Malware Families page 36 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

PEC 2017 ransomware
PEC 2017 is a ransomware known for encrypting files on the infected system, demanding a ransom for decryption.
PGPSnippet Ransomware ransomware
PGPSnippet Ransomware is a malicious software designed to encrypt files on a victim's computer and demand a ransom for decryption.
PG_MEM credential-stealerrat
PG_MEM is a sophisticated Remote Access Trojan (RAT) primarily used for credential theft and remote system access.
PHASEJAM dropper
PHASEJAM is a dropper written as a bash shell script that modifies Ivanti Connect Secure appliance components.
PHOREAL backdoor
Also known as Rizzo. PHOREAL, also known as Rizzo, is a signature backdoor associated with APT32 known for targeting sectors in Southeast Asia.
PHOTOFORK downloaderloader
PHOTOFORK is a downloader which is a modified version of GZIPLOADER.
PHOTOLITE loaderbotnet
PHOTOLITE is the lite version of the GZIPLOADER with limited capabilities i.e.
PHP ransomware
PHP ransomware is a type of malware that encrypts files on an infected system, demanding payment for decryption.
PHPsert webshell
PHPsert is a webshell used to execute PHP code that has been in use since at least 2023 against targets in Japan, Singapore, Peru, Taiwan…
PICKPOCKET credential-stealer
PICKPOCKET is a credential theft tool that dumps the user's website login credentials from Chrome, Firefox, and Internet Explorer to a file.
PICO Ransomware ransomware
S!Ri found a new Thanatos Ransomware variant called PICO Ransomware.
PIEHOP trojan
According to Mandiant, PIEHOP is a disruption tool written in Python and packaged with PyInstaller version 2.1+ that has the capability to…
PINEFLOWER backdoorspywaretrojan
According to Mandiant, PINEFLOWER is an Android malware family capable of a wide range of backdoor functionality, including stealing…
PINEGROVE rat
PINEGROVE is a remote access trojan primarily used in cyber-espionage campaigns targeting government and defense sectors.
PIRAT rat
PIRAT is a sophisticated Remote Access Trojan (RAT) primarily used for cyber-espionage.
PITFUEL loader
According to Mandiant, this is a SparkGateway plugin that loads LITTLELAMB.WOOLTEA through JNI.
PITHOOK trojanwebshell
According to Mandiant, PITHOOK hooks the accept and accept4 functions within the web process by modifying the PLT.
PITSOCK backdoor
According to Mandiant, this is backdoor which hooks the accept and setsockopt of the web process by modifying its procedure linkage table…
PITSTOP backdoor
PITSTOP is a backdoor that was deployed on compromised Ivanti Connect Secure VPNs during Cutting Edge to enable command execution and file…
PJApps trojan
PJApps is a malware family targeting Android devices, often serving as a trojan to compromise user data and device security.
PL ransomware
PL is a ransomware family known for encrypting victim files and demanding a ransom for decryption.
PLAINTEE backdoor
PLAINTEE is a malware sample that has been used by Rancor in targeted attacks in Singapore and Cambodia.
PLAY Ransomware ransomware
PLAY Ransomware is a type of malware that encrypts files on an infected system, demanding payment for decryption keys.
PLC-Blaster wormexploit-kit
PLC-Blaster is a piece of proof-of-concept malware that runs on Siemens S7 PLCs.
PLEAD ratdownloader
PLEAD is a remote access tool (RAT) and downloader used by BlackTech in targeted attacks in East Asia including Taiwan, Japan, and Hong…
PLEAD (ELF) spywarebackdoor
PLEAD is a malware family known for targeting specific regions in Asia, specifically Taiwan and Japan.
PLEAD (Windows) ratdownloader
Also known as DRAWDOWN, GOODTIMES, Linopid. PLEAD is a RAT used by the actor BlackTech.
PLUGGYAPE rat
According to CERT-UA, this malware establishes a connection to the management server using web sockets and/or MQTT, data is transmitted in…
PNGLoad loader
According to ESET Research, PNGLoad is a second-stage payload deployed by Worok on compromised systems and loaded either by CLRLoad or…
POISONPLUG backdoor
Also known as Barlaiy. According to FireEye, POISONPLUG is a highly obfuscated modular backdoor with plug-in capabilities.
POOLRAT rat
Also known as SIMPLESEA, SIMPLETEA. POOLRAT, also known as SIMPLESEA and SIMPLETEA, is a remote access trojan known for its use in cyber espionage campaigns.
POORAIM backdoor
POORAIM is a backdoor used by APT37 in campaigns since at least 2014.
POORTRY rootkit
According to Mandiant, POORTRY is a malware written as a driver, signed with a Microsoft Windows Hardware Compatibility Authenticode…
POSHSPY backdoor
POSHSPY is a backdoor that has been used by APT29 since at least 2015.
POWERBAND backdoorrat
.NET variant of ps1.powerton used for remote access and data exfiltration.
POWERPIPE backdoor
POWERPIPE is a backdoor malware known for targeting government and public sector entities in the United States.
POWERPLANT backdoor
This powershell code is a PowerShell written backdoor used by FIN7.
POWERSOURCE backdoor
Also known as DNSMessenger. POWERSOURCE is a PowerShell backdoor that is a heavily obfuscated and modified version of the publicly available tool DNS_TXT_Pwnage.
POWERSTAR ratbackdoor
POWERSTAR is a remote access tool commonly used in cyber espionage campaigns targeting government agencies and critical infrastructure…
POWERSTATS backdoor
Also known as Powermud, Valyria. POWERSTATS is a PowerShell-based first stage backdoor used by MuddyWater.
POWERTON backdoor
POWERTON is a custom PowerShell backdoor first observed in 2018.
POWERTRASH dropper
This PowerShell written malware is an in-memory dropper used by FIN7 to execute the included/embedded payload.
POWRUNER rat
POWRUNER is a PowerShell script that sends and receives commands to and from the C2 server.
PPDDDP ransomware
PPDDDP is a ransomware family that encrypts files on the victim's systems and demands a ransom for the decryption key.
PRISM ransomware
Also known as waterdrop. PRISM, also known as waterdrop, is a ransomware family primarily targeting large enterprises across various industries.
PRIVATELOG loader
Malware that abuses the Common Log File System (CLFS) to store/hide a second stage payload via registry transaction files.
PS1 loader
PS1 is a loader that was used to deploy 64-bit backdoors in the CostaRicto campaign.
PS1Bot botnetcredential-stealerkeylogger
According to Cisco Talos, this is multi-stage malware framework, implemented in PowerShell and C#, that possesses robust functionality…
PSCrypt ransomware
PSCrypt is a ransomware that primarily targets organizations in Eastern Europe, specifically Ukraine and Poland.
PSLogger keyloggerrat
Also known as ECCENTRICBANDWAGON. PSLogger, also known as ECCENTRICBANDWAGON, is a remote access tool and keylogger used to infiltrate targeted computer systems and capture…
PTP ransomware
PTP is a ransomware variant known for targeting multiple industries including healthcare, government, and financial services.
PUBG Ransomware ransomware
In what could only be a joke, a new ransomware has been discovered called "PUBG Ransomware" that will decrypt your files if you play the…
PUBLOAD loader
Also known as ClaimLoader. PUBLOAD is a stager malware that has been observed installing itself in existing directories such as `C:\Users\Public` or creating new…
PULSECHECK webshell
PULSECHECK is a web shell written in Perl that was used by APT5 as early as 2020 including against Pulse Secure VPNs at US Defense…
PULSEPACK
No detailed information is available about PULSEPACK.
PUMAKIT rootkit
Also known as Kitsune, PUMA. According to Elastic, PUMAKIT is a sophisticated loadable kernel module (LKM) rootkit that employs advanced stealth mechanisms to hide its…
PUNCHBUGGY backdoor
Also known as ShellTea. PUNCHBUGGY is a backdoor malware used by FIN8 that has been observed targeting POS networks in the hospitality industry.
PUNCHTRACK credential-stealer
Also known as PSVC. PUNCHTRACK is non-persistent point of sale (POS) system malware utilized by FIN8 to scrape payment card data.
PWNLNX backdoorrat
PWNLNX is a Linux-based malware that serves as a remote access tool with backdoor capabilities.
PXA Stealer credential-stealer
Also known as PXA, PXAStealer. PXA Stealer is an information-stealing malware written in Python, identified by Cisco Talos in an active campaign attributed to a…
PY#RATION ratkeylogger
According to Securonix, this malware exhibits remote access trojan (RAT) behavior, allowing for control of and persistence on the affected…
PZDC ransomware
PZDC is a ransomware strain that encrypts files on infected systems, demanding ransom payments for their decryption.
PackChat trojan
PackChat is a stealthy trojan used primarily for cyber espionage targeting sensitive sectors.
Pacman ransomware
Pacman is a ransomware strain that encrypts files on the victim's system and demands payment for the decryption key.
Pacu exploit-kit
Pacu is an open-source AWS exploitation framework.
PadCrypt ransomware
PadCrypt is a type of ransomware that stands out due to its live support chat feature, allowing victims to potentially negotiate their…
Padlock Screenlocker ransomware
Padlock Screenlocker is a ransomware that locks the screen of the infected device, displaying a message demanding a ransom to unlock.
Pain RAT rat
Pain RAT is a remote access tool used for unauthorized access to targeted systems.
Pallas spyware
Pallas is mobile surveillanceware that was custom-developed by Dark Caracal.
Panda Stealer credential-stealer
According to PCrisk, Panda is the name of a malicious program, which is classified as a stealer.
PandaBanker trojancredential-stealerbotnet
Also known as ZeusPanda. According to Arbor, Forcepoint and Proofpoint, Panda is a variant of the well-known Zeus banking trojan(*).
Pandora backdoorrootkit
Pandora is a multistage kernel rootkit with backdoor functionality that has been in use by Threat Group-3390 since at least 2020.
Pandora RAT rat
Also known as Pandora hVNC RAT. Pandora RAT, also known as Pandora hVNC RAT, is a remote access trojan that provides a threat actor with access to compromised systems.
Pantegana rat
Pantegana is a multi-platform remote access trojan (RAT) developed in the Go programming language, known for its versatility in targeting…
ParaSiteSnatcher trojanbackdoor
ParaSiteSnatcher is a trojan malware family that provides backdoor access to attackers primarily targeting financial services and…
Paradies Clipper credential-stealer
Paradies Clipper is a type of malware designed to intercept and alter clipboard contents, primarily targeting cryptocurrency transactions…
Paradise Ransomware ransomware
MalwareHunterTeam discovered a new Paradise Ransomware variant that uses the extension _V.0.0.0.1{[email protected]}.prt and…
Paradox rat
Paradox is a remote access trojan (RAT) known for its capability to infiltrate and control infected systems remotely.
Parallax RAT rat
Also known as ParallaxRAT. Parallax is a Remote Access Trojan used by attackers to gain access to a victim's machine.
Parasite ransomware
Parasite is a type of ransomware that encrypts files on infected systems, demanding a ransom payment in exchange for the decryption key.
Parasite-HTTP-RAT rat
Also known as Parasite HTTP. The RAT, dubbed Parasite HTTP, is especially notable for the extensive array of techniques it incorporates for sandbox detection…
Parite virus
According to Microsoft, Parite is a family of polymorphic file infectors that targets computers running Microsoft Windows.
Parrot TDS
This malicious code written in JavaScript is used as Traffic Direction System (TDS).
Parrot TDS WebShell webshell
In combination with Parrot TDS the usage of a classical web shell was observed by DECODED Avast.io.
PartyTicket ransomware
Also known as Elections GoRansom, HermeticRansom, SonicVote. PartyTicket is a Go-written ransomware, which was described as a poorly designed one by Zscaler.
Pasam trojanbackdoor
Pasam is a trojan used by Elderwood to open a backdoor on compromised hosts.
Pass-The-Hash Toolkit credential-stealer
Pass-The-Hash Toolkit is a toolkit that allows an adversary to "pass" a password hash (without knowing the original password) to log in to…
PassLock ransomware
PassLock is a ransomware family known for encrypting files on victim systems and demanding ransom payments to restore access.
Patcher ransomware
Also known as FileCoder, Findzip. Patcher is ransomware that specifically targets macOS users, attempting to encrypt their files and demand a ransom payment for decryption.
PathWiper wiper
According to Cisco Talos, this wiper replaces the contents of artifacts related to the file system with random data generated on the fly.
Pay-or-Lost ransomware
Pay-or-Lost is a type of ransomware that encrypts files on the victim's system, demanding a ransom payment in exchange for the decryption…
Pay2Decrypt ransomware
Pay2Decrypt is a ransomware that encrypts the victim's files and demands a ransom for decryption.
Pay2Key ransomware
Also known as Cobalt. Pay2Key is a ransomware written in C++ that has been used by Fox Kitten since at least July 2020 including campaigns against Israeli…
PayDOS Ransomware ransomware
Also known as Serpent Ransomware. This is most likely to affect English speaking users, since the note is written in English.
PayDay Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
PayForNature ransomware
PayForNature is a ransomware that encrypts victims' files and demands a ransom for decryption.
PaySafeGen (German) Ransomware ransomware
Also known as Paysafecard Generator 2016, PaySafeCard, PaySafeGen. This is most likely to affect German speaking users, since the note is written in German.
Payloadbin ransomware
Payloadbin is a ransomware group known for encrypting victims' data and demanding ransom in cryptocurrency, often leveraging double…
Paymen45 ransomware
Paymen45 is a type of ransomware that encrypts files on infected systems and demands payment for decryption.
Payment ransomware
Payment is a ransomware family that encrypts victims' files and demands payment for decryption keys, primarily targeting sectors likely to…