Malware Families page 35 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- OXAR ransomware
- OXAR is a ransomware family known for targeting the financial and government sectors.
- OZH RAT rat
- OZH RAT is a remote access trojan used primarily for cyber espionage.
- Oblique RAT ratspyware
- Oblique RAT is a remote access trojan primarily targeting government and educational institutions in India.
- ObliqueRAT rat
- ObliqueRAT is a remote access trojan, similar to Crimson, that has been in use by Transparent Tribe since at least 2020.
- Obscene
- Obscene is a malware family with limited information available about its functionality and targeting.
- ObserverStealer credential-stealer
- ObserverStealer is a credential-stealer malware targeting sensitive information, particularly in the financial-services and technology…
- OceanLotus backdoor
- According to PcRisk, Research shows that the OceanLotus 'backdoor' targets MacOS computers.
- OceanSalt trojan
- OceanSalt is a Trojan that was used in a campaign targeting victims in South Korea, United States, and Canada.
- Ocelot Ransomware (FAKE RANSOMWARE) ransomware
- Also known as Ocelot Locker Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- OctoRAT ratscreen-capture
- OctoRAT is a remote access trojan designed to enable attackers to remotely control compromised systems.
- OctoberSeventh wiper
- Also known as ESET Wiper. Emanuele De Lucia summarizes that this wiper was sent to potential targets in phishing mails that impersonated ESET as a follow up to a…
- Octopus trojan
- Octopus is a Windows Trojan written in the Delphi programming language that has been used by Nomadic Octopus to target government…
- Octopus (Powershell) rat
- The author describes Octopus as an "open source, pre-operation C2 server based on python which can control an Octopus powershell agent…
- Octopus (Windows) rat
- Octopus is a Remote Access Trojan (RAT) primarily targeting government and financial sectors in Central Asia, especially Kazakhstan and…
- Octopus Scanner trojan
- Octopus Scanner is a malware that targets software development projects by inserting itself into GitHub repositories.
- Octowave Loader loader
- Octowave Loader is a malware loader used to run other families of malware.
- OddJob trojan
- OddJob is a trojan primarily targeting financial institutions, known for intercepting and modifying web sessions in real-time, often used…
- Oderoor botnet
- Also known as Bobax, Kraken. Spam bot that was active around 2007 and after, one of the first malware families to use a domain generation algorithm.
- Odinaff trojan
- Odinaff is a malware family associated with attacks on financial services.
- Odyssey Stealer credential-stealer
- Odyssey Stealer is a credential-stealing malware identified in mid-2021, primarily targeting financial and technology sectors.
- Offence rat
- Offense RAT is a free renote administration tool made in Delphi 9.
- Offline ransomware ransomware
- Also known as Vipasana, Cryakl. Ransomware email addresses overlap with .777 addresses
- Ogre ransomware
- Ogre is a type of ransomware that encrypts files on target systems and demands a ransom for decryption.
- OhNo! ransomware
- OhNo! is a ransomware family designed to encrypt victim files and demand payment for the decryption key.
- OhNo-FakePDF ransomware
- OhNo-FakePDF is a ransomware that disguises itself as a PDF document to trick users into executing it, leading to file encryption and…
- OilBooster downloader
- OilBooster is a downloader written in Microsoft Visual C/C++ that has been used by OilRig since at least 2022 including against target…
- OilCheck downloader
- OilCheck is a C#/.NET downloader that has been used by OilRig since at least 2022 including against targets in Israel.
- OilRig ratspyware
- OilRig is an advanced persistent threat group known for targeting organizations in the Middle East, primarily focusing on sectors like…
- Okrum backdoor
- Okrum is a Windows backdoor that has been seen in use since December 2016 with strong links to Ke3chang.
- OldBoot rootkittrojan
- OldBoot is an Android malware family known for using a sophisticated bootkit component to persist on infected devices.
- Oled ransomware
- Oled is a type of ransomware that encrypts files on infected systems, demanding payment for decryption.
- Olympic Destroyer wiperworm
- Also known as SOURGRAPE. Olympic Destroyer is malware that was used by Sandworm Team against the 2018 Winter Olympics, held in Pyeongchang, South Korea.
- Olyx ratkeylogger
- Olyx is a remote access trojan (RAT) typically used to target specific industries, including financial services, government, and…
- OmniRAT rat
- OmniRAT is a versatile Remote Access Trojan (RAT) capable of controlling devices across multiple operating systems, including Android…
- OmniSphere ransomware
- OmniSphere is a ransomware family known for targeting critical infrastructure sectors and encrypting sensitive data to demand ransom.
- Ondritols backdoordownloader
- Also known as Onedrivetools. According to Symantec, this malware has been deployed against IT services companies in the U.S.
- One ransomware
- One ransomware encrypts files on an infected system and demands payment for decryption keys.
- Onepercent ransomware
- Onepercent is a ransomware variant that targets primarily North American organizations, focusing on sectors like financial services and…
- Oni ransomware
- Oni is a ransomware variant that primarily targets organizations in Japan.
- OnionDuke trojanspywarebackdoor
- OnionDuke is malware that was used by APT29 from 2013 to 2015.
- OnlinerSpambot botnettrojan
- Also known as Onliner, SBot. A spambot that has been observed being used for spreading Ursnif, Zeus Panda, Andromeda or Netflix phishing against Italy and Canada.
- OoPS Ramenware ransomware
- OoPS Ramenware is a type of ransomware that encrypts victims' files and demands payment for the decryption key, primarily targeting…
- OopsIE trojanrat
- OopsIE is a Trojan used by OilRig to remotely execute commands as well as upload/download files to/from victims.
- OopsLocker ransomware
- OopsLocker is a type of ransomware that encrypts files on infected systems, demanding a ransom for decryption.
- OpBlockBuster wiper
- OpBlockBuster is a destructive malware family known for targeting specific sectors, such as government and media, with wiper capabilities.
- OpGhoul trojan
- This entry serves as a placeholder of malware observed during Operation Ghoul.
- Opachki botnet
- Opachki is a botnet known for engaging in click fraud activities.
- OpcJacker cryptominerloader
- OpcJacker is a malware family known for its involvement in cryptomining operations and its role as a loader for other malicious payloads.
- OpenCarrot rat
- OpenCarrot is a Remote Access Trojan (RAT) used primarily for cyber espionage.
- OpenSUpdater downloader
- OpenSUpdater is an adware downloader primarily affecting users in the United States.
- OpenToYou ransomware
- OpenToYou is a ransomware strain that encrypts files on victim machines and demands payment for the decryption key.
- Operation Global III ransomwarevirus
- Operation Global III is a ransomware with file-infecting capabilities.
- Optix Pro rattrojan
- Optix Pro is a configurable remote access tool or Trojan, similar to SubSeven or BO2K
- OrBit backdoorcredential-stealerdropper
- According to stormshield, Orbit is a two-stage malware that appeared in July 2022, discovered by Intezer lab.
- OrcaRAT backdoorrat
- OrcaRAT is a Backdoor that targets the Windows platform.
- Orchard botnetcryptominer
- Also known as Antavmu. A malware generating DGA domains seeded by the Bitcoin Genesis Block.
- Orcus rat
- Orcus is a remote access trojan (RAT) known for its modular architecture and capability to operate as a malware-as-a-service on…
- Orcus RAT rat
- Also known as Schnorchel. Orcus has been advertised as a Remote Administration Tool (RAT) since early 2016.
- Ordinal ransomware
- Ordinal is a ransomware variant known for encrypting files on victim machines and demanding payment for decryption.
- Ordinypt ransomwarewiper
- Also known as GermanWiper, HSDFSDCrypt. Ordinypt, also known as GermanWiper and HSDFSDCrypt, is a type of ransomware that attempts to disguise itself as a file-encrypting Trojan…
- OriginBot credential-stealerdownloaderloader
- Also known as OriginBotnet, OriginLoader. OriginBot is a modular information stealer which can also download and execute other malicious payloads.
- OriginLogger keyloggercredential-stealer
- OriginLogger is a keylogger and information-stealing malware, often used to capture keystrokes and credential data.
- Orz backdoor
- Also known as AIRBREAK. Orz is a custom JavaScript backdoor used by Leviathan.
- Oscorp trojanrat
- Also known as UBEL. Oscorp, also known as UBEL, is a sophisticated remote access trojan.
- Oski Stealer credential-stealerspyware
- Oski is a stealer written in C++ that appeared around November 2019 and is being sold for between 70$ to 100$ on Russian-speaking forums.
- Osno ransomwarecredential-stealer
- Also known as Babax. Osno, also known as Babax, is a ransomware family that also functions as a credential stealer.
- OtterCandy backdoorcredential-stealerdownloader
- Also known as HardHatRAT, UNSEENMINK. OtterCandy is a JavaScript backdoor that uses the Socket.IO WebSocket protocol over port 5000 for command and control and exfiltrates data…
- OtterCookie credential-stealerspyware
- OtterCookie is a credential-stealing malware known for targeting financial services and government sectors primarily in the United States.
- Ousaban trojan
- Ousaban is a banking Trojan primarily targeting financial institutions.
- Out1 rat
- Out1 is a remote access tool written in python and used by MuddyWater since at least 2021.
- OutCrypt ransomware
- OutCrypt is a ransomware family that encrypts victims' files and demands payment for decryption.
- OutSteel downloaderloader
- OutSteel is a file uploader and document stealer developed with the scripting language AutoIT that has been used by Saint Bear since at…
- Outlook Backdoor backdoor
- Also known as FACADE. Outlook Backdoor, also known as FACADE, is a sophisticated backdoor malware utilized in targeted attacks against specific industries.
- Outsider trojanrat
- Outsider is a sophisticated remote access trojan (RAT) targeting organizations primarily in the government and financial sectors.
- Overlay RAT rat
- Overlay RAT is a remote access trojan used for cyber espionage and financial crimes.
- OvidiyStealer credential-stealer
- OvidiyStealer is a credential-stealing malware that targets applications such as web browsers to harvest user credentials.
- OwaAuth webshellcredential-stealer
- Also known as luckyowa. OwaAuth is a Web shell and credential stealer deployed to Microsoft Exchange servers that appears to be exclusively used by Threat…
- Owari botnetddos
- Mirai variant by actor "Anarchy" that used CVE-2017-17215 in July 2018 to compromise 18,000+ devices.
- Owl ransomware
- Also known as CryptoWire. Owl, also known as CryptoWire, is a ransomware variant that encrypts files on a victim's system, demanding payment in exchange for the…
- Owlproxy trojanbackdoor
- Owlproxy is a Trojan malware that acts as a proxy to facilitate remote access to compromised networks.
- Owowa credential-stealerwebshell
- Kaspersky describes this as a OWA add-on that has credential stealing capabilities.
- OxtaRAT ratkeyloggerscreen-capture
- OxtaRAT is a remote access tool predominantly used in targeted attacks.
- Ozone rat
- Ozone is a C++ remote control program that operates as a remote access trojan (RAT).
- Ozone RAT rat
- Ozone RAT is a remote access trojan that provides attackers with unauthorized access to an infected system.
- OzozaLocker Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- P. Storrie RAT rat
- Also known as P.Storrie RAT. P. Storrie RAT is a remote access trojan typically used in cyber-espionage operations. It has been primarily deployed against governmental…
- P.A.S. Webshell webshell
- Also known as Fobushell. P.A.S. Webshell is a publicly available multifunctional PHP webshell in use since at least 2016 that provides remote access and execution…
- P2P ZeuS botnetcredential-stealertrojan
- Also known as Peer-to-Peer ZeuS, Gameover ZeuS. P2P ZeuS is a closed-source fork of the leaked version of the ZeuS botnet.
- P2Pinfect botnetworm
- P2Pinfect is a fast-growing multi platform botnet, the purpose of which is still unknown.
- P8RAT rat
- Also known as HEAVYPOT, GreetCake. P8RAT is a fileless malware used by menuPass to download and execute payloads since at least 2020.
- PACEMAKER credential-stealer
- PACEMAKER is a credential stealer that was used by APT5 as early as 2020 including activity against US Defense Industrial Base (DIB)…
- PAKLOG keylogger
- PAKLOG is a keylogger known to be leveraged by Mustang Panda and was first observed utilized in 2024.
- PANIX rootkit
- According to its author, PANIX is a powerful, modular, and highly customizable Linux persistence framework designed for security…
- PAS rat
- PAS is a remote access trojan (RAT) known for targeting government and financial sectors.
- PATHLOADER loader
- PATHLOADER is a cyber espionage malware used primarily as a loader in various malicious campaigns.
- PC Surveillance System spyware
- Also known as PSS. Citizenlab notes that PC Surveillance System (PSS) is a commercial spyware product offered by Cyberbit and marketed to intelligence and…
- PClock и PClock2 ransomware
- PClock and PClock2 are ransomware variants that encrypt files on a victim's computer and demand a ransom for decryption.
- PClock3 Ransomware ransomware
- Also known as PClock SuppTeam Ransomware, WinPlock, CryptoLocker clone. This is most likely to affect English speaking users, since the note is written in English.
- PClock4 Ransomware ransomware
- Also known as PClock SysGop Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- PEBBLEDASH backdoorrat
- PEBBLEDASH is a sophisticated remote access tool (RAT) used by state-sponsored threat actors for espionage purposes.