Malware Families page 36 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- PEC 2017 ransomware
- PEC 2017 is a ransomware known for encrypting files on the infected system, demanding a ransom for decryption.
- PGPSnippet Ransomware ransomware
- PGPSnippet Ransomware is a malicious software designed to encrypt files on a victim's computer and demand a ransom for decryption.
- PG_MEM credential-stealerrat
- PG_MEM is a sophisticated Remote Access Trojan (RAT) primarily used for credential theft and remote system access.
- PHASEJAM dropper
- PHASEJAM is a dropper written as a bash shell script that modifies Ivanti Connect Secure appliance components.
- PHOREAL backdoor
- Also known as Rizzo. PHOREAL, also known as Rizzo, is a signature backdoor associated with APT32 known for targeting sectors in Southeast Asia.
- PHOTOFORK downloaderloader
- PHOTOFORK is a downloader which is a modified version of GZIPLOADER.
- PHOTOLITE loaderbotnet
- PHOTOLITE is the lite version of the GZIPLOADER with limited capabilities i.e.
- PHP ransomware
- PHP ransomware is a type of malware that encrypts files on an infected system, demanding payment for decryption.
- PHPsert webshell
- PHPsert is a webshell used to execute PHP code that has been in use since at least 2023 against targets in Japan, Singapore, Peru, Taiwan…
- PICKPOCKET credential-stealer
- PICKPOCKET is a credential theft tool that dumps the user's website login credentials from Chrome, Firefox, and Internet Explorer to a file.
- PICO Ransomware ransomware
- S!Ri found a new Thanatos Ransomware variant called PICO Ransomware.
- PIEHOP trojan
- According to Mandiant, PIEHOP is a disruption tool written in Python and packaged with PyInstaller version 2.1+ that has the capability to…
- PINEFLOWER backdoorspywaretrojan
- According to Mandiant, PINEFLOWER is an Android malware family capable of a wide range of backdoor functionality, including stealing…
- PINEGROVE rat
- PINEGROVE is a remote access trojan primarily used in cyber-espionage campaigns targeting government and defense sectors.
- PIRAT rat
- PIRAT is a sophisticated Remote Access Trojan (RAT) primarily used for cyber-espionage.
- PITFUEL loader
- According to Mandiant, this is a SparkGateway plugin that loads LITTLELAMB.WOOLTEA through JNI.
- PITHOOK trojanwebshell
- According to Mandiant, PITHOOK hooks the accept and accept4 functions within the web process by modifying the PLT.
- PITSOCK backdoor
- According to Mandiant, this is backdoor which hooks the accept and setsockopt of the web process by modifying its procedure linkage table…
- PITSTOP backdoor
- PITSTOP is a backdoor that was deployed on compromised Ivanti Connect Secure VPNs during Cutting Edge to enable command execution and file…
- PJApps trojan
- PJApps is a malware family targeting Android devices, often serving as a trojan to compromise user data and device security.
- PL ransomware
- PL is a ransomware family known for encrypting victim files and demanding a ransom for decryption.
- PLAINTEE backdoor
- PLAINTEE is a malware sample that has been used by Rancor in targeted attacks in Singapore and Cambodia.
- PLAY Ransomware ransomware
- PLAY Ransomware is a type of malware that encrypts files on an infected system, demanding payment for decryption keys.
- PLC-Blaster wormexploit-kit
- PLC-Blaster is a piece of proof-of-concept malware that runs on Siemens S7 PLCs.
- PLEAD ratdownloader
- PLEAD is a remote access tool (RAT) and downloader used by BlackTech in targeted attacks in East Asia including Taiwan, Japan, and Hong…
- PLEAD (ELF) spywarebackdoor
- PLEAD is a malware family known for targeting specific regions in Asia, specifically Taiwan and Japan.
- PLEAD (Windows) ratdownloader
- Also known as DRAWDOWN, GOODTIMES, Linopid. PLEAD is a RAT used by the actor BlackTech.
- PLUGGYAPE rat
- According to CERT-UA, this malware establishes a connection to the management server using web sockets and/or MQTT, data is transmitted in…
- PNGLoad loader
- According to ESET Research, PNGLoad is a second-stage payload deployed by Worok on compromised systems and loaded either by CLRLoad or…
- POISONPLUG backdoor
- Also known as Barlaiy. According to FireEye, POISONPLUG is a highly obfuscated modular backdoor with plug-in capabilities.
- POOLRAT rat
- Also known as SIMPLESEA, SIMPLETEA. POOLRAT, also known as SIMPLESEA and SIMPLETEA, is a remote access trojan known for its use in cyber espionage campaigns.
- POORAIM backdoor
- POORAIM is a backdoor used by APT37 in campaigns since at least 2014.
- POORTRY rootkit
- According to Mandiant, POORTRY is a malware written as a driver, signed with a Microsoft Windows Hardware Compatibility Authenticode…
- POSHSPY backdoor
- POSHSPY is a backdoor that has been used by APT29 since at least 2015.
- POWERBAND backdoorrat
- .NET variant of ps1.powerton used for remote access and data exfiltration.
- POWERPIPE backdoor
- POWERPIPE is a backdoor malware known for targeting government and public sector entities in the United States.
- POWERPLANT backdoor
- This powershell code is a PowerShell written backdoor used by FIN7.
- POWERSOURCE backdoor
- Also known as DNSMessenger. POWERSOURCE is a PowerShell backdoor that is a heavily obfuscated and modified version of the publicly available tool DNS_TXT_Pwnage.
- POWERSTAR ratbackdoor
- POWERSTAR is a remote access tool commonly used in cyber espionage campaigns targeting government agencies and critical infrastructure…
- POWERSTATS backdoor
- Also known as Powermud, Valyria. POWERSTATS is a PowerShell-based first stage backdoor used by MuddyWater.
- POWERTON backdoor
- POWERTON is a custom PowerShell backdoor first observed in 2018.
- POWERTRASH dropper
- This PowerShell written malware is an in-memory dropper used by FIN7 to execute the included/embedded payload.
- POWRUNER rat
- POWRUNER is a PowerShell script that sends and receives commands to and from the C2 server.
- PPDDDP ransomware
- PPDDDP is a ransomware family that encrypts files on the victim's systems and demands a ransom for the decryption key.
- PRISM ransomware
- Also known as waterdrop. PRISM, also known as waterdrop, is a ransomware family primarily targeting large enterprises across various industries.
- PRIVATELOG loader
- Malware that abuses the Common Log File System (CLFS) to store/hide a second stage payload via registry transaction files.
- PS1 loader
- PS1 is a loader that was used to deploy 64-bit backdoors in the CostaRicto campaign.
- PS1Bot botnetcredential-stealerkeylogger
- According to Cisco Talos, this is multi-stage malware framework, implemented in PowerShell and C#, that possesses robust functionality…
- PSCrypt ransomware
- PSCrypt is a ransomware that primarily targets organizations in Eastern Europe, specifically Ukraine and Poland.
- PSLogger keyloggerrat
- Also known as ECCENTRICBANDWAGON. PSLogger, also known as ECCENTRICBANDWAGON, is a remote access tool and keylogger used to infiltrate targeted computer systems and capture…
- PTP ransomware
- PTP is a ransomware variant known for targeting multiple industries including healthcare, government, and financial services.
- PUBG Ransomware ransomware
- In what could only be a joke, a new ransomware has been discovered called "PUBG Ransomware" that will decrypt your files if you play the…
- PUBLOAD loader
- Also known as ClaimLoader. PUBLOAD is a stager malware that has been observed installing itself in existing directories such as `C:\Users\Public` or creating new…
- PULSECHECK webshell
- PULSECHECK is a web shell written in Perl that was used by APT5 as early as 2020 including against Pulse Secure VPNs at US Defense…
- PULSEPACK
- No detailed information is available about PULSEPACK.
- PUMAKIT rootkit
- Also known as Kitsune, PUMA. According to Elastic, PUMAKIT is a sophisticated loadable kernel module (LKM) rootkit that employs advanced stealth mechanisms to hide its…
- PUNCHBUGGY backdoor
- Also known as ShellTea. PUNCHBUGGY is a backdoor malware used by FIN8 that has been observed targeting POS networks in the hospitality industry.
- PUNCHTRACK credential-stealer
- Also known as PSVC. PUNCHTRACK is non-persistent point of sale (POS) system malware utilized by FIN8 to scrape payment card data.
- PWNLNX backdoorrat
- PWNLNX is a Linux-based malware that serves as a remote access tool with backdoor capabilities.
- PXA Stealer credential-stealer
- Also known as PXA, PXAStealer. PXA Stealer is an information-stealing malware written in Python, identified by Cisco Talos in an active campaign attributed to a…
- PY#RATION ratkeylogger
- According to Securonix, this malware exhibits remote access trojan (RAT) behavior, allowing for control of and persistence on the affected…
- PZDC ransomware
- PZDC is a ransomware strain that encrypts files on infected systems, demanding ransom payments for their decryption.
- PackChat trojan
- PackChat is a stealthy trojan used primarily for cyber espionage targeting sensitive sectors.
- Pacman ransomware
- Pacman is a ransomware strain that encrypts files on the victim's system and demands payment for the decryption key.
- Pacu exploit-kit
- Pacu is an open-source AWS exploitation framework.
- PadCrypt ransomware
- PadCrypt is a type of ransomware that stands out due to its live support chat feature, allowing victims to potentially negotiate their…
- Padlock Screenlocker ransomware
- Padlock Screenlocker is a ransomware that locks the screen of the infected device, displaying a message demanding a ransom to unlock.
- Pain RAT rat
- Pain RAT is a remote access tool used for unauthorized access to targeted systems.
- Pallas spyware
- Pallas is mobile surveillanceware that was custom-developed by Dark Caracal.
- Panda Stealer credential-stealer
- According to PCrisk, Panda is the name of a malicious program, which is classified as a stealer.
- PandaBanker trojancredential-stealerbotnet
- Also known as ZeusPanda. According to Arbor, Forcepoint and Proofpoint, Panda is a variant of the well-known Zeus banking trojan(*).
- Pandora backdoorrootkit
- Pandora is a multistage kernel rootkit with backdoor functionality that has been in use by Threat Group-3390 since at least 2020.
- Pandora RAT rat
- Also known as Pandora hVNC RAT. Pandora RAT, also known as Pandora hVNC RAT, is a remote access trojan that provides a threat actor with access to compromised systems.
- Pantegana rat
- Pantegana is a multi-platform remote access trojan (RAT) developed in the Go programming language, known for its versatility in targeting…
- ParaSiteSnatcher trojanbackdoor
- ParaSiteSnatcher is a trojan malware family that provides backdoor access to attackers primarily targeting financial services and…
- Paradies Clipper credential-stealer
- Paradies Clipper is a type of malware designed to intercept and alter clipboard contents, primarily targeting cryptocurrency transactions…
- Paradise Ransomware ransomware
- MalwareHunterTeam discovered a new Paradise Ransomware variant that uses the extension _V.0.0.0.1{[email protected]}.prt and…
- Paradox rat
- Paradox is a remote access trojan (RAT) known for its capability to infiltrate and control infected systems remotely.
- Parallax RAT rat
- Also known as ParallaxRAT. Parallax is a Remote Access Trojan used by attackers to gain access to a victim's machine.
- Parasite ransomware
- Parasite is a type of ransomware that encrypts files on infected systems, demanding a ransom payment in exchange for the decryption key.
- Parasite-HTTP-RAT rat
- Also known as Parasite HTTP. The RAT, dubbed Parasite HTTP, is especially notable for the extensive array of techniques it incorporates for sandbox detection…
- Parite virus
- According to Microsoft, Parite is a family of polymorphic file infectors that targets computers running Microsoft Windows.
- Parrot TDS
- This malicious code written in JavaScript is used as Traffic Direction System (TDS).
- Parrot TDS WebShell webshell
- In combination with Parrot TDS the usage of a classical web shell was observed by DECODED Avast.io.
- PartyTicket ransomware
- Also known as Elections GoRansom, HermeticRansom, SonicVote. PartyTicket is a Go-written ransomware, which was described as a poorly designed one by Zscaler.
- Pasam trojanbackdoor
- Pasam is a trojan used by Elderwood to open a backdoor on compromised hosts.
- Pass-The-Hash Toolkit credential-stealer
- Pass-The-Hash Toolkit is a toolkit that allows an adversary to "pass" a password hash (without knowing the original password) to log in to…
- PassLock ransomware
- PassLock is a ransomware family known for encrypting files on victim systems and demanding ransom payments to restore access.
- Patcher ransomware
- Also known as FileCoder, Findzip. Patcher is ransomware that specifically targets macOS users, attempting to encrypt their files and demand a ransom payment for decryption.
- PathWiper wiper
- According to Cisco Talos, this wiper replaces the contents of artifacts related to the file system with random data generated on the fly.
- Pay-or-Lost ransomware
- Pay-or-Lost is a type of ransomware that encrypts files on the victim's system, demanding a ransom payment in exchange for the decryption…
- Pay2Decrypt ransomware
- Pay2Decrypt is a ransomware that encrypts the victim's files and demands a ransom for decryption.
- Pay2Key ransomware
- Also known as Cobalt. Pay2Key is a ransomware written in C++ that has been used by Fox Kitten since at least July 2020 including campaigns against Israeli…
- PayDOS Ransomware ransomware
- Also known as Serpent Ransomware. This is most likely to affect English speaking users, since the note is written in English.
- PayDay Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- PayForNature ransomware
- PayForNature is a ransomware that encrypts victims' files and demands a ransom for decryption.
- PaySafeGen (German) Ransomware ransomware
- Also known as Paysafecard Generator 2016, PaySafeCard, PaySafeGen. This is most likely to affect German speaking users, since the note is written in German.
- Payloadbin ransomware
- Payloadbin is a ransomware group known for encrypting victims' data and demanding ransom in cryptocurrency, often leveraging double…
- Paymen45 ransomware
- Paymen45 is a type of ransomware that encrypts files on infected systems and demands payment for decryption.
- Payment ransomware
- Payment is a ransomware family that encrypts victims' files and demands payment for decryption keys, primarily targeting sectors likely to…