Malware Families page 38 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- PolPo trojan
- PolPo is a trojan malware with relatively low prevalence.
- PolarEdge backdoor
- According to Sekoia, this is a form of TLS backdoor containing pre-defined commands.
- Poldat trojanrat
- Also known as KABOB, Zlib. Poldat is a sophisticated remote access trojan (RAT) that has been observed targeting government and financial sectors.
- Polski Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Polyglot ransomware
- Polyglot is a ransomware that imitates the behavior of CTB-Locker, using similar encryption techniques to lock users out of their assets.
- PolyglotDuke downloaderdropper
- PolyglotDuke is a downloader that has been used by APT29 since at least 2013.
- Pony credential-stealerdownloaderloader
- Also known as Fareit, Siplog. Pony is a credential stealing malware, though has also been used among adversaries for its downloader capabilities.
- PonyFinal ransomware
- PonyFinal is a ransomware strain that targets enterprises, often using Java Runtime Environment for execution.
- PoohMilk Loader loader
- PoohMilk Loader is a malware strain primarily used to load and execute additional malicious payloads on infected systems.
- PooleZoor ransomware
- PooleZoor is a ransomware family that encrypts files and demands payment for decryption.
- PoorWeb webshell
- PoorWeb is a webshell malware used to gain unauthorized access to web servers.
- PopCorn Time Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- PopCornTime ransomware
- PopCornTime is a ransomware strain that encrypts files and demands a ransom payment for decryption.
- Popcorn Time ransomware
- Popcorn Time is a form of ransomware that encrypts files and demands a Bitcoin payment to decrypt them.
- PornBlackmailer screen-captureransomwarespyware
- A new infection is being distributed by porn sites that tries to blackmail a victim into paying a ransom by stating they will tell law…
- PortDoor backdoor
- PortDoor is a sophisticated backdoor primarily targeting the defense and aerospace sectors.
- PortStarter trojan
- Also known as SocksProxyGo. PortStarter, also known as SocksProxyGo, is a Trojan malware that facilitates unauthorized network access by enabling port forwarding and…
- Poseidon (ELF) rat
- Poseidon is an ELF malware component of the Mythic C2 framework, designed for command and control operations.
- Poseidon (OS X) rat
- Poseidon (OS X) is part of the Mythic C2 framework, designed as a Remote Access Trojan (RAT) specifically for macOS systems.
- Poseidon Stealer credential-stealer
- Also known as Rodrigo Stealer. macOS infostealer sold by an individual named Rodrigo4, currently consisting of a disk image containing a Mach-O without app bundle, which…
- PoshC2 ratdropper
- PoshC2 is an open source remote administration and post-exploitation framework that is publicly available on GitHub.
- PostNapTea ratscreen-capture
- Also known as SIGNBT. PostNapTea aka SIGNBT is an HTTP(S) RAT that is written as a complex object-oriented project.
- Postlo rattrojan
- Postlo is a remote access trojan (RAT) used for cyber espionage activities, primarily targeting governmental and technology sectors.
- Potato Ransomware ransomware
- Wants a ransom to get the victim’s files back .
- Poulight Stealer credential-stealer
- Also known as Poullight. Poulight Stealer, also known as Poullight, is an information-stealing malware designed to exfiltrate sensitive data, including…
- Povisomware ransomware
- Povisomware is a ransomware family targeting various sectors to encrypt data and demand ransoms.
- Povlsomware ransomware
- According to Trend Micro, Povlsomware (Ransom.MSIL.POVLSOM.THBAOBA) is a proof-of-concept (POC) ransomware first released in November 2020…
- PowGoop loader
- PowGoop is a loader that consists of a DLL loader and a PowerShell-based downloader; it has been used by MuddyWater as their main loader.
- Poweliks trojanbotnet
- Poweliks is a fileless malware that maintains persistence by storing malicious scripts in the Windows registry.
- Power Loader downloaderloader
- Power Loader is modular code sold in the cybercrime market used as a downloader in malware families such as Carberp, Redyms and Gapz.
- PowerBrace ratspyware
- PowerBrace is a remote access trojan (RAT) known for enabling persistent unauthorized access to compromised systems.
- PowerCat trojan
- PowerCat is a simple, open-source PowerShell tool that functions similarly to the netcat utility.
- PowerDuke backdoor
- PowerDuke is a backdoor that was used by APT29 in 2016.
- PowerExchange backdoor
- PowerExchange is a PowerShell backdoor that has been used by OilRig since at least 2023 including against government targets in the Middle…
- PowerHarbor credential-stealerbackdoorspyware
- PowerHarbor is a modular PowerShell-based malware that consists of various modules.
- PowerHentai ransomware
- PowerHentai is a ransomware variant known for encrypting users' files and demanding a ransom.
- PowerLess backdoor
- PowerLess is a PowerShell-based modular backdoor that has been used by Magic Hound since at least 2022.
- PowerLoader loaderbackdoor
- PowerLoader is a malware downloader typically used to load other malicious payloads onto compromised systems.
- PowerLocky ransomware
- PowerLocky is a ransomware strain that encrypts files on infected systems, demanding a ransom for file decryption.
- PowerMagic backdoor
- PowerMagic is a backdoor malware associated with cyber espionage activities, particularly targeting government and energy sectors.
- PowerNet loaderrat
- According to Insikt Group, PowerNet is a custom Powershell loader that decompresses and executes NetSupport RAT.
- PowerPepper rat
- PowerPepper is a remote access trojan (RAT) used by the threat actor group TA416.
- PowerPool backdoortrojan
- PowerPool is a malware backdoor used in targeted attacks, primarily focusing on government and public sector organizations in Eastern…
- PowerPunch downloader
- PowerPunch is a lightweight downloader that has been used by Gamaredon Group since at least 2021.
- PowerRAT rat
- PowerRAT is a remote access tool used primarily for cyber espionage activities.
- PowerRatankba backdoorrat
- Also known as QUICKRIDE.POWER. QUICKRIDE.POWER is a PowerShell variant of the QUICKRIDE backdoor.
- PowerShell Locker 2013 ransomware
- PowerShell Locker 2013 is a ransomware family known for encrypting files and demanding payment in cryptocurrency.
- PowerShell Locker 2015 ransomware
- PowerShell Locker 2015 is a ransomware threat which leverages PowerShell scripts.
- PowerShellRunner loaderdownloader
- PowerShellRunner is a fileless malware that leverages PowerShell scripts to execute payloads on a target system.
- PowerShortShell backdoortrojan
- PowerShortShell is a stealthy PowerShell-based backdoor used for post-exploitation activities.
- PowerShower backdoordownloader
- PowerShower is a PowerShell backdoor used by Inception for initial reconnaissance and to download and execute second stage payloads.
- PowerSploit exploit-kit
- PowerSploit is an open source, offensive security framework comprised of PowerShell modules and scripts that perform a wide range of tasks…
- PowerSpritz ratspyware
- PowerSpritz is a remote access tool (RAT) used for cyber espionage.
- PowerStallion backdoor
- PowerStallion is a lightweight PowerShell backdoor used by Turla, possibly as a recovery access tool to install other backdoors.
- PowerWare ransomware
- Also known as PoshCoder. PowerWare, also known as PoshCoder, is a ransomware variant that uses PowerShell scripts for execution.
- PowerWorm ransomwarewiper
- Ransomware no decryption possible, throws key away, destroys the files
- PowerZure exploit-kitspyware
- PowerZure is a PowerShell project created to assess and exploit resources within Microsoft’s cloud platform, Azure.
- Powersniff trojandownloader
- Also known as PUNCHBUGGY. A malware of the gozi group, developed on the base of isfb.
- Powmet backdoor
- Powmet is a backdoor malware known for targeting government, financial, and technology sectors.
- Pr0tector ransomware
- Pr0tector is a ransomware known for encrypting victim's files and demanding payment for the decryption key.
- Predator ransomware
- Also known as PREYHUNTER. Predator, also known as PREYHUNTER, is a ransomware family that encrypts files and demands a ransom for the decryption key.
- Predator Pain credential-stealerkeyloggerscreen-capture
- Also known as PredatorPain. Unlike Zeus, Predator Pain and Limitless are relatively simple keyloggers.
- Predator The Thief credential-stealerspywarekeylogger
- Predator is a feature-rich information stealer.
- Premier RAT rat
- Premier RAT is a remote access tool often used for cyber espionage activities.
- PresFox trojandropper
- The family is adding a fake root certificate authority, sets a proxy.pac-url for local browsers and redirects infected users to fake…
- Prestige ransomware
- Prestige ransomware has been used by Sandworm Team since at least March 2022, including against transportation and related logistics…
- Priapos ransomware
- Priapos is a type of ransomware that encrypts files on an infected system and demands a ransom payment for decryption.
- Prikormka spyware
- Prikormka is a malware family used in a campaign known as Operation Groundbait.
- Prilex trojan
- Prilex is a sophisticated malware family known for targeting ATMs and POS systems, primarily in Brazil, to siphon credit card data and…
- Princess ransomware
- Princess is a form of ransomware that encrypts files on infected systems and demands a ransom payment in cryptocurrency for decryption.
- Princess Evolution cryptominerransomwareexploit-kit
- Also known as PrincessLocker Evolution. We have been observing a malvertising campaign via Rig exploit kit delivering a cryptocurrency-mining malware and the GandCrab ransomware…
- Princess Locker ransomware
- Princess Locker is a type of ransomware that encrypts files on the victim's machine and demands a ransom for decryption.
- PrincessLocker ransomware
- PrincessLocker is a ransomware family known for encrypting files on a victim's system and demanding a ransom payment, typically in…
- PrivateLoader loaderdownloader
- According to sekoia, PrivateLoader is a modular malware whose main capability is to download and execute one or several payloads.
- PrivetSanya trojan
- Black Lotus Labs identified malware for the Windows Subsystem for Linux (WSL).
- Pro-Ocean cryptominer
- Unit 42 describes this as a malware used by Rocke Group that deploys an XMRig miner.
- ProLock ransomware
- ProLock is a ransomware strain that has been used in Big Game Hunting (BGH) operations since at least 2020, often obtaining initial access…
- ProRat backdoorrattrojan
- ProRat is a Microsoft Windows based backdoor trojan, more commonly known as a Remote Administration Tool.
- Project Alice trojan
- Also known as AliceATM, PrAlice. Project Alice is a malware family primarily targeting ATMs in the financial services sector.
- Project Hook POS credential-stealer
- Project Hook POS is a type of malware designed to exfiltrate credit card data from point-of-sale systems.
- Project23 ransomware
- Project23 is a ransomware strain known for encrypting files on infected systems and demanding a ransom for decryption keys.
- Project34 Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Project57 ransomware
- Project57 is a ransomware strain known for targeting multiple sectors including financial services and healthcare.
- ProjectWood backdoorloader
- ProjectWood is a sophisticated cyber-espionage malware known for targeting government and military entities.
- Prometei (ELF) botnetcryptominer
- Prometei is a botnet and cryptomining malware primarily used to mine cryptocurrency, particularly Monero.
- Prometei (Windows) botnetcryptominer
- According to Lior Rochberger, Cybereason, prometei is a modular and multi-stage cryptocurrency botnet.
- Prometey ransomware
- Prometey is a versatile piece of ransomware that encrypts files and demands a ransom payment in cryptocurrency.
- Prometheus ransomware
- Ransomware written in .NET, apparently derived from the codebase of win.hakbit (Thanos) ransomware.
- Prometheus Backdoor backdoor
- Prometheus Backdoor is a PHP-based backdoor that enables unauthorized access to compromised servers.
- PromptLock ransomware
- According to ESET Research, PromptLock is first known AI-powered ransomware.
- Pronsis Loader loaderdownloader
- According to TrustWave, this is a loader leveraging JPHP, which was observed fetching Latrodectus and Lumma.
- ProposalCrypt Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Protected ransomware
- Protected is a ransomware known for encrypting data and demanding payment for decryption keys.
- Proto8RAT rat
- Proto8RAT is a remote access trojan primarily used for espionage activities, targeting government, financial services, and technology…
- Proton backdoorcredential-stealerspyware
- Proton is a macOS backdoor focusing on data theft and credential access.
- Proton RAT ratcredential-stealerkeylogger
- Also known as Calisto. Proton RAT is a Remote Access Trojan (RAT) specifically designed for macOS systems.
- ProtonBot botnet
- ProtonBot is a prominent malware family that acts as a botnet.
- Proxysvc downloader
- Proxysvc is a malicious DLL used by Lazarus Group in a campaign known as Operation GhostSecret.
- Prynt Stealer credential-stealer
- Prynt Stealer is a malware family that focuses on credential theft.
- Ps2exe ransomware
- Ps2exe is a ransomware that encrypts files on the infected system, demanding a ransom for decryption.