Malware Families page 32 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Mispadu trojan
Also known as URSA. Mispadu is a banking trojan written in Delphi that was first observed in 2019 and uses a Malware-as-a-Service (MaaS) business model.
Miuref botnettrojan
Miuref is a variant of the Zeus banking trojan known for forming botnets that facilitate credential theft and bank fraud.
Mivast backdoor
Mivast is a backdoor that has been used by Deep Panda.
MiyaRAT rat
According to Proofpoint, MiyaRAT is a remote access trojan (RAT) written in C++ that uses sockets for communications and has standard RAT…
MoDi RAT rat
MoDi RAT is a remote access trojan (RAT) known for being used in cyber espionage campaigns.
MoSucker ratbackdoor
MoSucker is a powerful backdoor - hacker's remote access tool.
MoWare H.F.D ransomware
MoWare H.F.D is a type of ransomware known for encrypting files and demanding a ransom from victims for decryption keys.
Mobef ransomware
Also known as Yakes, CryptoBit. Mobef is a ransomware family, also known as Yakes and CryptoBit, that encrypts files on the victim's system and demands a cryptocurrency…
Mobef-JustFun ransomware
Mobef-JustFun is a ransomware family designed to encrypt files on infected systems, targeting various industries.
MobiRAT rat
MobiRAT is a remote access tool targeting Android devices, often used to remotely control smartphones and gather data without users'…
MobileOrder trojan
MobileOrder is a Trojan intended to compromise Android mobile devices.
Mocky LNK downloadertrojan
LNK files used to lure and orchestrate execution of various scripts, interacting with the Mocky API service.
Mocton rat
Mocton is a remote access tool primarily used for cyber espionage.
ModPOS trojan
Also known as straxbot. ModPOS is a sophisticated point-of-sale malware targeting the retail and hospitality sectors.
ModPipe credential-stealer
ModPipe is point-of-sale (POS) malware capable of accessing sensitive information stored in devices running ORACLE MICROS Restaurant…
ModernLoader ratloader
Also known as AvatarBot. According to PCrisk, ModernLoader, also known as Avatar Bot and AvatarLoader, is a malicious program that has minimalistic loader and RAT…
Mofksys trojan
Mofksys is a trojan malware with capabilities to infiltrate government and technology sectors.
MofoTro rat
MofoTro is a newly identified remote access trojan (RAT) developed by the hacker Cool_mofo_2.
Moisha rattrojan
Moisha is a remote access tool (RAT) primarily used for espionage and stealing sensitive information from targeted systems.
Moisha Ransomware ransomware
Moisha is a .NET-based ransomware that employs double extortion techniques to encrypt and exfiltrate data from victims.
Moker backdoor
Moker is a backdoor malware that is capable of evading detection and gaining persistence on infected systems.
Mokes (ELF) backdoorrat
Mokes is a cross-platform remote access trojan that targets Linux systems as an ELF binary.
Mokes (OS X) ratbackdoor
Mokes, also known as Spreadtrum, is a cross-platform Remote Access Tool (RAT) targeting OS X, Linux, and Windows operating systems.
Mokes (Windows) ratbackdoor
Mokes, also known as a Remote Access Trojan (RAT), is a multi-platform malware family capable of targeting Windows systems.
Mole rat
Mole is a remote access trojan (RAT) used primarily for espionage purposes.
MoleNet downloaderbackdoor
MoleNet is a downloader tool with backdoor capabilities that has been observed in use since at least 2019.
Molerat Loader loader
Molerat Loader is a malware used by threat groups primarily targeting the Middle East.
Momentum backdoor
Momentum is a malware backdoor used for remote access and control.
Monero Miner cryptominer
Also known as CoinMiner. According to ESET, first seen in-the-wild on 26th May, 2017, the malicious mining software is a fork of a legitimate open source Monero…
MoneroPay ransomware
MoneroPay is a type of ransomware designed to encrypt files on a victim's computer, demanding payment in the cryptocurrency Monero for…
Moneybird ransomware
Moneybird is a ransomware variant written in C++ associated with Agrius operations.
Mongall backdoor
Mongall is a backdoor that has been used since at least 2013, including by Aoqin Dragon.
Mongo Lock ransomwarewiper
An attack called Mongo Lock is targeting remotely accessible and unprotected MongoDB databases, wiping them, and then demanding a ransom…
MongoLock ransomware
MongoLock is a ransomware that targets improperly secured MongoDB databases, encrypting their data and demanding ransom payments from…
Monokle spyware
Monokle is targeted, sophisticated mobile surveillanceware.
MonsterV2 credential-stealer
Also known as Aurotun Stealer. MonsterV2, also known as Aurotun Stealer, is a credential-stealing malware.
Monte ransomware
Monte is a ransomware family that encrypts files on infected systems and demands a ransom for the decryption key.
Monti ransomware
Monti is a ransomware family that primarily targets governmental and technology sectors.
MontysThree spyware
Also known as MT3. MontysThree, also known as MT3, is a cyber-espionage malware primarily attributed to state-sponsored threat actors.
Monument ransomware
Ransomware Use the DarkLocker 5 porn screenlocker - Jigsaw variant
MooBot botnetddos
MooBot is a botnet malware known for targeting IoT devices to perform distributed denial-of-service (DDoS) attacks.
MoonBounce rootkittrojan
MoonBounce is a malware embedded into a modified UEFI firmware.
MoonCryptor ransomware
MoonCryptor is a ransomware that targets various sectors such as healthcare, finance, and government.
MoonPeak rat
According to Cisco Talos, this RAT is derived from the open source XenoRAT.
MoonRise rat
MoonRise is a remote access trojan (RAT) primarily used for cyber espionage activities.
MoonWalk rattrojan
Also known as CurveLast, SneakCross. MoonWalk is a remote access trojan aimed at gaining unauthorized access to sensitive systems, primarily targeting government, financial…
MoonWind rat
MoonWind is a remote access tool (RAT) that was used in 2016 to target organizations in Thailand.
Moose botnet
Moose is a Linux-based botnet malware known for its capability to compromise and control routers and IoT devices.
MoqHao droppertrojan
Also known as Shaoye, Wroba, XLoader. MoqHao, also called Wroba and XLoader (not to be confused with the malware of the same name for Windows and macOS), is an Android-based…
Mordor ransomware
Mordor is a ransomware family known for targeting critical industries and encrypting data to extort victims for payment.
More_eggs backdoorloader
Also known as SKID, Terra Loader, SpicyOmelette. More_eggs is a JScript backdoor used by Cobalt Group and FIN6.
Mori backdoorrat
Mori is a backdoor that has been used by MuddyWater since at least January 2022.
MoriAgent rat
MoriAgent is a sophisticated remote access trojan used primarily in cyber-espionage campaigns.
Moriya backdoor
This tool is a passive backdoor which allows attackers to inspect all incoming traffic to the infected machine, filter out packets that…
Morpheus Loader loader
Morpheus Loader is a malware family used for facilitating the delivery and execution of additional payloads onto compromised systems.
Morphine trojanransomware
Morphine is a malware family known for deploying trojan and ransomware capabilities, primarily targeting financial services and government…
MorrisBatchCrypt ransomware
MorrisBatchCrypt is a ransomware variant known for encrypting files and demanding a ransom payment for decryption.
Mortis ransomware
Mortis is a ransomware family known for encrypting victim files and demanding ransom payments for decryption.
Morto worm
Morto is a network worm that spreads by exploiting weak passwords in the Windows Remote Desktop Protocol.
MosaicRegressor backdoor
MosaicRegressor is a modular malware framework used by threat actors to persist on UEFI firmware.
Moserpass credential-stealer
Moserpass is a credential-stealing malware family that primarily targets industries such as financial services, healthcare, and government.
Mosquito backdoorloader
Mosquito is a Win32 backdoor that has been used by Turla.
MostereRAT rat
According to Fortinet, this malware is written in Easy Programming Language (EPL), a Simplified-Chinese-based programming language…
Moth ransomware
Moth is a ransomware targeting multiple sectors, encrypting critical data and demanding ransom for decryption keys.
Mount Locker ransomware
Also known as Mount-Locker, DagonLocker, MountLocker. Mount Locker is a sophisticated ransomware that not only encrypts files on targeted systems, but also exfiltrates sensitive data to use in…
Mountlocket ransomware
Mountlocket is a type of ransomware that encrypts files on compromised machines, demanding a ransom for decryption keys.
Moure trojan
Moure is a banking trojan known for targeting financial platforms to exfiltrate sensitive banking information.
Mozi botnetddos
Mozi is a IoT botnet, that makes use of P2P for communication and reuses source code of other well-known malware families, including…
Mr.Dec ransomware
Also known as MrDec, Sherminator. Mr. Dec ransomware is cryptovirus that was first spotted in mid-May 2018, and since then was updated multiple times. The ransomware…
Mr.Locker ransomware
Mr.Locker is a type of ransomware known for encrypting files on infected systems and demanding payment for their release.
Mr403Forbidden ransomware
Mr403Forbidden is a ransomware known for encrypting files on infected systems, demanding a ransom for decryption.
MrDec ransomware
MrDec is a ransomware family that encrypts victims' files, demanding a ransom for their decryption.
MrPeter ransomware
MrPeter is a ransomware strain known for targeting government and financial sectors, encrypting data and demanding a ransom for decryption…
Msupedge trojanspyware
Msupedge is a sophisticated trojan used for cyber espionage and information theft.
MuchLove ransomware
MuchLove is a type of ransomware designed to encrypt files on infected systems and demand a ransom payment for decryption keys.
MuddyC2Go rattrojan
MuddyC2Go is a remote access Trojan known to be used by the MuddyWater threat actor group.
MuddyViper backdoor
MuddyViper is custom backdoor written in C and C++ used by MuddyWater for command and control (C2) communications and persistence.
Mudwater backdoorrat
Mudwater is a sophisticated remote access trojan (RAT) known for targeting governmental and financial sectors.
Mughthesec
Mughthesec is a type of adware that primarily targets macOS systems.
Muhstik ransomware
Muhstik is a ransomware strain known for targeting publicly exposed web application frameworks and database management systems.
MulCom backdoortrojan
MulCom is a sophisticated malware family known for targeting government and technology sectors.
MultiLayer Wiper wiper
MultiLayer Wiper is wiper malware written in .NET associated with Agrius operations.
Multigrain POS credential-stealer
Multigrain POS is a malware specifically designed to target point-of-sale systems, primarily used to steal credit card data.
Mumblehard botnetbackdoor
Mumblehard is a malware family known for sending spam emails.
Murofet botnetcredential-stealer
Also known as Licat. According to bin.re, Murofet, also called LICAT, is a member of the ZeuS family.
Mutabaha credential-stealerransomware
Mutabaha is a malware family known for its malicious activities targeting financial services and government sectors.
MyDogs rat
MyDogs is a remote access tool (RAT) that is often used for gaining unauthorized access to systems.
MyDoom backdoorddosworm
Also known as Mimail, Novarg. When executed, the worm opens up Windows' Notepad with garbage data in it.
MyKings Spreader cryptominerworm
MyKings Spreader is a self-propagating malware primarily used to distribute cryptominers.
Mydecryptor ransomware
Mydecryptor is a ransomware family known for encrypting victims' files and demanding a ransom for decryption.
MyloBot botnettrojan
Also known as FakeDGA, WillExec. According to PCrisk, MyloBot is a high-risk trojan-type virus that allows cyber criminals to control the infected machine.
MysteryBot trojankeyloggerransomware
MysteryBot is an Android banking Trojan with overlay capabilities with support for Android 7/8 but also provides other features such as…
MysterySnail rat
MysterySnail is a remote access trojan (RAT) often used in cyber espionage campaigns targeting technology and government sectors.
Mystic ransomware
Mystic is a ransomware family known for targeting critical sectors like healthcare, financial services, and the public sector.
Mystic Stealer credential-stealer
According to ZScaler, a new information stealer that was first advertised in April 2023, capable of stealing credentials from nearly 40…
Mythic rat
Mythic is an open source, cross-platform post-exploitation/command and control platform.
N-Splitter ransomware
N-Splitter is a Russian Koolova variant of ransomware known for encrypting files on infected systems, demanding a ransom for decryption.
N-W0rm worm
Also known as NWorm, nw0rm. N-W0rm, also known as NWorm or nw0rm, is a type of malicious software capable of self-replication and spreading across networks.
N2019cov ransomware
N2019cov is a type of ransomware that encrypts files on affected systems, demanding a ransom for decryption.
N3Cr0m0rPh botnetcryptominer
Also known as FreakOut, Necro. An IRC bot written in (obfuscated) Python code.