Malware Families page 34 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Ngioweb (ELF) downloaderbackdoor
- Ngioweb is a modular malware primarily affecting Linux systems, commonly used to download additional payloads and provide backdoor access…
- Ngioweb (Windows) backdoortrojan
- Also known as Grobios. Ngioweb, also known as Grobios, is a backdoor trojan that primarily targets Windows systems.
- NgrBot botnetcredential-stealer
- NgrBot is a piece of malware known for forming part of a botnet and stealing user credentials.
- Ngrok
- Nhtnwcuf ransomwarewiper
- Ransomware Does not encrypt the files / Files are destroyed
- Nhtnwcuf Ransomware (Fake) ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Nibiru trojanransomware
- Nibiru is a sophisticated piece of malware primarily targeting financial institutions and governmental organizations.
- Nidiran backdoor
- Also known as Backdoor.Nidiran. Nidiran is a custom backdoor developed and used by Suckfly.
- NightClub ratspyware
- NightClub is a modular implant written in C++ that has been used by MoustachedBouncer since at least 2014.
- Nightdoor backdoor
- Also known as NetMM, Suzafk. Nightdoor is a backdoor exclusively associated with Daggerfly operations.
- Nighthawk rat
- Nighthawk is a command-and-control (C2) framework used primarily for remote access and administration.
- Nightmare ransomware
- Nightmare is a ransomware family that encrypts data on infected systems demanding a ransom for decryption.
- Nightrunner webshell
- Nightrunner is a webshell used to gain unauthorized access to compromised web servers.
- NightshadeC2 (Python) ratkeyloggerscreen-capture
- According to eSentire, NightshadeC2 demonstrates an extensive capability set, including: Reverse shell via Command Prompt/PowerShell…
- NightshadeC2 (Windows) ratkeyloggerscreen-capture
- Also known as CastleRAT. According to eSentire, NightshadeC2 demonstrates an extensive capability set, including: Reverse shell via Command Prompt/PowerShell…
- Nightsky ransomware
- Also known as Night Sky. Nightsky is a ransomware family that targets manufacturing industries, primarily in the United States.
- NikiHTTP backdoorscreen-capture
- NikiHTTP is a versatile backdoor and has multiple capabilities such as download of files, executing them, performing commands, take…
- NikiTeaR ratscreen-captureloader
- NikiTeaR is a sophisticated, custom-developed RAT, which is a rewritten variant of the NikiHTTP (aka NikiTea) RAT.
- NimBlackout exploit-kit
- According to its author, NimBlackout is an adaptation of the @Blackout project originally developed in C++ by @ZeroMemoryEx, which…
- NimGrabber credential-stealerspyware
- Malware written in Nim, stealing data including discord tokens from browsers, exfiltrating the results via a Discord webhook.
- NimbleMamba rat
- NimbleMamba is a new implant used by TA402/Molerats group as replacement of LastConn.
- Nimbo-C2 (ELF) rat
- According to the author, Nimbo-C2 is yet another (simple and lightweight) C2 framework.
- Nimbo-C2 (Windows) rat
- According to the author, Nimbo-C2 is yet another (simple and lightweight) C2 framework.
- Nimplant rat
- Part of Mythic C2, written in Nim. Considered deprecated, as it is only compatible with Mythic 2.1.
- Nimrev backdoor
- Nimrev is a backdoor malware written in the Nim programming language.
- NineRAT rat
- NineRAT is a remote access Trojan that allows attackers to gain unauthorized access and control of infected systems.
- Ninja rat
- Ninja is a malware developed in C++ that has been used by ToddyCat to penetrate networks and control remote systems since at least 2020.
- NinjaLoc ransomware
- NinjaLoc is a ransomware strain known for encrypting files and demanding a ransom for decryption keys.
- NirCmd
- NirCmd is a benign tool by NirSoft that provides various functionalities.
- Nitol botnetddos
- Nitol is a type of malware identified as a botnet that is often used for distributed denial-of-service (DDoS) attacks.
- Nitro ransomware
- Also known as Hydra. Ransomware family which requires payment in Discord gift cards ("Discord Nitro").
- Nitrogen Loader loader
- Nitrogen Loader is a sophisticated malware framework used for deploying various malicious payloads.
- Nitrogen Ransomware ransomware
- This ransomware has much in common with the LukaLocker ransomware.
- Nitrokod cryptominer
- Nitrokod is a Turkish cryptominer campaign known for distributing cryptocurrency mining software disguised as popular software applications.
- NiuB rat
- Golang-based RAT that offers execution of shell commands and download+run capability.
- NixScare Stealer credential-stealer
- NixScare Stealer is a malware variant focused on harvesting credentials from infected systems.
- Nltest
- Nltest is a Windows command-line utility used to list domain controllers and enumerate domain trusts.
- No-Justice ransomware
- No-Justice is a ransomware variant known for targeting government and financial sectors, employing encryption to hold data hostage until a…
- NoaBot botnet
- NoaBot is a malware family often associated with botnet activities.
- Noblis ransomware
- Noblis is a type of ransomware designed to encrypt files on infected systems and demand a ransom for the decryption key.
- Nocturnal Stealer credential-stealer
- Nocturnal Stealer is a credential-stealing malware family designed to extract sensitive information such as login credentials from…
- NodeCordRAT ratcredential-stealerscreen-capture
- NodeCordRAT is a cross-platform Remote Access Trojan and information stealer written in Node.js that targets Windows, macOS, and Linux…
- NodeJS Ransomware ransomware
- NodeJS Ransomware is a type of ransomware that downloads and utilizes NodeJS when deployed.
- NodeRAT rat
- NodeRAT is a remote access tool developed using JavaScript.
- NodeStealer credential-stealer
- NodeStealer is a malicious software primarily used for stealing credentials from infected systems.
- Nodera Ransomware ransomware
- Also known as Nodera. Nodera is a ransomware family that uses the Node.js framework and was discovered by Quick Heal researchers.
- Nog4yH4n ransomware
- Nog4yH4n is a type of ransomware that encrypts files on a victim's system, demanding a ransom for decryption.
- Nokoyawa ransomware
- Nokoyawa is a ransomware malware family known for targeting various industries and encrypting files for financial gain.
- Nokoyawa Ransomware ransomware
- Nokoyawa Ransomware is a malicious software variant known for encrypting files on infected systems, demanding ransom payments for…
- Nomikon ransomware
- Nomikon is a ransomware that encrypts files on infected systems and demands a ransom for decryption keys.
- NominatusToxicBattery wipervirus
- A wiper that overwrites target files with itself, thus spreading in virus-fashion.
- NonEuclid RAT rat
- Also known as LiberiumRAT, ShadowRoot, SheetRAT. NonEuclid RAT is a sophisticated remote access tool used primarily for cyber espionage activities.
- NoobCrypt ransomware
- NoobCrypt is a ransomware that encrypts files on the infected system and demands a ransom for decryption.
- Nood RAT rat
- Nood RAT is a remote access Trojan that allows attackers to gain control over infected systems.
- Nopyfy ransomware
- Nopyfy is a type of ransomware that encrypts files on infected systems and demands payment for decryption keys.
- NorthStar rat
- An open source C2 framework intended for pentest and red teaming activities.
- Nosedive botnetddosdropper
- According to Black Lotus Labs, Nosedive is a custom variation of the Mirai implant that is supported on all major SOHO and IoT…
- Nosu credential-stealer
- According to PCrisk, Nosu is the name of a malicious program classified as a stealer.
- NosyDownloader downloader
- According to ESET Research, this malware is used by LongNosedGoblin and executes a chain of obfuscated commands passed to a spawned…
- NotAHero ransomware
- NotAHero is a ransomware family known for encrypting files on infected systems and demanding ransom payments for decryption keys.
- NotCompatible botnettrojan
- NotCompatible is an Android malware family that was used between at least 2014 and 2016.
- NotPetya wiperwormransomware
- Also known as ExPetr, Diskcoder.C, GoldenEye. NotPetya is malware that was used by Sandworm Team in a worldwide attack starting on June 27, 2017.
- Nova Stealer credential-stealerscreen-capturetrojan
- Also known as Malicord. Nova Stealer is a new information stealer that is offered as Malware-as-a-Service by a new French-speaking actor called "Nova Sentinel".
- NoxPlayer spyware
- NoxPlayer is an Android emulator that was targeted by threat actors due to vulnerabilities in its software update mechanism, allowing them…
- Nozelesn ransomware
- Nozelesn is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption.
- Nozelesn (Decryptor) ransomware
- Nozelesn is a ransomware strain targeting primarily Ukrainian entities, often encrypting files and demanding a ransom for decryption.
- Ntospy credential-stealer
- Ntospy is a credential stealer leveraging a well-established technique of abusing the Windows Network Provider interface, a method…
- Nuclear RAT ratbackdoor
- Nuclear RAT (short for Nuclear Remote Administration Tool) is a backdoor trojan horse that infects Windows NT family systems (Windows…
- NuggetPhantom ratcryptominer
- NSFOCUS describes PhantomNugget as a modularized malware toolkit, that was spread using EternalBlue.
- Nuke ransomware
- Nuke is a type of ransomware that encrypts files on the infected system and demands a ransom for decryption.
- NukeSped trojandownloaderspyware
- This threat can install other malware on your PC, including Trojan:Win32/NukeSped.B!dha and Trojan:Win32/NukeSped.C!dha.
- Nullbyte ransomware
- Ransomware
- Nullmixer dropperloader
- Nullmixer is a dropper/loader for additional malware.
- Nulltica ransomware
- Nulltica is known for encrypting user data and demanding ransom for decryption.
- Numando trojancredential-stealer
- According to PCrisk, Numando is a banking trojan written in the Delphi programming language.
- Nx / OSR ransomware
- Nx / OSR is a ransomware variant known for encrypting files on victim systems and demanding a payment for decryption keys.
- Nymaim downloaderransomwaretrojan
- Also known as nymain. Nymaim is a trojan downloader. It downloads (and runs) other malware on affected systems and was one of the primary malware families…
- Nymaim2 ransomwaretrojan
- According to bin.re, in April 2018 a new version of Nymaim appeared, that has dropped previous obfuscation, and uses a new wordlist based…
- Nyton ransomware
- Nyton is a type of ransomware that encrypts files on infected systems, demanding payment for decryption keys.
- Nytro
- Nytro is a relatively obscure piece of malware for which limited public information is available.
- Nyxem wormvirus
- Nyxem is a computer virus and worm known for spreading through email attachments.
- OATBOAT loader
- OATBOAT is a loader that loads and executes shellcode payloads.
- OBAD trojan
- OBAD is an Android malware family known for its complex functionality and capability of obfuscation.
- OCEANMAP backdoorrat
- OCEANMAP is a sophisticated remote access tool (RAT) used by state-sponsored actors to conduct espionage against government and defense…
- OCT ransomware
- Also known as OctEncrypt. OCT, also known as OctEncrypt, is a ransomware family that encrypts files on infected systems and demands ransom payments for decryption…
- ODAgent downloader
- ODAgent is a C#/.NET downloader that has been used by OilRig since at least 2022 including against target organizations in Israel to…
- ODCODC ransomware
- ODCODC is a ransomware that encrypts files on the infected system and demands a ransom in exchange for the decryption key.
- OFFODE exploit-kit
- According to the author, this is a project that will give understanding of bypassing Multi Factor Authentication (MFA) of an outlook…
- OLDBAIT credential-stealer
- Also known as Sasfis. OLDBAIT is a credential harvester associated with APT28, targeting government and defense sectors primarily in Ukraine and the United…
- OMG! Ransomware ransomware
- Also known as GPCode. Ransomware. Infection: drive-by-download; Platform: Windows; Extorsion by Prepaid Voucher
- ONHAT rat
- ONHAT is a remote access tool (RAT) used primarily in cyber espionage operations.
- ONI ransomwarewiper
- ONI is a ransomware primarily targeting organizations in Japan, often used in conjunction with wiper malware to exfiltrate and destroy data.
- ONYX Ransomeware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- OPdailyallowance ransomware
- OPdailyallowance is a ransomware family known for targeting critical industries such as public sector and healthcare.
- ORANGEADE dropper
- FireEye details ORANGEADE as a dropper for the CREAMSICLE malware.
- ORPCBackdoor backdoor
- ORPCBackdoor is a backdoor malware used primarily for cyber espionage purposes.
- OSAMiner cryptominer
- OSAMiner is a cryptominer malware primarily targeting macOS systems, known for its obfuscation techniques.
- OSInfo spyware
- OSInfo is a custom tool used by APT3 to do internal discovery on a victim's computer and network.
- OSX/Shlayer trojan
- Also known as Zshlayer, Crossrider. OSX/Shlayer is a Trojan designed to install adware on macOS that was first discovered in 2018.
- OSX_OCEANLOTUS.D backdoor
- Also known as Backdoor.MacOS.OCEANLOTUS.F. OSX_OCEANLOTUS.D is a macOS backdoor used by APT32.