Malware Families page 37 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- PcShare rat
- PcShare is an open source remote access tool that has been modified and used by Chinese threat actors, most notably during the FunnyDream…
- Pcexter downloader
- Pcexter is an uploader that has been used by ToddyCat since at least 2023 to exfiltrate stolen files.
- PeaceNotWar wiper
- PeaceNotWar was integrated into the nodejs module node-ipc as a piece of malware/protestware with wiper characteristics.
- Pearl Stealer credential-stealer
- Pearl Stealer is a credential-stealing malware family known for targeting financial and governmental sectors to harvest sensitive data.
- PeckBirdy backdoorrattrojan
- According to Trend Micro, PeckBirdy is a script-based framework which, while possessing advanced capabilities, is implemented using…
- Pedcont ransomware
- new destrucrtive ransomware called Pedcont that claims to encrypt files because the victim has accessed illegal content on the deep web.
- PeddleCheap backdoor
- PeddleCheap is a module of the DanderSpritz framework which surface with the "Lost in Translation" release of TheShadowBrokers leaks.
- Pegasus for Android spyware
- Also known as Chrysaor. Pegasus for Android is the Android version of malware that has reportedly been linked to the NSO Group.
- Pegasus for iOS spywaretrojan
- Pegasus for iOS is the iOS version of malware that has reportedly been linked to the NSO Group.
- Peirates exploit-kit
- Peirates is a post-exploitation Kubernetes exploitation framework with a focus on gathering service account tokens for lateral movement…
- Pekraut trojanrat
- Pekraut is a remote access trojan known for targeting financial services and government sectors.
- Pelmeni loaderrat
- Pelmeni is a malware loader used as a wrapper for Kazuar.
- Penco trojan
- Penco is a trojan malware primarily used to target financial and governmental institutions.
- Pendor ransomware
- Pendor is a type of ransomware designed to encrypt files on the victim's system and demand a ransom for decryption.
- PennyWise Stealer credential-stealer
- PennyWise Stealer is a malware family designed to steal credentials from compromised systems.
- Pennywise ransomware
- Pennywise is a ransomware family known for encrypting files on victim's systems, demanding payment for decryption keys.
- Penquin rat
- Also known as Penquin 2.0, Penquin_x64. Penquin is a remote access trojan (RAT) with multiple versions used by Turla to target Linux systems since at least 2014.
- Penquin Turla backdoorrootkit
- Penquin Turla is a sophisticated Linux malware associated with the Turla APT group.
- PentagonRAT rat
- PentagonRAT is a remote access trojan often utilized in cyber-espionage operations targeting government and defense sectors.
- Peppy rat
- Peppy is a Python-based remote access Trojan, active since at least 2012, with similarities to Crimson.
- Peppy RAT ratkeylogger
- Peppy is a Python-based RAT with the majority of its appearances having similarities or definite overlap with MSIL/Crimson appearances.
- PerlBot botnetddostrojan
- Also known as DDoS Perl IrcBot, ShellBot. PerlBot, also known as DDoS Perl IrcBot or ShellBot, is a malware family leveraging the Perl scripting language for distributed…
- Persirai botnet
- Persirai is a botnet malware that targets internet-connected IP cameras.
- PetitPotato backdoorrat
- PetitPotato is a remote access Trojan (RAT) used for cyber espionage activities targeting multiple industries, including government…
- PetrWrap ransomwaretrojan
- The PetrWrap Trojan is written in C and compiled in MS Visual Studio.
- PetrWrap Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Petya ransomwarewiper
- Also known as Goldeneye. Ransomware encrypts disk partitions PDFBewerbungsmappe.exe
- PewCrypt +decrypt ransomware
- PewCrypt is a ransomware which encrypts files on the infected system and demands payment for decryption.
- PewDiePie ransomware
- PewDiePie is a type of ransomware that encrypts files on infected systems and demands a ransom payment for their decryption.
- PewPew ransomware
- PewPew is a form of ransomware known for encrypting files on infected systems and demanding a ransom for their decryption.
- PhanDoor ratbackdoor
- PhanDoor is a remote access tool primarily used by threat actors targeting government and educational institutions in Southeast Asia.
- Phantom Stealer credential-stealerkeyloggerspyware
- According to Proofpoint, this is a fork of Stealerium that has high overlap with its originating codebase.
- PhantomCore backdoorransomware
- According to Cyble, PhantomCore is a backdoor utilized by the hacktivist group Head Mare.
- PhantomLance spywaretrojan
- Also known as PWNDROID1. PhantomLance is a sophisticated malware family known for targeting Android devices.
- Phemedrone Stealer credential-stealer
- Also known as Ov3r_Stealer. Phemedrone Stealer, also known as Ov3r_Stealer, is a credential-stealing malware family targeting sensitive information across various…
- Phenakite spywaretrojan
- Also known as Dakkatoni. Phenakite is a mobile malware that is used by APT-C-23 to target iOS devices.
- Philadelphia ransomware
- Philadelphia is a type of ransomware coded by an individual known as 'The_Rainmaker'.
- Philadephia Ransom ransomware
- Philadelphia Ransom is a ransomware family known for encrypting files on infected systems and demanding a ransom for their decryption.
- Phobos ransomware
- Also known as Java NotDharma. Phobos exploits open or poorly secured RDP ports to sneak inside networks and execute a ransomware attack, encrypting files and demanding…
- PhobosImposter ransomware
- PhobosImposter is a ransomware strain known for encrypting files and demanding a ransom in cryptocurrency.
- Phoenix ransomware
- Phoenix ransomware is known for targeting organizations in financial services, healthcare, and government sectors across North America and…
- Phoenix Keylogger keyloggercredential-stealer
- Phoenix Keylogger is a keylogger and information stealer that targets sensitive information, including credentials, from infected systems.
- Phoenix Locker ransomware
- Phoenix Locker is a ransomware family that encrypts files on infected systems and demands a ransom for decryption keys.
- PhoneNumber ransomware
- PhoneNumber is a ransomware type malware known for encrypting files on victim devices and demanding a ransom for decryption.
- PhoneSpy spyware
- According to Zimperium, PhoneSpy is a spyware aimed at South Korean residents with Android devices.
- Phonk trojan
- Phonk is a malware that functions primarily as a trojan, capable of stealthily infiltrating computer systems.
- PhonyC2 rat
- PhonyC2 is a remote access tool (RAT) designed to provide attackers with control over compromised systems.
- Phorpiex botnetdownloadercryptominer
- Also known as Trik, phorphiex. Proofpoint describes Phorpiex/Trik as a SDBot fork (thus IRC-based) that has been used to distribute GandCrab, Pushdo, Pony, and coinminers.
- PhotoLoader loader
- Also known as GZIPLOADER. A loader used to deliver IcedID, fetching a fake image from which payloads are extracted.
- PicassoLoader loader
- PicassoLoader is a malware loader used to distribute various malicious payloads.
- PicklesRansomware ransomware
- Also known as Pickles. This is most likely to affect English speaking users, since the note is written in English.
- Pierogi rat
- Pierogi is a Remote Access Trojan (RAT) linked to Russian threat actors, primarily targeting Eastern European entities.
- PigmyGoat rattrojan
- PigmyGoat is a remote access trojan primarily used to infiltrate government and financial organizations.
- Pikabot backdoor
- Pikabot is a backdoor used for initial access and follow-on tool deployment active since early 2023.
- Pillowmint credential-stealer
- Pillowmint is a point-of-sale malware used by FIN7 designed to capture credit card information.
- PinchDuke trojanbackdoor
- PinchDuke is malware that was used by APT29 from 2008 to 2010.
- PindOS trojan
- PindOS is a sophisticated trojan primarily targeting government and technology sectors.
- Ping
- Ping is an operating system utility commonly used to troubleshoot and verify network connections.
- PingBack ratbackdoor
- PingBack is a Remote Access Trojan (RAT) known for providing attackers with backdoor access to compromised systems.
- PingPull rat
- PingPull is a remote access Trojan (RAT) written in Visual C++ that has been used by GALLIUM since at least June 2022.
- Pink botnet
- A botnet with P2P and centralized C&C capabilities.
- PintSized backdoor
- Backdoor as a fork of OpenSSH_6.0 with no logging, and “-P” and “-z” hidden command arguments.
- PipeMagic rat
- PipeMagic is a remote access trojan targeting critical infrastructure, particularly in the energy sector.
- PipeMon backdoor
- PipeMon is a multi-stage modular backdoor used by Winnti Group.
- PipeSnoop rat
- Also known as TOFUPIPE. Cisco Talos states that PipeSnoop can accept arbitrary shellcode from a named pipe and execute it on the infected endpoint.
- PirateStealer credential-stealertrojan
- PirateStealer is an infostealer malware focused on stealing credentials from infected systems.
- Pirateware ransomware
- Pirateware is a type of ransomware that encrypts files on the victim's system and demands payment for the decryption key.
- Pirrit
- Pirrit is an adware known to primarily target macOS systems.
- Pisloader backdoorratloader
- Pisloader is a malware family that is notable due to its use of DNS as a C2 protocol as well as its use of anti-analysis tactics.
- Pitou botnetrootkit
- According to TG Soft, Pitou has beeen released on April 2014.
- PittyTiger RAT rat
- PittyTiger RAT is a remote access trojan used by an advanced persistent threat group, primarily targeting sectors such as government…
- PixPirate trojan
- According to PCrisk, The PixPirate is a dangerous Android banking Trojan that has the capability to carry out ATS (Automatic Transfer…
- PixStealer trojancredential-stealer
- Also known as BrazKing. PixStealer, also known as BrazKing, is a mobile banking trojan that primarily targets Android devices.
- PixyNetLoader loader
- PixyNetLoader is a malware loader designed to deploy additional malware onto infected systems.
- Pizhon ransomware
- Pizhon is a type of ransomware known to encrypt files on infected systems, demanding a ransom payment for decryption keys.
- PizzaCrypts ransomware
- PizzaCrypts is a ransomware family that encrypts files on the victim's machine and demands a ransom for decryption.
- PjobRAT rat
- PjobRAT is a remote access trojan often used in targeted cyber espionage campaigns primarily focused on South Asian countries.
- Pkybot downloadertrojan
- Also known as Bublik, Pykbot, TBag. Pkybot is a trojan, which has its roots as a downloader dubbed Bublik in 2013 and was seen distributing GameoverZeus in 2014 (ref…
- Plague backdoorrootkit
- According to Nexttron Systems, this is an implant built as a malicious PAM (Pluggable Authentication Module), enabling attackers to…
- PlainGnome spywaredropper
- According to Lookout, PlainGnome consists of a two-stage deployment in which a very minimal first stage drops a malicious APK once it’s…
- Planetary ransomware
- First discovered by malware security analyst, Lawrence Abrams, PLANETARY is an updated variant of another high-risk ransomware called HC7.
- Plasma RAT ratbotnetcryptominer
- Plasma RAT’s stub is fairly advanced, having many robust features.
- Playcrypt ransomware
- Also known as Play. Playcrypt is a ransomware that has been used by Play since at least 2022 in attacks against against the business, government, critical…
- PleaseRead Ransomware ransomware
- Also known as VHDLocker Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- Ploutus ATM trojan
- Ploutus ATM malware is designed to target automated teller machines (ATMs), allowing attackers to dispense cash without needing a bank card.
- PlugX rat
- Also known as Thoper, TVT, DestroyRAT. PlugX is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.
- Plurox backdoorbotnetcryptominer
- Plurox is a modular malware family that can dynamically load plugins for various functionalities, including acting as a backdoor, a…
- PoSlurp credential-stealer
- Also known as PUNCHTRACK. PoSlurp, also known as PUNCHTRACK, is a malware family designed to steal payment card data from point-of-sale (POS) systems.
- Pocket RAT rat
- Pocket RAT is a remote access trojan primarily targeting mobile devices, often used for surveillance and data exfiltration.
- Poco RAT rat
- Poco RAT is a remote access tool used primarily for cyber espionage activities.
- PocoDown downloaderloader
- Also known as Blitz, PocoDownloader. uses POCO C++ cross-platform library, Xor-based string obfuscation, SSL library code and string overlap with Xtunnel, infrastructure…
- Podec trojan
- Podec is an Android trojan that redirects users to premium rate SMS services, leading to financial exploitation.
- Poet RAT rat
- Cisco Talos has discovered a Python-based RAT they call Poet RAT.
- PoetRAT rat
- PoetRAT is a remote access trojan (RAT) that was first identified in April 2020.
- Poison RAT rat
- Poison RAT is a remote access trojan commonly used for cyber espionage.
- PoisonCarp spyware
- Also known as INSOMNIA. PoisonCarp, also known as INSOMNIA, is a cyber espionage group targeting government entities in South Asia.
- PoisonFang ransomware
- PoisonFang is a ransomware malware known for encrypting files on infected systems and demanding a ransom for their decryption.
- PoisonIvy rat
- Also known as Breut, Poison Ivy, Darkmoon. PoisonIvy is a popular remote access tool (RAT) that has been used by many groups.
- Pojie ransomware
- Pojie is a ransomware that encrypts files on infected systems, demanding a ransom for file decryption.
- PokemonGO ransomware
- PokemonGO is a ransomware variant based on the open-source project Hidden Tear.