Malware Families page 33 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- N3Tworm worm
- N3Tworm is a network-based malware notable for its ability to self-replicate and spread across connected systems.
- N40 botnet
- Botnet with focus on banks in Latin America and South America.
- NACHOCHEESE rat
- Also known as Cyruslish, TWOPENCE, VIVACIOUSGIFT. According to FireEye, NACHOCHEESE is a command-line tunneler that accepts delimited C&C IPs or domains via command-line and gives actors…
- NAPLISTENER trojanbackdoor
- NAPLISTENER is a stealthy backdoor trojan used primarily in cyber-espionage operations against government and financial sectors.
- NAS Data Compromiser ransomware
- The NAS Data Compromiser is a type of ransomware that targets network-attached storage (NAS) devices.
- NBTscan
- NBTscan is an open source tool that has been used by state groups to conduct internal reconnaissance within a compromised network.
- NCrypt Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- NDiskMonitor backdoor
- NDiskMonitor is a custom backdoor written in .NET that appears to be unique to Patchwork.
- NESTEGG backdoor
- NESTEGG is a memory-only backdoor that can proxy commands to other infected systems using a custom routing scheme.
- NET-MONITOR PRO spywarescreen-capture
- Net Monitor for Employees lets you see what everyone's doing - without leaving your desk.
- NET-STAR backdoorloaderwebshell
- According to Unit 42, NET-STAR is a .NET malware suite designed to target Internet Information Services (IIS) web servers.
- NETEAGLE backdoor
- Also known as Neteagle_Scout, ScoutEagle. NETEAGLE is a backdoor developed by APT30 with compile dates as early as 2008.
- NETWIRE rat
- NETWIRE is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at…
- NGLite backdoortrojan
- NGLite is a backdoor Trojan that is only capable of running commands received through its C2 channel.
- NICECURL backdoor
- NICECURL is a VBScript-based backdoor used by APT42 to download additional modules.
- NKAbuse backdoortrojanddos
- NKAbuse is a Go-based, multi-platform malware abusing NKN (New Kind of Network) technology for data exchange between peers, functioning as…
- NM4 ransomware
- NM4 is a ransomware family known for encrypting files on the victim's system and demanding a ransom for recovery.
- NMCRYPT Ransomware ransomwaretrojan
- The NMCRYPT Ransomware is a generic file encryption Trojan that was detected in the middle of April 2018.
- NMoreia 2.0 Ransomware ransomware
- Also known as HakunaMatataRansomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- NMoreira ransomware
- Also known as XRatTeam, XPan. NMoreira, also known as XRatTeam or XPan, is a ransomware family that targets Brazilian entities, particularly in the financial and…
- NMoreira Ransomware ransomware
- Also known as Fake Maktub Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- NOKKI rat
- NOKKI is a modular remote access tool. The earliest observed attack using NOKKI was in January 2018. NOKKI has significant code overlap…
- NOOPLDR loader
- NOOPLDR is a shellcode loader with XML/C# and DLL versions that has been used by MirrorFace to load HiddenFace.
- NOROBOT botnetloader
- Also known as BAITSWITCH. NOROBOT, also known as BAITSWITCH, is a sophisticated botnet typically used to conduct various malicious operations such as data…
- NOTROBIN backdoor
- Also known as remove_bds. FireEye states that NOTROBIN is a utility written in Go 1.10 and compiled to a 64-bit ELF binary for BSD systems.
- NPPSPY credential-stealerspyware
- NPPSPY is an implementation of a theoretical mechanism first presented in 2004 for capturing credentials submitted to a Windows system via…
- NSPX30 rat
- NSPX30 is a remote access tool known to target government and technology sectors.
- NVISOSPIT rat
- NVISOSPIT is a remote access trojan (RAT) primarily used in cyber-espionage campaigns targeting governmental and defense sectors.
- NZMR ransomware
- NZMR is a ransomware variant that encrypts files on the victim's system, demanding a ransom payment for decryption.
- Naampa ransomware
- Naampa is a ransomware family that encrypts files on infected systems and demands payment in cryptocurrency.
- Nabucur ransomware
- Nabucur is a form of ransomware. It encrypts files on the victim's system, demanding payment in cryptocurrency for the decryption key…
- Nagini rat
- Nagini is a remote access tool (RAT) used to gain unauthorized access and control over computer systems.
- Nagini Ransomware ransomware
- Also known as Voldemort Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- Naid trojanbackdoor
- Naid is a trojan used by Elderwood to open a backdoor on compromised hosts.
- Naikon rat
- Also known as Sacto. Naikon is a cyber espionage malware attributed to a state-sponsored group focusing on intelligence gathering.
- NailaoLocker ransomware
- According to Orange Cybwerdefense, NailaoLocker is a ransomware using AES-256-CTR mode, which conveniently logs its encryption activities…
- Namaste ransomware
- Namaste is a ransomware variant that encrypts files on infected systems, demanding a ransom payment in exchange for decryption keys.
- NanHaiShu ratbackdoor
- NanHaiShu is a remote access tool and JScript backdoor used by Leviathan.
- NanoCore ratkeyloggerscreen-capture
- NanoCore is a modular remote access tool developed in .NET that can be used to spy on victims and steal information.
- NanoLocker ransomware
- NanoLocker is a type of ransomware that does not change file extensions and operates via a graphical user interface.
- Nanocore RAT ratcredential-stealerspyware
- Also known as Nancrat, NanoCore. Nanocore is a Remote Access Tool used to steal credentials and to spy on cameras.
- Narilam wiper
- Narilam is a malware that targets financial databases, specifically those used in Iran.
- NativeZone loader
- NativeZone is the name given collectively to disposable custom Cobalt Strike loaders used by APT29 since at least 2021.
- Nautilus trojanspyware
- Nautilus is a sophisticated malware family known for its espionage capabilities primarily targeting financial services and technology…
- NavRAT rat
- Also known as JinhoSpy. NavRAT is a remote access tool designed to upload, download, and execute files.
- NazCrypt ransomware
- NazCrypt is a type of ransomware that encrypts files on the victim's system and demands payment in exchange for a decryption key.
- Nebulae backdoor
- Nebulae Is a backdoor that has been used by Naikon since at least 2020.
- Neconyd backdoortrojan
- Neconyd is a backdoor Trojan used in cyber espionage campaigns, primarily targeting government and technology sectors.
- Necurs botnet
- Also known as nucurs. Necurs is a notorious malware family primarily known for its capabilities as a spam botnet.
- NedDnLoader downloader
- NedDnLoader is an HTTP(S) downloader that uses AES for C&C trafic encryption.
- Nefilim ransomware
- Also known as Nephilim. According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5.
- Negozl ransomware
- Negozl is a ransomware family known for targeting a wide range of industries with a focus on financial services and healthcare.
- Neitrino ransomware
- Neitrino is a ransomware variant that encrypts files on the infected system and demands a ransom payment for their recovery.
- NemeS1S Ransomware ransomware
- NemeS1S Ransomware is a Ransomware as a Service (RaaS) offering that allows affiliates to deploy ransomware attacks on a variety of targets.
- Nemesis rat
- Also known as Project Nemesis. Nemesis is a remote access trojan (RAT) primarily used for cyber espionage activities.
- Nemesis Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Nemim rat
- Also known as Nemain. Nemim, also known as Nemain, is a Remote Access Trojan (RAT) used primarily for cyber espionage.
- Nemty ransomware
- A new ransomware family dubbed “Nemty” for the extension it adds to encrypted files has recently surfaced in the wild.
- Nemucod ransomware
- Also known as Nemucod-7z, Nemucod-AES. Ransomware 7zip (a0.exe) variant cannot be decrypted Encrypts the first 2048 Bytes
- Neo-reGeorg webshell
- Neo-reGeorg is an open-source web shell designed as a restructuring of reGeorg with improved usability, security, and fixes for exising…
- Neoichor rat
- Neoichor is C2 malware used by Ke3chang since at least 2019; similar malware families used by the group include Leeson and Numbldea.
- Nerbian RAT rat
- Proofpoint observed distribution of this RAT since late April 2022, it is written on Go and incorporates code from various open-source Git…
- Nerex backdoortrojan
- Nerex is a Trojan used by Elderwood to open a backdoor on compromised hosts.
- Net
- Also known as net.exe. The Net utility is a component of the Windows operating system.
- Net Crawler wormcredential-stealer
- Also known as NetC. Net Crawler is an intranet worm capable of extracting credentials using credential dumpers and spreading to systems on a network over SMB…
- Net Devil rat
- Also known as NetDevil. Net Devil is a remote access trojan that allows attackers to control infected systems remotely.
- NetC trojan
- NetC is a malware family known for targeting financial and government sectors.
- NetDevil backdoorrat
- Backdoor.NetDevil allows a hacker to remotely control an infected computer.
- NetDooka ratloader
- A RAT written in .NET, delivered with a driver to protect it from deletion.
- NetFlash ratbackdoor
- NetFlash is a type of remote access trojan (RAT) known for its capabilities to install backdoors and maintain persistence on infected…
- NetKey backdoorrat
- NetKey is a remote access tool (RAT) associated with multiple cyber espionage campaigns.
- NetSpy spyware
- NetSpy is a freely available network reconnaissance tool used for collecting information within networks.
- NetSupportManager RAT rat
- Also known as NetSupport. Enigma Software notes that NetSupport Manager is a genuine application, which was first released about twenty years ago.
- NetTraveler spywarebackdoor
- Also known as TravNet. NetTraveler is malware that has been used in multiple cyber espionage campaigns for basic surveillance of victims.
- NetWire RC ratcredential-stealerkeylogger
- Also known as NetWeird, NetWire, Recam. Netwire is a RAT, its functionality seems focused on password stealing and keylogging, but includes remote control capabilities as well.
- NetWorm worm
- NetWorm is a network-propagating worm known for exploiting vulnerabilities to spread across systems and networks.
- Netbus backdoorrat
- NetBus or Netbus is a software program for remotely controlling a Microsoft Windows computer system over a network.
- NetfilterRootkit rootkit
- NetfilterRootkit is a WFP application layer enforcement callout driver which is signed by Microsoft via the Windows Hardware Compatibility…
- Netflix Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Netix ransomware
- Also known as RANSOM_NETIX.A. Netix is a ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
- Netrepser spywarebackdoor
- Netrepser is a spyware and backdoor toolkit associated with cyber-espionage campaigns, particularly targeting the Ukrainian government.
- Netsupport Manager rat
- NetSupport Manager continues to deliver the very latest in remote access, PC support and desktop management capabilities.
- Netwalker ransomware
- Netwalker is fileless ransomware written in PowerShell and executed directly in memory.
- Neuron rat
- Neuron is a Remote Access Trojan (RAT) primarily used for cyber-espionage.
- Neutrino botnetexploit-kit
- Also known as Kasidet. Neutrino, also known as Kasidet, is a malware family known for its exploit kit functionality, often used in cyber attacks against…
- Neutrino POS credential-stealer
- Neutrino POS is malware that targets point-of-sale systems to steal payment card information.
- Nevada ransomware
- Nevada is a ransomware family observed targeting several sectors including financial services and retail.
- NewBot Loader loader
- NewBot Loader is a type of malware designed to silently load and deliver malicious payloads onto compromised systems.
- NewBounce trojanransomware
- NewBounce is a type of malware that combines characteristics of both trojans and ransomware.
- NewCT trojancredential-stealer
- Also known as CT. NewCT, also known as CT, is a banking trojan designed to steal credentials from financial sector targets.
- NewCore rattrojan
- NewCore is a remote access trojan first discovered by Fortinet researchers while conducting analysis on a China-linked APT campaign…
- NewCore RAT rat
- NewCore RAT is a remote access trojan primarily targeting organizations in South Korea and Hong Kong.
- NewPass credential-stealer
- NewPass is a credential-stealing malware variant known for targeting user login information.
- NewPosThings trojan
- NewPosThings is a malware family that targets point-of-sale systems to steal credit card information.
- NewWave ransomware
- NewWave is a form of ransomware that encrypts files on infected systems and demands a ransom for decryption keys.
- NewsReels spywaretrojan
- NewsReels is a form of spyware targeting media outlets and government entities, focusing on information gathering and infiltration.
- Nexster Bot botnet
- Nexster Bot is a malware family known to create botnets for launching coordinated attacks.
- NextCry ransomware
- NextCry is a ransomware that targets Linux servers running NextCloud, encrypting user data and demanding a ransom for file decryption.
- Nexus botnetcredential-stealertrojan
- Nexus is a sophisticated banking trojan targeting financial institutions, primarily in North America and Europe.
- NexusLogger credential-stealerkeylogger
- NexusLogger is a credential-stealing malware often used to capture keystrokes and exfiltrate sensitive information.