Malware Families page 32 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Mispadu trojan
- Also known as URSA. Mispadu is a banking trojan written in Delphi that was first observed in 2019 and uses a Malware-as-a-Service (MaaS) business model.
- Miuref botnettrojan
- Miuref is a variant of the Zeus banking trojan known for forming botnets that facilitate credential theft and bank fraud.
- Mivast backdoor
- Mivast is a backdoor that has been used by Deep Panda.
- MiyaRAT rat
- According to Proofpoint, MiyaRAT is a remote access trojan (RAT) written in C++ that uses sockets for communications and has standard RAT…
- MoDi RAT rat
- MoDi RAT is a remote access trojan (RAT) known for being used in cyber espionage campaigns.
- MoSucker ratbackdoor
- MoSucker is a powerful backdoor - hacker's remote access tool.
- MoWare H.F.D ransomware
- MoWare H.F.D is a type of ransomware known for encrypting files and demanding a ransom from victims for decryption keys.
- Mobef ransomware
- Also known as Yakes, CryptoBit. Mobef is a ransomware family, also known as Yakes and CryptoBit, that encrypts files on the victim's system and demands a cryptocurrency…
- Mobef-JustFun ransomware
- Mobef-JustFun is a ransomware family designed to encrypt files on infected systems, targeting various industries.
- MobiRAT rat
- MobiRAT is a remote access tool targeting Android devices, often used to remotely control smartphones and gather data without users'…
- MobileOrder trojan
- MobileOrder is a Trojan intended to compromise Android mobile devices.
- Mocky LNK downloadertrojan
- LNK files used to lure and orchestrate execution of various scripts, interacting with the Mocky API service.
- Mocton rat
- Mocton is a remote access tool primarily used for cyber espionage.
- ModPOS trojan
- Also known as straxbot. ModPOS is a sophisticated point-of-sale malware targeting the retail and hospitality sectors.
- ModPipe credential-stealer
- ModPipe is point-of-sale (POS) malware capable of accessing sensitive information stored in devices running ORACLE MICROS Restaurant…
- ModernLoader ratloader
- Also known as AvatarBot. According to PCrisk, ModernLoader, also known as Avatar Bot and AvatarLoader, is a malicious program that has minimalistic loader and RAT…
- Mofksys trojan
- Mofksys is a trojan malware with capabilities to infiltrate government and technology sectors.
- MofoTro rat
- MofoTro is a newly identified remote access trojan (RAT) developed by the hacker Cool_mofo_2.
- Moisha rattrojan
- Moisha is a remote access tool (RAT) primarily used for espionage and stealing sensitive information from targeted systems.
- Moisha Ransomware ransomware
- Moisha is a .NET-based ransomware that employs double extortion techniques to encrypt and exfiltrate data from victims.
- Moker backdoor
- Moker is a backdoor malware that is capable of evading detection and gaining persistence on infected systems.
- Mokes (ELF) backdoorrat
- Mokes is a cross-platform remote access trojan that targets Linux systems as an ELF binary.
- Mokes (OS X) ratbackdoor
- Mokes, also known as Spreadtrum, is a cross-platform Remote Access Tool (RAT) targeting OS X, Linux, and Windows operating systems.
- Mokes (Windows) ratbackdoor
- Mokes, also known as a Remote Access Trojan (RAT), is a multi-platform malware family capable of targeting Windows systems.
- Mole rat
- Mole is a remote access trojan (RAT) used primarily for espionage purposes.
- MoleNet downloaderbackdoor
- MoleNet is a downloader tool with backdoor capabilities that has been observed in use since at least 2019.
- Molerat Loader loader
- Molerat Loader is a malware used by threat groups primarily targeting the Middle East.
- Momentum backdoor
- Momentum is a malware backdoor used for remote access and control.
- Monero Miner cryptominer
- Also known as CoinMiner. According to ESET, first seen in-the-wild on 26th May, 2017, the malicious mining software is a fork of a legitimate open source Monero…
- MoneroPay ransomware
- MoneroPay is a type of ransomware designed to encrypt files on a victim's computer, demanding payment in the cryptocurrency Monero for…
- Moneybird ransomware
- Moneybird is a ransomware variant written in C++ associated with Agrius operations.
- Mongall backdoor
- Mongall is a backdoor that has been used since at least 2013, including by Aoqin Dragon.
- Mongo Lock ransomwarewiper
- An attack called Mongo Lock is targeting remotely accessible and unprotected MongoDB databases, wiping them, and then demanding a ransom…
- MongoLock ransomware
- MongoLock is a ransomware that targets improperly secured MongoDB databases, encrypting their data and demanding ransom payments from…
- Monokle spyware
- Monokle is targeted, sophisticated mobile surveillanceware.
- MonsterV2 credential-stealer
- Also known as Aurotun Stealer. MonsterV2, also known as Aurotun Stealer, is a credential-stealing malware.
- Monte ransomware
- Monte is a ransomware family that encrypts files on infected systems and demands a ransom for the decryption key.
- Monti ransomware
- Monti is a ransomware family that primarily targets governmental and technology sectors.
- MontysThree spyware
- Also known as MT3. MontysThree, also known as MT3, is a cyber-espionage malware primarily attributed to state-sponsored threat actors.
- Monument ransomware
- Ransomware Use the DarkLocker 5 porn screenlocker - Jigsaw variant
- MooBot botnetddos
- MooBot is a botnet malware known for targeting IoT devices to perform distributed denial-of-service (DDoS) attacks.
- MoonBounce rootkittrojan
- MoonBounce is a malware embedded into a modified UEFI firmware.
- MoonCryptor ransomware
- MoonCryptor is a ransomware that targets various sectors such as healthcare, finance, and government.
- MoonPeak rat
- According to Cisco Talos, this RAT is derived from the open source XenoRAT.
- MoonRise rat
- MoonRise is a remote access trojan (RAT) primarily used for cyber espionage activities.
- MoonWalk rattrojan
- Also known as CurveLast, SneakCross. MoonWalk is a remote access trojan aimed at gaining unauthorized access to sensitive systems, primarily targeting government, financial…
- MoonWind rat
- MoonWind is a remote access tool (RAT) that was used in 2016 to target organizations in Thailand.
- Moose botnet
- Moose is a Linux-based botnet malware known for its capability to compromise and control routers and IoT devices.
- MoqHao droppertrojan
- Also known as Shaoye, Wroba, XLoader. MoqHao, also called Wroba and XLoader (not to be confused with the malware of the same name for Windows and macOS), is an Android-based…
- Mordor ransomware
- Mordor is a ransomware family known for targeting critical industries and encrypting data to extort victims for payment.
- More_eggs backdoorloader
- Also known as SKID, Terra Loader, SpicyOmelette. More_eggs is a JScript backdoor used by Cobalt Group and FIN6.
- Mori backdoorrat
- Mori is a backdoor that has been used by MuddyWater since at least January 2022.
- MoriAgent rat
- MoriAgent is a sophisticated remote access trojan used primarily in cyber-espionage campaigns.
- Moriya backdoor
- This tool is a passive backdoor which allows attackers to inspect all incoming traffic to the infected machine, filter out packets that…
- Morpheus Loader loader
- Morpheus Loader is a malware family used for facilitating the delivery and execution of additional payloads onto compromised systems.
- Morphine trojanransomware
- Morphine is a malware family known for deploying trojan and ransomware capabilities, primarily targeting financial services and government…
- MorrisBatchCrypt ransomware
- MorrisBatchCrypt is a ransomware variant known for encrypting files and demanding a ransom payment for decryption.
- Mortis ransomware
- Mortis is a ransomware family known for encrypting victim files and demanding ransom payments for decryption.
- Morto worm
- Morto is a network worm that spreads by exploiting weak passwords in the Windows Remote Desktop Protocol.
- MosaicRegressor backdoor
- MosaicRegressor is a modular malware framework used by threat actors to persist on UEFI firmware.
- Moserpass credential-stealer
- Moserpass is a credential-stealing malware family that primarily targets industries such as financial services, healthcare, and government.
- Mosquito backdoorloader
- Mosquito is a Win32 backdoor that has been used by Turla.
- MostereRAT rat
- According to Fortinet, this malware is written in Easy Programming Language (EPL), a Simplified-Chinese-based programming language…
- Moth ransomware
- Moth is a ransomware targeting multiple sectors, encrypting critical data and demanding ransom for decryption keys.
- Mount Locker ransomware
- Also known as Mount-Locker, DagonLocker, MountLocker. Mount Locker is a sophisticated ransomware that not only encrypts files on targeted systems, but also exfiltrates sensitive data to use in…
- Mountlocket ransomware
- Mountlocket is a type of ransomware that encrypts files on compromised machines, demanding a ransom for decryption keys.
- Moure trojan
- Moure is a banking trojan known for targeting financial platforms to exfiltrate sensitive banking information.
- Mozi botnetddos
- Mozi is a IoT botnet, that makes use of P2P for communication and reuses source code of other well-known malware families, including…
- Mr.Dec ransomware
- Also known as MrDec, Sherminator. Mr. Dec ransomware is cryptovirus that was first spotted in mid-May 2018, and since then was updated multiple times. The ransomware…
- Mr.Locker ransomware
- Mr.Locker is a type of ransomware known for encrypting files on infected systems and demanding payment for their release.
- Mr403Forbidden ransomware
- Mr403Forbidden is a ransomware known for encrypting files on infected systems, demanding a ransom for decryption.
- MrDec ransomware
- MrDec is a ransomware family that encrypts victims' files, demanding a ransom for their decryption.
- MrPeter ransomware
- MrPeter is a ransomware strain known for targeting government and financial sectors, encrypting data and demanding a ransom for decryption…
- Msupedge trojanspyware
- Msupedge is a sophisticated trojan used for cyber espionage and information theft.
- MuchLove ransomware
- MuchLove is a type of ransomware designed to encrypt files on infected systems and demand a ransom payment for decryption keys.
- MuddyC2Go rattrojan
- MuddyC2Go is a remote access Trojan known to be used by the MuddyWater threat actor group.
- MuddyViper backdoor
- MuddyViper is custom backdoor written in C and C++ used by MuddyWater for command and control (C2) communications and persistence.
- Mudwater backdoorrat
- Mudwater is a sophisticated remote access trojan (RAT) known for targeting governmental and financial sectors.
- Mughthesec
- Mughthesec is a type of adware that primarily targets macOS systems.
- Muhstik ransomware
- Muhstik is a ransomware strain known for targeting publicly exposed web application frameworks and database management systems.
- MulCom backdoortrojan
- MulCom is a sophisticated malware family known for targeting government and technology sectors.
- MultiLayer Wiper wiper
- MultiLayer Wiper is wiper malware written in .NET associated with Agrius operations.
- Multigrain POS credential-stealer
- Multigrain POS is a malware specifically designed to target point-of-sale systems, primarily used to steal credit card data.
- Mumblehard botnetbackdoor
- Mumblehard is a malware family known for sending spam emails.
- Murofet botnetcredential-stealer
- Also known as Licat. According to bin.re, Murofet, also called LICAT, is a member of the ZeuS family.
- Mutabaha credential-stealerransomware
- Mutabaha is a malware family known for its malicious activities targeting financial services and government sectors.
- MyDogs rat
- MyDogs is a remote access tool (RAT) that is often used for gaining unauthorized access to systems.
- MyDoom backdoorddosworm
- Also known as Mimail, Novarg. When executed, the worm opens up Windows' Notepad with garbage data in it.
- MyKings Spreader cryptominerworm
- MyKings Spreader is a self-propagating malware primarily used to distribute cryptominers.
- Mydecryptor ransomware
- Mydecryptor is a ransomware family known for encrypting victims' files and demanding a ransom for decryption.
- MyloBot botnettrojan
- Also known as FakeDGA, WillExec. According to PCrisk, MyloBot is a high-risk trojan-type virus that allows cyber criminals to control the infected machine.
- MysteryBot trojankeyloggerransomware
- MysteryBot is an Android banking Trojan with overlay capabilities with support for Android 7/8 but also provides other features such as…
- MysterySnail rat
- MysterySnail is a remote access trojan (RAT) often used in cyber espionage campaigns targeting technology and government sectors.
- Mystic ransomware
- Mystic is a ransomware family known for targeting critical sectors like healthcare, financial services, and the public sector.
- Mystic Stealer credential-stealer
- According to ZScaler, a new information stealer that was first advertised in April 2023, capable of stealing credentials from nearly 40…
- Mythic rat
- Mythic is an open source, cross-platform post-exploitation/command and control platform.
- N-Splitter ransomware
- N-Splitter is a Russian Koolova variant of ransomware known for encrypting files on infected systems, demanding a ransom for decryption.
- N-W0rm worm
- Also known as NWorm, nw0rm. N-W0rm, also known as NWorm or nw0rm, is a type of malicious software capable of self-replication and spreading across networks.
- N2019cov ransomware
- N2019cov is a type of ransomware that encrypts files on affected systems, demanding a ransom for decryption.
- N3Cr0m0rPh botnetcryptominer
- Also known as FreakOut, Necro. An IRC bot written in (obfuscated) Python code.