known trojan malware family typically used for stealing personal and financial information.
MegaCortex ransomware
MegaCortex is ransomware that first appeared in May 2019.
MegaCreep rattrojan
MegaCreep is a remote access trojan primarily targeting governmental and technological sectors.
MegaLocker ransomware
MegaLocker is a ransomware family known for encrypting files and demanding ransom payments in cryptocurrency.
MegaTrojan trojan
MegaTrojan is a trojan malware written in Visual Basic.
Megazord ransomware
Megazord is a Rust-based variant of Akira ransomware that has been in use since at least August 2023 to target Windows environments.
MeguminTrojan ddoscryptominerloader
Megumin Trojan, is a malware focused on multiple fields (DDoS, Miner, Loader, Clipper).
Meister ransomware
Meister is a ransomware family that specifically targets victims in France.
Mekotio trojan
Mekotio is a banking trojan that mainly targets Latin American countries, particularly Brazil, Chile, and Mexico.
Melcoz trojan
Melcoz is a banking trojan family built from the open source tool Remote Access PC.
Melofee backdoorrat
Also known as Mélofée. Melofee, also known as Mélofée, is a remote access trojan possibly linked to state-sponsored activity.
MeltingClaw rat
MeltingClaw is a remote access trojan primarily used for cyber espionage targeting government and defense sectors.
MercurialGrabber credential-stealerkeylogger
MercurialGrabber is a type of credential-stealing malware that captures sensitive information like passwords and keystrokes.
Mercury Ransomware ransomware
extension ".Mercury", note "!!!READ_IT!!!.txt" with 4 different 64-char hex as ID, 3 of which have dashes.
Merdoor backdoor
Merdoor is a backdoor primarily used for cyber espionage, providing persistent access to target systems.
Merlin ratbackdoor
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
Merry Christmas ransomware
Also known as Merry X-Mas, MRCR. It’s directed to English and Italian speaking users, therefore is able to infect worldwide.
MetaStealer credential-stealerspyware
On March 7, 2022, KELA observed a threat actor named _META_ announcing the launch of META – a new information-stealing malware, available…
MetadataBin ransomware
Also known as Ransomware32. MetadataBin, also known as Ransomware32, is a type of ransomware that encrypts user files and demands a ransom for decryption.
Metamorfo trojan
Also known as Casbaneiro. Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018.
Meteor wiper
Meteor is a wiper that was used against Iranian government organizations, including Iranian Railways, the Ministry of Roads, and Urban…
Meteoritan ransomware
Meteoritan is a ransomware that encrypts files on the victim's system, demanding payment for decryption.
Meterpreter (Android) backdoorrat
Meterpreter for Android is a post-exploitation framework that provides an attacker with control over compromised devices.
Meterpreter (Windows) rattrojan
Meterpreter is a versatile payload part of the Metasploit Framework, known for its capability to provide dynamic and stealthy remote…
Mevade botnet
Also known as SBC, Sefnit. Mevade, also known as SBC or Sefnit, is a botnet that utilized Tor .onion links to obscure its command and control communications, making…
Mew767 ransomware
Mew767 is a type of ransomware that encrypts files on infected devices and demands a ransom payment for file decryption.
Mewsei ratspyware
Mewsei is a Remote Access Trojan (RAT) primarily used in espionage campaigns targeting government and financial sectors.
MgBot backdoorbotnetspyware
Also known as BLame, MgmBot, POCOSTICK. MgBot is a modular malware framework exclusively associated with Daggerfly operations since at least 2012.
MiKey backdoortrojan
MiKey is a backdoor trojan known for its use in espionage campaigns targeting financial and government sectors.
Miancha ratspyware
Miancha is a remote access tool (RAT) primarily used for espionage purposes.
Micrass backdoor
Micrass is a malware family primarily used for cyber-espionage targeting government and technology sectors.
MicroBackdoor backdoor
Open-source lightweight backdoor for C2 communication.
Microcin rat
Microcin is a Remote Access Trojan (RAT) primarily used in cyber-espionage campaigns.
Micropsia rat
Micropsia is a remote access tool written in Delphi.
Midas ransomware
This malware written in C# is a variant of the Thanos ransomware family and emerged in October 2021 and is obfuscated using SmartAssembly.
Midrashim virus
A x64 ELF file infector with non-destructive payload.
Mijnal ransomware
Mijnal is a type of ransomware known to encrypt files and demand a ransom in exchange for decryption keys.
Mike NotSTOP ransomware
Mike NotSTOP is a ransomware family that encrypts files on a victim's system, demanding payment for decryption keys.
Mikoponi trojandownloader
Mikoponi is a trojan malware family that primarily targets financial services and government sectors.
Mikoyan ransomware
Mikoyan is a ransomware strain that encrypts files on infected systems and demands ransom payment for decryption keys.
Milan backdoor
Also known as James. Milan is a backdoor implant based on DanBot that was written in Visual C++ and .NET.
MilkmanVictory ransomware
MilkmanVictory is a ransomware that encrypts victim's data to demand ransom payments.
Milum rat
In August 2019, Kaspersky Labs discovered a malware they dubbed Milum (naming based on internal file name fragments) when investigating an…
MimiPenguin credential-stealer
MimiPenguin is a credential dumper, similar to Mimikatz, designed specifically for Linux platforms.
Mimic Ransomware ransomware
According to PCrisk, Mimic is a ransomware-type program.
Mimikatz credential-stealer
Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that…
MindLost ransomware
MindLost is a ransomware that encrypts files on compromised systems, demanding a ransom payment for decryption.
MindSystem ransomware
MindSystem is a ransomware that encrypts sensitive data on infected systems, targeting sectors such as financial services, healthcare, and…
Mineping ddos
Mineping is a malicious tool designed to launch DDoS attacks specifically targeting Minecraft servers, aiming to disrupt gameplay and…
Miner-C cryptominer
Miner-C is malware that mines victims for the Monero cryptocurrency.
Mini ransomware
Mini ransomware is a type of malware that encrypts data on a victim's system, demanding a ransom for decryption.
Mini Shai-Hulud
Mini Shai-Hulud is a credential stealer and self-replicating supply chain worm, derived from Shai-Hulud, that has been used by TeamPCP to…
MiniASP webshell
MiniASP is a malware identified as a webshell, often used to maintain unauthorized access on compromised web servers.
MiniBrowse trojanspyware
MiniBrowse is a trojan and spyware malware family often associated with cyber espionage activities targeting government and public sector…
MiniDuke downloaderbackdoorloader
MiniDuke is malware that was used by APT29 from 2010 to 2015.
MiniJS backdoor
MiniJS is a very simple JavaScript-based first-stage backdoor.
MiniJunk
MiniJunk is a malware with limited publicly available information.
MiniPocket trojan
MiniPocket is a Trojan malware that primarily functions as a lightweight espionage tool.
MiniStealer credential-stealer
MiniStealer is a credential-stealing malware family known for targeting sensitive information such as login credentials.
Minimo trojan
Minimo is a malware trojan often used in cyber espionage campaigns.
Minodo backdoor
Since late February 2023, Minodo Backdoor campaigns have been employed to deliver either the Project Nemesis information stealer or more…
Minotaur ransomware
Minotaur is a strain of ransomware known for encrypting files on compromised systems and demanding ransom payments to unlock them.
MintStealer credential-stealertrojan
MintStealer is a credential-stealing malware family primarily targeting financial services.
MintsLoader loaderratcredential-stealer
According to Orange Cyberdefense, MintsLoader is a little-known, multi-stage malware loader that has been used since at least February 2023.
Mirage rat
Mirage is a Remote Access Trojan (RAT) primarily used for cyber espionage by threat actors.
MirageFox rat
MirageFox is a remote access tool used against Windows systems.
Mirai (ELF) botnetddostrojan
Also known as Katana. Mirai is one of the first significant botnets targeting exposed networking devices running Linux.
Mirai (Windows) botnetddos
Mirai is a malware that primarily targets Internet of Things (IoT) devices to form large botnets used for distributed denial-of-service…
MireWare ransomware
MireWare is a type of ransomware derived from the HiddenTear open-source project.
MirrorBlast trojandownloader
According to Minerva Labs, MirrorBlast malware is a trojan that is known for attacking users’ browsers.
MirrorKey loader
According to Trend Micro, this is a loader for win.transbox, used by threat actor Earth Yako.
MirrorStealer credential-stealer
MirrorStealer is a credential stealer that has been used by MirrorFace since at least 2022 to steal credentials from various applications…
Mis-Type backdoor
Mis-Type is a backdoor hybrid that was used in Operation Dust Storm by 2012.
Mischa ransomware
Also known as "Petya's little brother", Misha, Petya+Mischa. Ransomware Packaged with Petya PDFBewerbungsmappe.exe
Misdat backdoor
Misdat is a backdoor that was used in Operation Dust Storm from 2010 to 2011.
Misfox trojanbackdoor
Also known as Dromedan, MixFox, ModPack. Misfox, also known as Dromedan, MixFox, and ModPack, is a malware family that provides backdoor access to victim systems.
Misha credential-stealer
Undocumented information stealer targeting multiple browsers and cryptocurrences.