Malware Families page 37 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

PcShare rat
PcShare is an open source remote access tool that has been modified and used by Chinese threat actors, most notably during the FunnyDream…
Pcexter downloader
Pcexter is an uploader that has been used by ToddyCat since at least 2023 to exfiltrate stolen files.
PeaceNotWar wiper
PeaceNotWar was integrated into the nodejs module node-ipc as a piece of malware/protestware with wiper characteristics.
Pearl Stealer credential-stealer
Pearl Stealer is a credential-stealing malware family known for targeting financial and governmental sectors to harvest sensitive data.
PeckBirdy backdoorrattrojan
According to Trend Micro, PeckBirdy is a script-based framework which, while possessing advanced capabilities, is implemented using…
Pedcont ransomware
new destrucrtive ransomware called Pedcont that claims to encrypt files because the victim has accessed illegal content on the deep web.
PeddleCheap backdoor
PeddleCheap is a module of the DanderSpritz framework which surface with the "Lost in Translation" release of TheShadowBrokers leaks.
Pegasus for Android spyware
Also known as Chrysaor. Pegasus for Android is the Android version of malware that has reportedly been linked to the NSO Group.
Pegasus for iOS spywaretrojan
Pegasus for iOS is the iOS version of malware that has reportedly been linked to the NSO Group.
Peirates exploit-kit
Peirates is a post-exploitation Kubernetes exploitation framework with a focus on gathering service account tokens for lateral movement…
Pekraut trojanrat
Pekraut is a remote access trojan known for targeting financial services and government sectors.
Pelmeni loaderrat
Pelmeni is a malware loader used as a wrapper for Kazuar.
Penco trojan
Penco is a trojan malware primarily used to target financial and governmental institutions.
Pendor ransomware
Pendor is a type of ransomware designed to encrypt files on the victim's system and demand a ransom for decryption.
PennyWise Stealer credential-stealer
PennyWise Stealer is a malware family designed to steal credentials from compromised systems.
Pennywise ransomware
Pennywise is a ransomware family known for encrypting files on victim's systems, demanding payment for decryption keys.
Penquin rat
Also known as Penquin 2.0, Penquin_x64. Penquin is a remote access trojan (RAT) with multiple versions used by Turla to target Linux systems since at least 2014.
Penquin Turla backdoorrootkit
Penquin Turla is a sophisticated Linux malware associated with the Turla APT group.
PentagonRAT rat
PentagonRAT is a remote access trojan often utilized in cyber-espionage operations targeting government and defense sectors.
Peppy rat
Peppy is a Python-based remote access Trojan, active since at least 2012, with similarities to Crimson.
Peppy RAT ratkeylogger
Peppy is a Python-based RAT with the majority of its appearances having similarities or definite overlap with MSIL/Crimson appearances.
PerlBot botnetddostrojan
Also known as DDoS Perl IrcBot, ShellBot. PerlBot, also known as DDoS Perl IrcBot or ShellBot, is a malware family leveraging the Perl scripting language for distributed…
Persirai botnet
Persirai is a botnet malware that targets internet-connected IP cameras.
PetitPotato backdoorrat
PetitPotato is a remote access Trojan (RAT) used for cyber espionage activities targeting multiple industries, including government…
PetrWrap ransomwaretrojan
The PetrWrap Trojan is written in C and compiled in MS Visual Studio.
PetrWrap Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Petya ransomwarewiper
Also known as Goldeneye. Ransomware encrypts disk partitions PDFBewerbungsmappe.exe
PewCrypt +decrypt ransomware
PewCrypt is a ransomware which encrypts files on the infected system and demands payment for decryption.
PewDiePie ransomware
PewDiePie is a type of ransomware that encrypts files on infected systems and demands a ransom payment for their decryption.
PewPew ransomware
PewPew is a form of ransomware known for encrypting files on infected systems and demanding a ransom for their decryption.
PhanDoor ratbackdoor
PhanDoor is a remote access tool primarily used by threat actors targeting government and educational institutions in Southeast Asia.
Phantom Stealer credential-stealerkeyloggerspyware
According to Proofpoint, this is a fork of Stealerium that has high overlap with its originating codebase.
PhantomCore backdoorransomware
According to Cyble, PhantomCore is a backdoor utilized by the hacktivist group Head Mare.
PhantomLance spywaretrojan
Also known as PWNDROID1. PhantomLance is a sophisticated malware family known for targeting Android devices.
Phemedrone Stealer credential-stealer
Also known as Ov3r_Stealer. Phemedrone Stealer, also known as Ov3r_Stealer, is a credential-stealing malware family targeting sensitive information across various…
Phenakite spywaretrojan
Also known as Dakkatoni. Phenakite is a mobile malware that is used by APT-C-23 to target iOS devices.
Philadelphia ransomware
Philadelphia is a type of ransomware coded by an individual known as 'The_Rainmaker'.
Philadephia Ransom ransomware
Philadelphia Ransom is a ransomware family known for encrypting files on infected systems and demanding a ransom for their decryption.
Phobos ransomware
Also known as Java NotDharma. Phobos exploits open or poorly secured RDP ports to sneak inside networks and execute a ransomware attack, encrypting files and demanding…
PhobosImposter ransomware
PhobosImposter is a ransomware strain known for encrypting files and demanding a ransom in cryptocurrency.
Phoenix ransomware
Phoenix ransomware is known for targeting organizations in financial services, healthcare, and government sectors across North America and…
Phoenix Keylogger keyloggercredential-stealer
Phoenix Keylogger is a keylogger and information stealer that targets sensitive information, including credentials, from infected systems.
Phoenix Locker ransomware
Phoenix Locker is a ransomware family that encrypts files on infected systems and demands a ransom for decryption keys.
PhoneNumber ransomware
PhoneNumber is a ransomware type malware known for encrypting files on victim devices and demanding a ransom for decryption.
PhoneSpy spyware
According to Zimperium, PhoneSpy is a spyware aimed at South Korean residents with Android devices.
Phonk trojan
Phonk is a malware that functions primarily as a trojan, capable of stealthily infiltrating computer systems.
PhonyC2 rat
PhonyC2 is a remote access tool (RAT) designed to provide attackers with control over compromised systems.
Phorpiex botnetdownloadercryptominer
Also known as Trik, phorphiex. Proofpoint describes Phorpiex/Trik as a SDBot fork (thus IRC-based) that has been used to distribute GandCrab, Pushdo, Pony, and coinminers.
PhotoLoader loader
Also known as GZIPLOADER. A loader used to deliver IcedID, fetching a fake image from which payloads are extracted.
PicassoLoader loader
PicassoLoader is a malware loader used to distribute various malicious payloads.
PicklesRansomware ransomware
Also known as Pickles. This is most likely to affect English speaking users, since the note is written in English.
Pierogi rat
Pierogi is a Remote Access Trojan (RAT) linked to Russian threat actors, primarily targeting Eastern European entities.
PigmyGoat rattrojan
PigmyGoat is a remote access trojan primarily used to infiltrate government and financial organizations.
Pikabot backdoor
Pikabot is a backdoor used for initial access and follow-on tool deployment active since early 2023.
Pillowmint credential-stealer
Pillowmint is a point-of-sale malware used by FIN7 designed to capture credit card information.
PinchDuke trojanbackdoor
PinchDuke is malware that was used by APT29 from 2008 to 2010.
PindOS trojan
PindOS is a sophisticated trojan primarily targeting government and technology sectors.
Ping
Ping is an operating system utility commonly used to troubleshoot and verify network connections.
PingBack ratbackdoor
PingBack is a Remote Access Trojan (RAT) known for providing attackers with backdoor access to compromised systems.
PingPull rat
PingPull is a remote access Trojan (RAT) written in Visual C++ that has been used by GALLIUM since at least June 2022.
Pink botnet
A botnet with P2P and centralized C&C capabilities.
PintSized backdoor
Backdoor as a fork of OpenSSH_6.0 with no logging, and “-P” and “-z” hidden command arguments.
PipeMagic rat
PipeMagic is a remote access trojan targeting critical infrastructure, particularly in the energy sector.
PipeMon backdoor
PipeMon is a multi-stage modular backdoor used by Winnti Group.
PipeSnoop rat
Also known as TOFUPIPE. Cisco Talos states that PipeSnoop can accept arbitrary shellcode from a named pipe and execute it on the infected endpoint.
PirateStealer credential-stealertrojan
PirateStealer is an infostealer malware focused on stealing credentials from infected systems.
Pirateware ransomware
Pirateware is a type of ransomware that encrypts files on the victim's system and demands payment for the decryption key.
Pirrit
Pirrit is an adware known to primarily target macOS systems.
Pisloader backdoorratloader
Pisloader is a malware family that is notable due to its use of DNS as a C2 protocol as well as its use of anti-analysis tactics.
Pitou botnetrootkit
According to TG Soft, Pitou has beeen released on April 2014.
PittyTiger RAT rat
PittyTiger RAT is a remote access trojan used by an advanced persistent threat group, primarily targeting sectors such as government…
PixPirate trojan
According to PCrisk, The PixPirate is a dangerous Android banking Trojan that has the capability to carry out ATS (Automatic Transfer…
PixStealer trojancredential-stealer
Also known as BrazKing. PixStealer, also known as BrazKing, is a mobile banking trojan that primarily targets Android devices.
PixyNetLoader loader
PixyNetLoader is a malware loader designed to deploy additional malware onto infected systems.
Pizhon ransomware
Pizhon is a type of ransomware known to encrypt files on infected systems, demanding a ransom payment for decryption keys.
PizzaCrypts ransomware
PizzaCrypts is a ransomware family that encrypts files on the victim's machine and demands a ransom for decryption.
PjobRAT rat
PjobRAT is a remote access trojan often used in targeted cyber espionage campaigns primarily focused on South Asian countries.
Pkybot downloadertrojan
Also known as Bublik, Pykbot, TBag. Pkybot is a trojan, which has its roots as a downloader dubbed Bublik in 2013 and was seen distributing GameoverZeus in 2014 (ref…
Plague backdoorrootkit
According to Nexttron Systems, this is an implant built as a malicious PAM (Pluggable Authentication Module), enabling attackers to…
PlainGnome spywaredropper
According to Lookout, PlainGnome consists of a two-stage deployment in which a very minimal first stage drops a malicious APK once it’s…
Planetary ransomware
First discovered by malware security analyst, Lawrence Abrams, PLANETARY is an updated variant of another high-risk ransomware called HC7.
Plasma RAT ratbotnetcryptominer
Plasma RAT’s stub is fairly advanced, having many robust features.
Playcrypt ransomware
Also known as Play. Playcrypt is a ransomware that has been used by Play since at least 2022 in attacks against against the business, government, critical…
PleaseRead Ransomware ransomware
Also known as VHDLocker Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
Ploutus ATM trojan
Ploutus ATM malware is designed to target automated teller machines (ATMs), allowing attackers to dispense cash without needing a bank card.
PlugX rat
Also known as Thoper, TVT, DestroyRAT. PlugX is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.
Plurox backdoorbotnetcryptominer
Plurox is a modular malware family that can dynamically load plugins for various functionalities, including acting as a backdoor, a…
PoSlurp credential-stealer
Also known as PUNCHTRACK. PoSlurp, also known as PUNCHTRACK, is a malware family designed to steal payment card data from point-of-sale (POS) systems.
Pocket RAT rat
Pocket RAT is a remote access trojan primarily targeting mobile devices, often used for surveillance and data exfiltration.
Poco RAT rat
Poco RAT is a remote access tool used primarily for cyber espionage activities.
PocoDown downloaderloader
Also known as Blitz, PocoDownloader. uses POCO C++ cross-platform library, Xor-based string obfuscation, SSL library code and string overlap with Xtunnel, infrastructure…
Podec trojan
Podec is an Android trojan that redirects users to premium rate SMS services, leading to financial exploitation.
Poet RAT rat
Cisco Talos has discovered a Python-based RAT they call Poet RAT.
PoetRAT rat
PoetRAT is a remote access trojan (RAT) that was first identified in April 2020.
Poison RAT rat
Poison RAT is a remote access trojan commonly used for cyber espionage.
PoisonCarp spyware
Also known as INSOMNIA. PoisonCarp, also known as INSOMNIA, is a cyber espionage group targeting government entities in South Asia.
PoisonFang ransomware
PoisonFang is a ransomware malware known for encrypting files on infected systems and demanding a ransom for their decryption.
PoisonIvy rat
Also known as Breut, Poison Ivy, Darkmoon. PoisonIvy is a popular remote access tool (RAT) that has been used by many groups.
Pojie ransomware
Pojie is a ransomware that encrypts files on infected systems, demanding a ransom for file decryption.
PokemonGO ransomware
PokemonGO is a ransomware variant based on the open-source project Hidden Tear.