Malware Families page 38 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

PolPo trojan
PolPo is a trojan malware with relatively low prevalence.
PolarEdge backdoor
According to Sekoia, this is a form of TLS backdoor containing pre-defined commands.
Poldat trojanrat
Also known as KABOB, Zlib. Poldat is a sophisticated remote access trojan (RAT) that has been observed targeting government and financial sectors.
Polski Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Polyglot ransomware
Polyglot is a ransomware that imitates the behavior of CTB-Locker, using similar encryption techniques to lock users out of their assets.
PolyglotDuke downloaderdropper
PolyglotDuke is a downloader that has been used by APT29 since at least 2013.
Pony credential-stealerdownloaderloader
Also known as Fareit, Siplog. Pony is a credential stealing malware, though has also been used among adversaries for its downloader capabilities.
PonyFinal ransomware
PonyFinal is a ransomware strain that targets enterprises, often using Java Runtime Environment for execution.
PoohMilk Loader loader
PoohMilk Loader is a malware strain primarily used to load and execute additional malicious payloads on infected systems.
PooleZoor ransomware
PooleZoor is a ransomware family that encrypts files and demands payment for decryption.
PoorWeb webshell
PoorWeb is a webshell malware used to gain unauthorized access to web servers.
PopCorn Time Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
PopCornTime ransomware
PopCornTime is a ransomware strain that encrypts files and demands a ransom payment for decryption.
Popcorn Time ransomware
Popcorn Time is a form of ransomware that encrypts files and demands a Bitcoin payment to decrypt them.
PornBlackmailer screen-captureransomwarespyware
A new infection is being distributed by porn sites that tries to blackmail a victim into paying a ransom by stating they will tell law…
PortDoor backdoor
PortDoor is a sophisticated backdoor primarily targeting the defense and aerospace sectors.
PortStarter trojan
Also known as SocksProxyGo. PortStarter, also known as SocksProxyGo, is a Trojan malware that facilitates unauthorized network access by enabling port forwarding and…
Poseidon (ELF) rat
Poseidon is an ELF malware component of the Mythic C2 framework, designed for command and control operations.
Poseidon (OS X) rat
Poseidon (OS X) is part of the Mythic C2 framework, designed as a Remote Access Trojan (RAT) specifically for macOS systems.
Poseidon Stealer credential-stealer
Also known as Rodrigo Stealer. macOS infostealer sold by an individual named Rodrigo4, currently consisting of a disk image containing a Mach-O without app bundle, which…
PoshC2 ratdropper
PoshC2 is an open source remote administration and post-exploitation framework that is publicly available on GitHub.
PostNapTea ratscreen-capture
Also known as SIGNBT. PostNapTea aka SIGNBT is an HTTP(S) RAT that is written as a complex object-oriented project.
Postlo rattrojan
Postlo is a remote access trojan (RAT) used for cyber espionage activities, primarily targeting governmental and technology sectors.
Potato Ransomware ransomware
Wants a ransom to get the victim’s files back .
Poulight Stealer credential-stealer
Also known as Poullight. Poulight Stealer, also known as Poullight, is an information-stealing malware designed to exfiltrate sensitive data, including…
Povisomware ransomware
Povisomware is a ransomware family targeting various sectors to encrypt data and demand ransoms.
Povlsomware ransomware
According to Trend Micro, Povlsomware (Ransom.MSIL.POVLSOM.THBAOBA) is a proof-of-concept (POC) ransomware first released in November 2020…
PowGoop loader
PowGoop is a loader that consists of a DLL loader and a PowerShell-based downloader; it has been used by MuddyWater as their main loader.
Poweliks trojanbotnet
Poweliks is a fileless malware that maintains persistence by storing malicious scripts in the Windows registry.
Power Loader downloaderloader
Power Loader is modular code sold in the cybercrime market used as a downloader in malware families such as Carberp, Redyms and Gapz.
PowerBrace ratspyware
PowerBrace is a remote access trojan (RAT) known for enabling persistent unauthorized access to compromised systems.
PowerCat trojan
PowerCat is a simple, open-source PowerShell tool that functions similarly to the netcat utility.
PowerDuke backdoor
PowerDuke is a backdoor that was used by APT29 in 2016.
PowerExchange backdoor
PowerExchange is a PowerShell backdoor that has been used by OilRig since at least 2023 including against government targets in the Middle…
PowerHarbor credential-stealerbackdoorspyware
PowerHarbor is a modular PowerShell-based malware that consists of various modules.
PowerHentai ransomware
PowerHentai is a ransomware variant known for encrypting users' files and demanding a ransom.
PowerLess backdoor
PowerLess is a PowerShell-based modular backdoor that has been used by Magic Hound since at least 2022.
PowerLoader loaderbackdoor
PowerLoader is a malware downloader typically used to load other malicious payloads onto compromised systems.
PowerLocky ransomware
PowerLocky is a ransomware strain that encrypts files on infected systems, demanding a ransom for file decryption.
PowerMagic backdoor
PowerMagic is a backdoor malware associated with cyber espionage activities, particularly targeting government and energy sectors.
PowerNet loaderrat
According to Insikt Group, PowerNet is a custom Powershell loader that decompresses and executes NetSupport RAT.
PowerPepper rat
PowerPepper is a remote access trojan (RAT) used by the threat actor group TA416.
PowerPool backdoortrojan
PowerPool is a malware backdoor used in targeted attacks, primarily focusing on government and public sector organizations in Eastern…
PowerPunch downloader
PowerPunch is a lightweight downloader that has been used by Gamaredon Group since at least 2021.
PowerRAT rat
PowerRAT is a remote access tool used primarily for cyber espionage activities.
PowerRatankba backdoorrat
Also known as QUICKRIDE.POWER. QUICKRIDE.POWER is a PowerShell variant of the QUICKRIDE backdoor.
PowerShell Locker 2013 ransomware
PowerShell Locker 2013 is a ransomware family known for encrypting files and demanding payment in cryptocurrency.
PowerShell Locker 2015 ransomware
PowerShell Locker 2015 is a ransomware threat which leverages PowerShell scripts.
PowerShellRunner loaderdownloader
PowerShellRunner is a fileless malware that leverages PowerShell scripts to execute payloads on a target system.
PowerShortShell backdoortrojan
PowerShortShell is a stealthy PowerShell-based backdoor used for post-exploitation activities.
PowerShower backdoordownloader
PowerShower is a PowerShell backdoor used by Inception for initial reconnaissance and to download and execute second stage payloads.
PowerSploit exploit-kit
PowerSploit is an open source, offensive security framework comprised of PowerShell modules and scripts that perform a wide range of tasks…
PowerSpritz ratspyware
PowerSpritz is a remote access tool (RAT) used for cyber espionage.
PowerStallion backdoor
PowerStallion is a lightweight PowerShell backdoor used by Turla, possibly as a recovery access tool to install other backdoors.
PowerWare ransomware
Also known as PoshCoder. PowerWare, also known as PoshCoder, is a ransomware variant that uses PowerShell scripts for execution.
PowerWorm ransomwarewiper
Ransomware no decryption possible, throws key away, destroys the files
PowerZure exploit-kitspyware
PowerZure is a PowerShell project created to assess and exploit resources within Microsoft’s cloud platform, Azure.
Powersniff trojandownloader
Also known as PUNCHBUGGY. A malware of the gozi group, developed on the base of isfb.
Powmet backdoor
Powmet is a backdoor malware known for targeting government, financial, and technology sectors.
Pr0tector ransomware
Pr0tector is a ransomware known for encrypting victim's files and demanding payment for the decryption key.
Predator ransomware
Also known as PREYHUNTER. Predator, also known as PREYHUNTER, is a ransomware family that encrypts files and demands a ransom for the decryption key.
Predator Pain credential-stealerkeyloggerscreen-capture
Also known as PredatorPain. Unlike Zeus, Predator Pain and Limitless are relatively simple keyloggers.
Predator The Thief credential-stealerspywarekeylogger
Predator is a feature-rich information stealer.
Premier RAT rat
Premier RAT is a remote access tool often used for cyber espionage activities.
PresFox trojandropper
The family is adding a fake root certificate authority, sets a proxy.pac-url for local browsers and redirects infected users to fake…
Prestige ransomware
Prestige ransomware has been used by Sandworm Team since at least March 2022, including against transportation and related logistics…
Priapos ransomware
Priapos is a type of ransomware that encrypts files on an infected system and demands a ransom payment for decryption.
Prikormka spyware
Prikormka is a malware family used in a campaign known as Operation Groundbait.
Prilex trojan
Prilex is a sophisticated malware family known for targeting ATMs and POS systems, primarily in Brazil, to siphon credit card data and…
Princess ransomware
Princess is a form of ransomware that encrypts files on infected systems and demands a ransom payment in cryptocurrency for decryption.
Princess Evolution cryptominerransomwareexploit-kit
Also known as PrincessLocker Evolution. We have been observing a malvertising campaign via Rig exploit kit delivering a cryptocurrency-mining malware and the GandCrab ransomware…
Princess Locker ransomware
Princess Locker is a type of ransomware that encrypts files on the victim's machine and demands a ransom for decryption.
PrincessLocker ransomware
PrincessLocker is a ransomware family known for encrypting files on a victim's system and demanding a ransom payment, typically in…
PrivateLoader loaderdownloader
According to sekoia, PrivateLoader is a modular malware whose main capability is to download and execute one or several payloads.
PrivetSanya trojan
Black Lotus Labs identified malware for the Windows Subsystem for Linux (WSL).
Pro-Ocean cryptominer
Unit 42 describes this as a malware used by Rocke Group that deploys an XMRig miner.
ProLock ransomware
ProLock is a ransomware strain that has been used in Big Game Hunting (BGH) operations since at least 2020, often obtaining initial access…
ProRat backdoorrattrojan
ProRat is a Microsoft Windows based backdoor trojan, more commonly known as a Remote Administration Tool.
Project Alice trojan
Also known as AliceATM, PrAlice. Project Alice is a malware family primarily targeting ATMs in the financial services sector.
Project Hook POS credential-stealer
Project Hook POS is a type of malware designed to exfiltrate credit card data from point-of-sale systems.
Project23 ransomware
Project23 is a ransomware strain known for encrypting files on infected systems and demanding a ransom for decryption keys.
Project34 Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Project57 ransomware
Project57 is a ransomware strain known for targeting multiple sectors including financial services and healthcare.
ProjectWood backdoorloader
ProjectWood is a sophisticated cyber-espionage malware known for targeting government and military entities.
Prometei (ELF) botnetcryptominer
Prometei is a botnet and cryptomining malware primarily used to mine cryptocurrency, particularly Monero.
Prometei (Windows) botnetcryptominer
According to Lior Rochberger, Cybereason, prometei is a modular and multi-stage cryptocurrency botnet.
Prometey ransomware
Prometey is a versatile piece of ransomware that encrypts files and demands a ransom payment in cryptocurrency.
Prometheus ransomware
Ransomware written in .NET, apparently derived from the codebase of win.hakbit (Thanos) ransomware.
Prometheus Backdoor backdoor
Prometheus Backdoor is a PHP-based backdoor that enables unauthorized access to compromised servers.
PromptLock ransomware
According to ESET Research, PromptLock is first known AI-powered ransomware.
Pronsis Loader loaderdownloader
According to TrustWave, this is a loader leveraging JPHP, which was observed fetching Latrodectus and Lumma.
ProposalCrypt Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Protected ransomware
Protected is a ransomware known for encrypting data and demanding payment for decryption keys.
Proto8RAT rat
Proto8RAT is a remote access trojan primarily used for espionage activities, targeting government, financial services, and technology…
Proton backdoorcredential-stealerspyware
Proton is a macOS backdoor focusing on data theft and credential access.
Proton RAT ratcredential-stealerkeylogger
Also known as Calisto. Proton RAT is a Remote Access Trojan (RAT) specifically designed for macOS systems.
ProtonBot botnet
ProtonBot is a prominent malware family that acts as a botnet.
Proxysvc downloader
Proxysvc is a malicious DLL used by Lazarus Group in a campaign known as Operation GhostSecret.
Prynt Stealer credential-stealer
Prynt Stealer is a malware family that focuses on credential theft.
Ps2exe ransomware
Ps2exe is a ransomware that encrypts files on the infected system, demanding a ransom for decryption.