Malware Families page 35 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

OXAR ransomware
OXAR is a ransomware family known for targeting the financial and government sectors.
OZH RAT rat
OZH RAT is a remote access trojan used primarily for cyber espionage.
Oblique RAT ratspyware
Oblique RAT is a remote access trojan primarily targeting government and educational institutions in India.
ObliqueRAT rat
ObliqueRAT is a remote access trojan, similar to Crimson, that has been in use by Transparent Tribe since at least 2020.
Obscene
Obscene is a malware family with limited information available about its functionality and targeting.
ObserverStealer credential-stealer
ObserverStealer is a credential-stealer malware targeting sensitive information, particularly in the financial-services and technology…
OceanLotus backdoor
According to PcRisk, Research shows that the OceanLotus 'backdoor' targets MacOS computers.
OceanSalt trojan
OceanSalt is a Trojan that was used in a campaign targeting victims in South Korea, United States, and Canada.
Ocelot Ransomware (FAKE RANSOMWARE) ransomware
Also known as Ocelot Locker Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
OctoRAT ratscreen-capture
OctoRAT is a remote access trojan designed to enable attackers to remotely control compromised systems.
OctoberSeventh wiper
Also known as ESET Wiper. Emanuele De Lucia summarizes that this wiper was sent to potential targets in phishing mails that impersonated ESET as a follow up to a…
Octopus trojan
Octopus is a Windows Trojan written in the Delphi programming language that has been used by Nomadic Octopus to target government…
Octopus (Powershell) rat
The author describes Octopus as an "open source, pre-operation C2 server based on python which can control an Octopus powershell agent…
Octopus (Windows) rat
Octopus is a Remote Access Trojan (RAT) primarily targeting government and financial sectors in Central Asia, especially Kazakhstan and…
Octopus Scanner trojan
Octopus Scanner is a malware that targets software development projects by inserting itself into GitHub repositories.
Octowave Loader loader
Octowave Loader is a malware loader used to run other families of malware.
OddJob trojan
OddJob is a trojan primarily targeting financial institutions, known for intercepting and modifying web sessions in real-time, often used…
Oderoor botnet
Also known as Bobax, Kraken. Spam bot that was active around 2007 and after, one of the first malware families to use a domain generation algorithm.
Odinaff trojan
Odinaff is a malware family associated with attacks on financial services.
Odyssey Stealer credential-stealer
Odyssey Stealer is a credential-stealing malware identified in mid-2021, primarily targeting financial and technology sectors.
Offence rat
Offense RAT is a free renote administration tool made in Delphi 9.
Offline ransomware ransomware
Also known as Vipasana, Cryakl. Ransomware email addresses overlap with .777 addresses
Ogre ransomware
Ogre is a type of ransomware that encrypts files on target systems and demands a ransom for decryption.
OhNo! ransomware
OhNo! is a ransomware family designed to encrypt victim files and demand payment for the decryption key.
OhNo-FakePDF ransomware
OhNo-FakePDF is a ransomware that disguises itself as a PDF document to trick users into executing it, leading to file encryption and…
OilBooster downloader
OilBooster is a downloader written in Microsoft Visual C/C++ that has been used by OilRig since at least 2022 including against target…
OilCheck downloader
OilCheck is a C#/.NET downloader that has been used by OilRig since at least 2022 including against targets in Israel.
OilRig ratspyware
OilRig is an advanced persistent threat group known for targeting organizations in the Middle East, primarily focusing on sectors like…
Okrum backdoor
Okrum is a Windows backdoor that has been seen in use since December 2016 with strong links to Ke3chang.
OldBoot rootkittrojan
OldBoot is an Android malware family known for using a sophisticated bootkit component to persist on infected devices.
Oled ransomware
Oled is a type of ransomware that encrypts files on infected systems, demanding payment for decryption.
Olympic Destroyer wiperworm
Also known as SOURGRAPE. Olympic Destroyer is malware that was used by Sandworm Team against the 2018 Winter Olympics, held in Pyeongchang, South Korea.
Olyx ratkeylogger
Olyx is a remote access trojan (RAT) typically used to target specific industries, including financial services, government, and…
OmniRAT rat
OmniRAT is a versatile Remote Access Trojan (RAT) capable of controlling devices across multiple operating systems, including Android…
OmniSphere ransomware
OmniSphere is a ransomware family known for targeting critical infrastructure sectors and encrypting sensitive data to demand ransom.
Ondritols backdoordownloader
Also known as Onedrivetools. According to Symantec, this malware has been deployed against IT services companies in the U.S.
One ransomware
One ransomware encrypts files on an infected system and demands payment for decryption keys.
Onepercent ransomware
Onepercent is a ransomware variant that targets primarily North American organizations, focusing on sectors like financial services and…
Oni ransomware
Oni is a ransomware variant that primarily targets organizations in Japan.
OnionDuke trojanspywarebackdoor
OnionDuke is malware that was used by APT29 from 2013 to 2015.
OnlinerSpambot botnettrojan
Also known as Onliner, SBot. A spambot that has been observed being used for spreading Ursnif, Zeus Panda, Andromeda or Netflix phishing against Italy and Canada.
OoPS Ramenware ransomware
OoPS Ramenware is a type of ransomware that encrypts victims' files and demands payment for the decryption key, primarily targeting…
OopsIE trojanrat
OopsIE is a Trojan used by OilRig to remotely execute commands as well as upload/download files to/from victims.
OopsLocker ransomware
OopsLocker is a type of ransomware that encrypts files on infected systems, demanding a ransom for decryption.
OpBlockBuster wiper
OpBlockBuster is a destructive malware family known for targeting specific sectors, such as government and media, with wiper capabilities.
OpGhoul trojan
This entry serves as a placeholder of malware observed during Operation Ghoul.
Opachki botnet
Opachki is a botnet known for engaging in click fraud activities.
OpcJacker cryptominerloader
OpcJacker is a malware family known for its involvement in cryptomining operations and its role as a loader for other malicious payloads.
OpenCarrot rat
OpenCarrot is a Remote Access Trojan (RAT) used primarily for cyber espionage.
OpenSUpdater downloader
OpenSUpdater is an adware downloader primarily affecting users in the United States.
OpenToYou ransomware
OpenToYou is a ransomware strain that encrypts files on victim machines and demands payment for the decryption key.
Operation Global III ransomwarevirus
Operation Global III is a ransomware with file-infecting capabilities.
Optix Pro rattrojan
Optix Pro is a configurable remote access tool or Trojan, similar to SubSeven or BO2K
OrBit backdoorcredential-stealerdropper
According to stormshield, Orbit is a two-stage malware that appeared in July 2022, discovered by Intezer lab.
OrcaRAT backdoorrat
OrcaRAT is a Backdoor that targets the Windows platform.
Orchard botnetcryptominer
Also known as Antavmu. A malware generating DGA domains seeded by the Bitcoin Genesis Block.
Orcus rat
Orcus is a remote access trojan (RAT) known for its modular architecture and capability to operate as a malware-as-a-service on…
Orcus RAT rat
Also known as Schnorchel. Orcus has been advertised as a Remote Administration Tool (RAT) since early 2016.
Ordinal ransomware
Ordinal is a ransomware variant known for encrypting files on victim machines and demanding payment for decryption.
Ordinypt ransomwarewiper
Also known as GermanWiper, HSDFSDCrypt. Ordinypt, also known as GermanWiper and HSDFSDCrypt, is a type of ransomware that attempts to disguise itself as a file-encrypting Trojan…
OriginBot credential-stealerdownloaderloader
Also known as OriginBotnet, OriginLoader. OriginBot is a modular information stealer which can also download and execute other malicious payloads.
OriginLogger keyloggercredential-stealer
OriginLogger is a keylogger and information-stealing malware, often used to capture keystrokes and credential data.
Orz backdoor
Also known as AIRBREAK. Orz is a custom JavaScript backdoor used by Leviathan.
Oscorp trojanrat
Also known as UBEL. Oscorp, also known as UBEL, is a sophisticated remote access trojan.
Oski Stealer credential-stealerspyware
Oski is a stealer written in C++ that appeared around November 2019 and is being sold for between 70$ to 100$ on Russian-speaking forums.
Osno ransomwarecredential-stealer
Also known as Babax. Osno, also known as Babax, is a ransomware family that also functions as a credential stealer.
OtterCandy backdoorcredential-stealerdownloader
Also known as HardHatRAT, UNSEENMINK. OtterCandy is a JavaScript backdoor that uses the Socket.IO WebSocket protocol over port 5000 for command and control and exfiltrates data…
OtterCookie credential-stealerspyware
OtterCookie is a credential-stealing malware known for targeting financial services and government sectors primarily in the United States.
Ousaban trojan
Ousaban is a banking Trojan primarily targeting financial institutions.
Out1 rat
Out1 is a remote access tool written in python and used by MuddyWater since at least 2021.
OutCrypt ransomware
OutCrypt is a ransomware family that encrypts victims' files and demands payment for decryption.
OutSteel downloaderloader
OutSteel is a file uploader and document stealer developed with the scripting language AutoIT that has been used by Saint Bear since at…
Outlook Backdoor backdoor
Also known as FACADE. Outlook Backdoor, also known as FACADE, is a sophisticated backdoor malware utilized in targeted attacks against specific industries.
Outsider trojanrat
Outsider is a sophisticated remote access trojan (RAT) targeting organizations primarily in the government and financial sectors.
Overlay RAT rat
Overlay RAT is a remote access trojan used for cyber espionage and financial crimes.
OvidiyStealer credential-stealer
OvidiyStealer is a credential-stealing malware that targets applications such as web browsers to harvest user credentials.
OwaAuth webshellcredential-stealer
Also known as luckyowa. OwaAuth is a Web shell and credential stealer deployed to Microsoft Exchange servers that appears to be exclusively used by Threat…
Owari botnetddos
Mirai variant by actor "Anarchy" that used CVE-2017-17215 in July 2018 to compromise 18,000+ devices.
Owl ransomware
Also known as CryptoWire. Owl, also known as CryptoWire, is a ransomware variant that encrypts files on a victim's system, demanding payment in exchange for the…
Owlproxy trojanbackdoor
Owlproxy is a Trojan malware that acts as a proxy to facilitate remote access to compromised networks.
Owowa credential-stealerwebshell
Kaspersky describes this as a OWA add-on that has credential stealing capabilities.
OxtaRAT ratkeyloggerscreen-capture
OxtaRAT is a remote access tool predominantly used in targeted attacks.
Ozone rat
Ozone is a C++ remote control program that operates as a remote access trojan (RAT).
Ozone RAT rat
Ozone RAT is a remote access trojan that provides attackers with unauthorized access to an infected system.
OzozaLocker Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
P. Storrie RAT rat
Also known as P.Storrie RAT. P. Storrie RAT is a remote access trojan typically used in cyber-espionage operations. It has been primarily deployed against governmental…
P.A.S. Webshell webshell
Also known as Fobushell. P.A.S. Webshell is a publicly available multifunctional PHP webshell in use since at least 2016 that provides remote access and execution…
P2P ZeuS botnetcredential-stealertrojan
Also known as Peer-to-Peer ZeuS, Gameover ZeuS. P2P ZeuS is a closed-source fork of the leaked version of the ZeuS botnet.
P2Pinfect botnetworm
P2Pinfect is a fast-growing multi platform botnet, the purpose of which is still unknown.
P8RAT rat
Also known as HEAVYPOT, GreetCake. P8RAT is a fileless malware used by menuPass to download and execute payloads since at least 2020.
PACEMAKER credential-stealer
PACEMAKER is a credential stealer that was used by APT5 as early as 2020 including activity against US Defense Industrial Base (DIB)…
PAKLOG keylogger
PAKLOG is a keylogger known to be leveraged by Mustang Panda and was first observed utilized in 2024.
PANIX rootkit
According to its author, PANIX is a powerful, modular, and highly customizable Linux persistence framework designed for security…
PAS rat
PAS is a remote access trojan (RAT) known for targeting government and financial sectors.
PATHLOADER loader
PATHLOADER is a cyber espionage malware used primarily as a loader in various malicious campaigns.
PC Surveillance System spyware
Also known as PSS. Citizenlab notes that PC Surveillance System (PSS) is a commercial spyware product offered by Cyberbit and marketed to intelligence and…
PClock и PClock2 ransomware
PClock and PClock2 are ransomware variants that encrypt files on a victim's computer and demand a ransom for decryption.
PClock3 Ransomware ransomware
Also known as PClock SuppTeam Ransomware, WinPlock, CryptoLocker clone. This is most likely to affect English speaking users, since the note is written in English.
PClock4 Ransomware ransomware
Also known as PClock SysGop Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
PEBBLEDASH backdoorrat
PEBBLEDASH is a sophisticated remote access tool (RAT) used by state-sponsored threat actors for espionage purposes.