Malware Families page 33 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

N3Tworm worm
N3Tworm is a network-based malware notable for its ability to self-replicate and spread across connected systems.
N40 botnet
Botnet with focus on banks in Latin America and South America.
NACHOCHEESE rat
Also known as Cyruslish, TWOPENCE, VIVACIOUSGIFT. According to FireEye, NACHOCHEESE is a command-line tunneler that accepts delimited C&C IPs or domains via command-line and gives actors…
NAPLISTENER trojanbackdoor
NAPLISTENER is a stealthy backdoor trojan used primarily in cyber-espionage operations against government and financial sectors.
NAS Data Compromiser ransomware
The NAS Data Compromiser is a type of ransomware that targets network-attached storage (NAS) devices.
NBTscan
NBTscan is an open source tool that has been used by state groups to conduct internal reconnaissance within a compromised network.
NCrypt Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
NDiskMonitor backdoor
NDiskMonitor is a custom backdoor written in .NET that appears to be unique to Patchwork.
NESTEGG backdoor
NESTEGG is a memory-only backdoor that can proxy commands to other infected systems using a custom routing scheme.
NET-MONITOR PRO spywarescreen-capture
Net Monitor for Employees lets you see what everyone's doing - without leaving your desk.
NET-STAR backdoorloaderwebshell
According to Unit 42, NET-STAR is a .NET malware suite designed to target Internet Information Services (IIS) web servers.
NETEAGLE backdoor
Also known as Neteagle_Scout, ScoutEagle. NETEAGLE is a backdoor developed by APT30 with compile dates as early as 2008.
NETWIRE rat
NETWIRE is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at…
NGLite backdoortrojan
NGLite is a backdoor Trojan that is only capable of running commands received through its C2 channel.
NICECURL backdoor
NICECURL is a VBScript-based backdoor used by APT42 to download additional modules.
NKAbuse backdoortrojanddos
NKAbuse is a Go-based, multi-platform malware abusing NKN (New Kind of Network) technology for data exchange between peers, functioning as…
NM4 ransomware
NM4 is a ransomware family known for encrypting files on the victim's system and demanding a ransom for recovery.
NMCRYPT Ransomware ransomwaretrojan
The NMCRYPT Ransomware is a generic file encryption Trojan that was detected in the middle of April 2018.
NMoreia 2.0 Ransomware ransomware
Also known as HakunaMatataRansomware. It’s directed to English speaking users, therefore is able to infect worldwide.
NMoreira ransomware
Also known as XRatTeam, XPan. NMoreira, also known as XRatTeam or XPan, is a ransomware family that targets Brazilian entities, particularly in the financial and…
NMoreira Ransomware ransomware
Also known as Fake Maktub Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
NOKKI rat
NOKKI is a modular remote access tool. The earliest observed attack using NOKKI was in January 2018. NOKKI has significant code overlap…
NOOPLDR loader
NOOPLDR is a shellcode loader with XML/C# and DLL versions that has been used by MirrorFace to load HiddenFace.
NOROBOT botnetloader
Also known as BAITSWITCH. NOROBOT, also known as BAITSWITCH, is a sophisticated botnet typically used to conduct various malicious operations such as data…
NOTROBIN backdoor
Also known as remove_bds. FireEye states that NOTROBIN is a utility written in Go 1.10 and compiled to a 64-bit ELF binary for BSD systems.
NPPSPY credential-stealerspyware
NPPSPY is an implementation of a theoretical mechanism first presented in 2004 for capturing credentials submitted to a Windows system via…
NSPX30 rat
NSPX30 is a remote access tool known to target government and technology sectors.
NVISOSPIT rat
NVISOSPIT is a remote access trojan (RAT) primarily used in cyber-espionage campaigns targeting governmental and defense sectors.
NZMR ransomware
NZMR is a ransomware variant that encrypts files on the victim's system, demanding a ransom payment for decryption.
Naampa ransomware
Naampa is a ransomware family that encrypts files on infected systems and demands payment in cryptocurrency.
Nabucur ransomware
Nabucur is a form of ransomware. It encrypts files on the victim's system, demanding payment in cryptocurrency for the decryption key…
Nagini rat
Nagini is a remote access tool (RAT) used to gain unauthorized access and control over computer systems.
Nagini Ransomware ransomware
Also known as Voldemort Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
Naid trojanbackdoor
Naid is a trojan used by Elderwood to open a backdoor on compromised hosts.
Naikon rat
Also known as Sacto. Naikon is a cyber espionage malware attributed to a state-sponsored group focusing on intelligence gathering.
NailaoLocker ransomware
According to Orange Cybwerdefense, NailaoLocker is a ransomware using AES-256-CTR mode, which conveniently logs its encryption activities…
Namaste ransomware
Namaste is a ransomware variant that encrypts files on infected systems, demanding a ransom payment in exchange for decryption keys.
NanHaiShu ratbackdoor
NanHaiShu is a remote access tool and JScript backdoor used by Leviathan.
NanoCore ratkeyloggerscreen-capture
NanoCore is a modular remote access tool developed in .NET that can be used to spy on victims and steal information.
NanoLocker ransomware
NanoLocker is a type of ransomware that does not change file extensions and operates via a graphical user interface.
Nanocore RAT ratcredential-stealerspyware
Also known as Nancrat, NanoCore. Nanocore is a Remote Access Tool used to steal credentials and to spy on cameras.
Narilam wiper
Narilam is a malware that targets financial databases, specifically those used in Iran.
NativeZone loader
NativeZone is the name given collectively to disposable custom Cobalt Strike loaders used by APT29 since at least 2021.
Nautilus trojanspyware
Nautilus is a sophisticated malware family known for its espionage capabilities primarily targeting financial services and technology…
NavRAT rat
Also known as JinhoSpy. NavRAT is a remote access tool designed to upload, download, and execute files.
NazCrypt ransomware
NazCrypt is a type of ransomware that encrypts files on the victim's system and demands payment in exchange for a decryption key.
Nebulae backdoor
Nebulae Is a backdoor that has been used by Naikon since at least 2020.
Neconyd backdoortrojan
Neconyd is a backdoor Trojan used in cyber espionage campaigns, primarily targeting government and technology sectors.
Necurs botnet
Also known as nucurs. Necurs is a notorious malware family primarily known for its capabilities as a spam botnet.
NedDnLoader downloader
NedDnLoader is an HTTP(S) downloader that uses AES for C&C trafic encryption.
Nefilim ransomware
Also known as Nephilim. According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5.
Negozl ransomware
Negozl is a ransomware family known for targeting a wide range of industries with a focus on financial services and healthcare.
Neitrino ransomware
Neitrino is a ransomware variant that encrypts files on the infected system and demands a ransom payment for their recovery.
NemeS1S Ransomware ransomware
NemeS1S Ransomware is a Ransomware as a Service (RaaS) offering that allows affiliates to deploy ransomware attacks on a variety of targets.
Nemesis rat
Also known as Project Nemesis. Nemesis is a remote access trojan (RAT) primarily used for cyber espionage activities.
Nemesis Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Nemim rat
Also known as Nemain. Nemim, also known as Nemain, is a Remote Access Trojan (RAT) used primarily for cyber espionage.
Nemty ransomware
A new ransomware family dubbed “Nemty” for the extension it adds to encrypted files has recently surfaced in the wild.
Nemucod ransomware
Also known as Nemucod-7z, Nemucod-AES. Ransomware 7zip (a0.exe) variant cannot be decrypted Encrypts the first 2048 Bytes
Neo-reGeorg webshell
Neo-reGeorg is an open-source web shell designed as a restructuring of reGeorg with improved usability, security, and fixes for exising…
Neoichor rat
Neoichor is C2 malware used by Ke3chang since at least 2019; similar malware families used by the group include Leeson and Numbldea.
Nerbian RAT rat
Proofpoint observed distribution of this RAT since late April 2022, it is written on Go and incorporates code from various open-source Git…
Nerex backdoortrojan
Nerex is a Trojan used by Elderwood to open a backdoor on compromised hosts.
Net
Also known as net.exe. The Net utility is a component of the Windows operating system.
Net Crawler wormcredential-stealer
Also known as NetC. Net Crawler is an intranet worm capable of extracting credentials using credential dumpers and spreading to systems on a network over SMB…
Net Devil rat
Also known as NetDevil. Net Devil is a remote access trojan that allows attackers to control infected systems remotely.
NetC trojan
NetC is a malware family known for targeting financial and government sectors.
NetDevil backdoorrat
Backdoor.NetDevil allows a hacker to remotely control an infected computer.
NetDooka ratloader
A RAT written in .NET, delivered with a driver to protect it from deletion.
NetFlash ratbackdoor
NetFlash is a type of remote access trojan (RAT) known for its capabilities to install backdoors and maintain persistence on infected…
NetKey backdoorrat
NetKey is a remote access tool (RAT) associated with multiple cyber espionage campaigns.
NetSpy spyware
NetSpy is a freely available network reconnaissance tool used for collecting information within networks.
NetSupportManager RAT rat
Also known as NetSupport. Enigma Software notes that NetSupport Manager is a genuine application, which was first released about twenty years ago.
NetTraveler spywarebackdoor
Also known as TravNet. NetTraveler is malware that has been used in multiple cyber espionage campaigns for basic surveillance of victims.
NetWire RC ratcredential-stealerkeylogger
Also known as NetWeird, NetWire, Recam. Netwire is a RAT, its functionality seems focused on password stealing and keylogging, but includes remote control capabilities as well.
NetWorm worm
NetWorm is a network-propagating worm known for exploiting vulnerabilities to spread across systems and networks.
Netbus backdoorrat
NetBus or Netbus is a software program for remotely controlling a Microsoft Windows computer system over a network.
NetfilterRootkit rootkit
NetfilterRootkit is a WFP application layer enforcement callout driver which is signed by Microsoft via the Windows Hardware Compatibility…
Netflix Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Netix ransomware
Also known as RANSOM_NETIX.A. Netix is a ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
Netrepser spywarebackdoor
Netrepser is a spyware and backdoor toolkit associated with cyber-espionage campaigns, particularly targeting the Ukrainian government.
Netsupport Manager rat
NetSupport Manager continues to deliver the very latest in remote access, PC support and desktop management capabilities.
Netwalker ransomware
Netwalker is fileless ransomware written in PowerShell and executed directly in memory.
Neuron rat
Neuron is a Remote Access Trojan (RAT) primarily used for cyber-espionage.
Neutrino botnetexploit-kit
Also known as Kasidet. Neutrino, also known as Kasidet, is a malware family known for its exploit kit functionality, often used in cyber attacks against…
Neutrino POS credential-stealer
Neutrino POS is malware that targets point-of-sale systems to steal payment card information.
Nevada ransomware
Nevada is a ransomware family observed targeting several sectors including financial services and retail.
NewBot Loader loader
NewBot Loader is a type of malware designed to silently load and deliver malicious payloads onto compromised systems.
NewBounce trojanransomware
NewBounce is a type of malware that combines characteristics of both trojans and ransomware.
NewCT trojancredential-stealer
Also known as CT. NewCT, also known as CT, is a banking trojan designed to steal credentials from financial sector targets.
NewCore rattrojan
NewCore is a remote access trojan first discovered by Fortinet researchers while conducting analysis on a China-linked APT campaign…
NewCore RAT rat
NewCore RAT is a remote access trojan primarily targeting organizations in South Korea and Hong Kong.
NewPass credential-stealer
NewPass is a credential-stealing malware variant known for targeting user login information.
NewPosThings trojan
NewPosThings is a malware family that targets point-of-sale systems to steal credit card information.
NewWave ransomware
NewWave is a form of ransomware that encrypts files on infected systems and demands a ransom for decryption keys.
NewsReels spywaretrojan
NewsReels is a form of spyware targeting media outlets and government entities, focusing on information gathering and infiltration.
Nexster Bot botnet
Nexster Bot is a malware family known to create botnets for launching coordinated attacks.
NextCry ransomware
NextCry is a ransomware that targets Linux servers running NextCloud, encrypting user data and demanding a ransom for file decryption.
Nexus botnetcredential-stealertrojan
Nexus is a sophisticated banking trojan targeting financial institutions, primarily in North America and Europe.
NexusLogger credential-stealerkeylogger
NexusLogger is a credential-stealing malware often used to capture keystrokes and exfiltrate sensitive information.