Malware Families page 34 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Ngioweb (ELF) downloaderbackdoor
Ngioweb is a modular malware primarily affecting Linux systems, commonly used to download additional payloads and provide backdoor access…
Ngioweb (Windows) backdoortrojan
Also known as Grobios. Ngioweb, also known as Grobios, is a backdoor trojan that primarily targets Windows systems.
NgrBot botnetcredential-stealer
NgrBot is a piece of malware known for forming part of a botnet and stealing user credentials.
Ngrok
Nhtnwcuf ransomwarewiper
Ransomware Does not encrypt the files / Files are destroyed
Nhtnwcuf Ransomware (Fake) ransomware
This is most likely to affect English speaking users, since the note is written in English.
Nibiru trojanransomware
Nibiru is a sophisticated piece of malware primarily targeting financial institutions and governmental organizations.
Nidiran backdoor
Also known as Backdoor.Nidiran. Nidiran is a custom backdoor developed and used by Suckfly.
NightClub ratspyware
NightClub is a modular implant written in C++ that has been used by MoustachedBouncer since at least 2014.
Nightdoor backdoor
Also known as NetMM, Suzafk. Nightdoor is a backdoor exclusively associated with Daggerfly operations.
Nighthawk rat
Nighthawk is a command-and-control (C2) framework used primarily for remote access and administration.
Nightmare ransomware
Nightmare is a ransomware family that encrypts data on infected systems demanding a ransom for decryption.
Nightrunner webshell
Nightrunner is a webshell used to gain unauthorized access to compromised web servers.
NightshadeC2 (Python) ratkeyloggerscreen-capture
According to eSentire, NightshadeC2 demonstrates an extensive capability set, including: Reverse shell via Command Prompt/PowerShell…
NightshadeC2 (Windows) ratkeyloggerscreen-capture
Also known as CastleRAT. According to eSentire, NightshadeC2 demonstrates an extensive capability set, including: Reverse shell via Command Prompt/PowerShell…
Nightsky ransomware
Also known as Night Sky. Nightsky is a ransomware family that targets manufacturing industries, primarily in the United States.
NikiHTTP backdoorscreen-capture
NikiHTTP is a versatile backdoor and has multiple capabilities such as download of files, executing them, performing commands, take…
NikiTeaR ratscreen-captureloader
NikiTeaR is a sophisticated, custom-developed RAT, which is a rewritten variant of the NikiHTTP (aka NikiTea) RAT.
NimBlackout exploit-kit
According to its author, NimBlackout is an adaptation of the @Blackout project originally developed in C++ by @ZeroMemoryEx, which…
NimGrabber credential-stealerspyware
Malware written in Nim, stealing data including discord tokens from browsers, exfiltrating the results via a Discord webhook.
NimbleMamba rat
NimbleMamba is a new implant used by TA402/Molerats group as replacement of LastConn.
Nimbo-C2 (ELF) rat
According to the author, Nimbo-C2 is yet another (simple and lightweight) C2 framework.
Nimbo-C2 (Windows) rat
According to the author, Nimbo-C2 is yet another (simple and lightweight) C2 framework.
Nimplant rat
Part of Mythic C2, written in Nim. Considered deprecated, as it is only compatible with Mythic 2.1.
Nimrev backdoor
Nimrev is a backdoor malware written in the Nim programming language.
NineRAT rat
NineRAT is a remote access Trojan that allows attackers to gain unauthorized access and control of infected systems.
Ninja rat
Ninja is a malware developed in C++ that has been used by ToddyCat to penetrate networks and control remote systems since at least 2020.
NinjaLoc ransomware
NinjaLoc is a ransomware strain known for encrypting files and demanding a ransom for decryption keys.
NirCmd
NirCmd is a benign tool by NirSoft that provides various functionalities.
Nitol botnetddos
Nitol is a type of malware identified as a botnet that is often used for distributed denial-of-service (DDoS) attacks.
Nitro ransomware
Also known as Hydra. Ransomware family which requires payment in Discord gift cards ("Discord Nitro").
Nitrogen Loader loader
Nitrogen Loader is a sophisticated malware framework used for deploying various malicious payloads.
Nitrogen Ransomware ransomware
This ransomware has much in common with the LukaLocker ransomware.
Nitrokod cryptominer
Nitrokod is a Turkish cryptominer campaign known for distributing cryptocurrency mining software disguised as popular software applications.
NiuB rat
Golang-based RAT that offers execution of shell commands and download+run capability.
NixScare Stealer credential-stealer
NixScare Stealer is a malware variant focused on harvesting credentials from infected systems.
Nltest
Nltest is a Windows command-line utility used to list domain controllers and enumerate domain trusts.
No-Justice ransomware
No-Justice is a ransomware variant known for targeting government and financial sectors, employing encryption to hold data hostage until a…
NoaBot botnet
NoaBot is a malware family often associated with botnet activities.
Noblis ransomware
Noblis is a type of ransomware designed to encrypt files on infected systems and demand a ransom for the decryption key.
Nocturnal Stealer credential-stealer
Nocturnal Stealer is a credential-stealing malware family designed to extract sensitive information such as login credentials from…
NodeCordRAT ratcredential-stealerscreen-capture
NodeCordRAT is a cross-platform Remote Access Trojan and information stealer written in Node.js that targets Windows, macOS, and Linux…
NodeJS Ransomware ransomware
NodeJS Ransomware is a type of ransomware that downloads and utilizes NodeJS when deployed.
NodeRAT rat
NodeRAT is a remote access tool developed using JavaScript.
NodeStealer credential-stealer
NodeStealer is a malicious software primarily used for stealing credentials from infected systems.
Nodera Ransomware ransomware
Also known as Nodera. Nodera is a ransomware family that uses the Node.js framework and was discovered by Quick Heal researchers.
Nog4yH4n ransomware
Nog4yH4n is a type of ransomware that encrypts files on a victim's system, demanding a ransom for decryption.
Nokoyawa ransomware
Nokoyawa is a ransomware malware family known for targeting various industries and encrypting files for financial gain.
Nokoyawa Ransomware ransomware
Nokoyawa Ransomware is a malicious software variant known for encrypting files on infected systems, demanding ransom payments for…
Nomikon ransomware
Nomikon is a ransomware that encrypts files on infected systems and demands a ransom for decryption keys.
NominatusToxicBattery wipervirus
A wiper that overwrites target files with itself, thus spreading in virus-fashion.
NonEuclid RAT rat
Also known as LiberiumRAT, ShadowRoot, SheetRAT. NonEuclid RAT is a sophisticated remote access tool used primarily for cyber espionage activities.
NoobCrypt ransomware
NoobCrypt is a ransomware that encrypts files on the infected system and demands a ransom for decryption.
Nood RAT rat
Nood RAT is a remote access Trojan that allows attackers to gain control over infected systems.
Nopyfy ransomware
Nopyfy is a type of ransomware that encrypts files on infected systems and demands payment for decryption keys.
NorthStar rat
An open source C2 framework intended for pentest and red teaming activities.
Nosedive botnetddosdropper
According to Black Lotus Labs, Nosedive is a custom variation of the Mirai implant that is supported on all major SOHO and IoT…
Nosu credential-stealer
According to PCrisk, Nosu is the name of a malicious program classified as a stealer.
NosyDownloader downloader
According to ESET Research, this malware is used by LongNosedGoblin and executes a chain of obfuscated commands passed to a spawned…
NotAHero ransomware
NotAHero is a ransomware family known for encrypting files on infected systems and demanding ransom payments for decryption keys.
NotCompatible botnettrojan
NotCompatible is an Android malware family that was used between at least 2014 and 2016.
NotPetya wiperwormransomware
Also known as ExPetr, Diskcoder.C, GoldenEye. NotPetya is malware that was used by Sandworm Team in a worldwide attack starting on June 27, 2017.
Nova Stealer credential-stealerscreen-capturetrojan
Also known as Malicord. Nova Stealer is a new information stealer that is offered as Malware-as-a-Service by a new French-speaking actor called "Nova Sentinel".
NoxPlayer spyware
NoxPlayer is an Android emulator that was targeted by threat actors due to vulnerabilities in its software update mechanism, allowing them…
Nozelesn ransomware
Nozelesn is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption.
Nozelesn (Decryptor) ransomware
Nozelesn is a ransomware strain targeting primarily Ukrainian entities, often encrypting files and demanding a ransom for decryption.
Ntospy credential-stealer
Ntospy is a credential stealer leveraging a well-established technique of abusing the Windows Network Provider interface, a method…
Nuclear RAT ratbackdoor
Nuclear RAT (short for Nuclear Remote Administration Tool) is a backdoor trojan horse that infects Windows NT family systems (Windows…
NuggetPhantom ratcryptominer
NSFOCUS describes PhantomNugget as a modularized malware toolkit, that was spread using EternalBlue.
Nuke ransomware
Nuke is a type of ransomware that encrypts files on the infected system and demands a ransom for decryption.
NukeSped trojandownloaderspyware
This threat can install other malware on your PC, including Trojan:Win32/NukeSped.B!dha and Trojan:Win32/NukeSped.C!dha.
Nullbyte ransomware
Ransomware
Nullmixer dropperloader
Nullmixer is a dropper/loader for additional malware.
Nulltica ransomware
Nulltica is known for encrypting user data and demanding ransom for decryption.
Numando trojancredential-stealer
According to PCrisk, Numando is a banking trojan written in the Delphi programming language.
Nx / OSR ransomware
Nx / OSR is a ransomware variant known for encrypting files on victim systems and demanding a payment for decryption keys.
Nymaim downloaderransomwaretrojan
Also known as nymain. Nymaim is a trojan downloader. It downloads (and runs) other malware on affected systems and was one of the primary malware families…
Nymaim2 ransomwaretrojan
According to bin.re, in April 2018 a new version of Nymaim appeared, that has dropped previous obfuscation, and uses a new wordlist based…
Nyton ransomware
Nyton is a type of ransomware that encrypts files on infected systems, demanding payment for decryption keys.
Nytro
Nytro is a relatively obscure piece of malware for which limited public information is available.
Nyxem wormvirus
Nyxem is a computer virus and worm known for spreading through email attachments.
OATBOAT loader
OATBOAT is a loader that loads and executes shellcode payloads.
OBAD trojan
OBAD is an Android malware family known for its complex functionality and capability of obfuscation.
OCEANMAP backdoorrat
OCEANMAP is a sophisticated remote access tool (RAT) used by state-sponsored actors to conduct espionage against government and defense…
OCT ransomware
Also known as OctEncrypt. OCT, also known as OctEncrypt, is a ransomware family that encrypts files on infected systems and demands ransom payments for decryption…
ODAgent downloader
ODAgent is a C#/.NET downloader that has been used by OilRig since at least 2022 including against target organizations in Israel to…
ODCODC ransomware
ODCODC is a ransomware that encrypts files on the infected system and demands a ransom in exchange for the decryption key.
OFFODE exploit-kit
According to the author, this is a project that will give understanding of bypassing Multi Factor Authentication (MFA) of an outlook…
OLDBAIT credential-stealer
Also known as Sasfis. OLDBAIT is a credential harvester associated with APT28, targeting government and defense sectors primarily in Ukraine and the United…
OMG! Ransomware ransomware
Also known as GPCode. Ransomware. Infection: drive-by-download; Platform: Windows; Extorsion by Prepaid Voucher
ONHAT rat
ONHAT is a remote access tool (RAT) used primarily in cyber espionage operations.
ONI ransomwarewiper
ONI is a ransomware primarily targeting organizations in Japan, often used in conjunction with wiper malware to exfiltrate and destroy data.
ONYX Ransomeware ransomware
This is most likely to affect English speaking users, since the note is written in English.
OPdailyallowance ransomware
OPdailyallowance is a ransomware family known for targeting critical industries such as public sector and healthcare.
ORANGEADE dropper
FireEye details ORANGEADE as a dropper for the CREAMSICLE malware.
ORPCBackdoor backdoor
ORPCBackdoor is a backdoor malware used primarily for cyber espionage purposes.
OSAMiner cryptominer
OSAMiner is a cryptominer malware primarily targeting macOS systems, known for its obfuscation techniques.
OSInfo spyware
OSInfo is a custom tool used by APT3 to do internal discovery on a victim's computer and network.
OSX/Shlayer trojan
Also known as Zshlayer, Crossrider. OSX/Shlayer is a Trojan designed to install adware on macOS that was first discovered in 2018.
OSX_OCEANLOTUS.D backdoor
Also known as Backdoor.MacOS.OCEANLOTUS.F. OSX_OCEANLOTUS.D is a macOS backdoor used by APT32.