Malware Families page 39 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

PsExec
PsExec is a free Microsoft tool that can be used to execute a program on another computer.
PseudoManuscrypt spyware
According to PCrisk, PseudoManuscrypt is the name of the malware that spies on victims.
PshCrypt ransomware
PshCrypt is a type of ransomware that encrypts victim files and demands a ransom for decryption.
PsiX botnetkeyloggerransomware
Also known as PsiXBot. According to Matthew Mesa, this is a modular bot.
Psylo trojan
Psylo is a shellcode-based Trojan that has been used by Scarlet Mimic.
Pteranodon backdoor
Also known as Pterodo. Pteranodon is a custom backdoor used by Gamaredon Group.
PteroGraphin rat
PteroGraphin is a remote access tool (RAT) used for cyber espionage.
Pterois loader
According to Seqrite, this is a loader for a follow-up side-loaded and in memory-staged Cobalt Strike Beacon.
PubNubRAT rat
PubNubRAT is a remote access trojan (RAT) known for leveraging the PubNub real-time cloud messaging API for communication.
PulpFictionQuote ransomware
PulpFictionQuote is a ransomware known for encrypting files and demanding payment for their release.
Pulpy ransomware
Pulpy is a type of ransomware that encrypts victim data and demands a ransom for decryption.
Pulsar RAT ratcredential-stealerkeylogger
According to Broadcom, Pulsar RAT is a derivation of Quasar RAT, which has miscellaneous functionality including keylogging…
PulsarTea backdoor
PulsarTea is a backdoor malware believed to be used by Chinese threat actors.
PumaBot botnetddos
PumaBot is a botnet malware known for distributing denial-of-service attacks against financial services, government, and…
Pump ransomware
Pump ransomware is known for encrypting files on an infected system and demanding a ransom for decryption.
Punisher RAT rat
Punisher RAT is a remote administration tool used primarily for cyber-espionage.
Punkey POS credential-stealer
Also known as poscardstealer, pospunk, punkeypos. Punkey POS is a type of malware that specifically targets point-of-sale systems to steal credit card information.
Pupy rat
Pupy is an open source, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool.
PureCrypter loader
PureCrypter is a fully-featured malware loader, developed by a threat actor called “PureCoder," that has been in use since at least 2021…
PureLocker ransomware
PureLocker is a sophisticated ransomware that has been known to target primarily the financial services and healthcare industries.
PureLogs Stealer credential-stealer
PureLogs, also known as PureLog Stealer, is an infostealer malware from the Pure family that aims to steal sensitive information from…
PureRAT rat
Also known as PureHVNC, ResolverRAT. According to Morphisec, this RAT combines advanced in-memory execution, API and resource resolution at runtime, and layered evasion…
Pureland credential-stealer
According to SentinelOne, this is an infostealer, targeting among other things the encrypted database of Zoom.
PurpleFox rootkitloader
Purple Fox uses msi.dll function, 'MsiInstallProductA', to download and execute its payload.
PurpleWave credential-stealerdownloader
ZScaler reported on a new Infostealer called PurpleWave, which is written in C++ and silently installs itself onto a user’s system.
Pushdo downloader
Pushdo is usually classified as a "downloader" trojan - meaning its true purpose is to download and install additional malicious software.
Putabmow
No information is currently available for this malware named Putabmow, including its purpose or impacted sectors.
PvzOut backdoorrat
PvzOut is a sophisticated remote access trojan (RAT) known for targeting government, financial, and tech sectors.
PwndLocker ransomware
Also known as ProLock. PwndLocker, also known as ProLock, is a ransomware family that targets various industries, encrypting data and demanding ransom payments…
Pwnet cryptominer
Cryptocurrency miner that was distributed masquerading as a Counter-Strike: Global Offensive hack.
PyAesLoader loader
PyAesLoader is a malware loader utilized by various cyber espionage groups to deploy additional payloads.
PyArk trojancredential-stealer
PyArk is a trojan designed primarily for credential theft, targeting various sectors including government and financial services.
PyCL Ransomware ransomware
Also known as Dxh26wam. PyCL Ransomware is a type of malicious software designed to encrypt files on a victim's system, demanding a ransom for decryption.
PyDCrypt droppertrojan
PyDCrypt is malware written in Python designed to deliver DCSrv.
PyL33T Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
PyLocky ransomware
Also known as Locky Locker. PyLocky is a ransomware that tries to pass off as Locky in its ransom note.
PyVil rat
PyVil RAT is a Remote Access Trojan known for its ability to steal sensitive information and provide remote access capabilities to the…
PyXie ratkeyloggercredential-stealer
Also known as PyXie RAT. Full-featured Python RAT compiled into an executable.
Pykspa wormspyware
According to Akamai, Pykspa is a worm that spreads via Skype by sending messages to other Skype users with download links.
PylangGhost rat
Also known as WeaselStore. PylangGhost, also known as WeaselStore, is a RAT reimplemented in Python from its original Golang version.
Pyramid rat
According to its author, Pyramid is a post exploitation framework written in Python, capable of executing offensive tooling from a signed…
Pysa ransomware
Also known as Mespinoza, Pyza. Pysa is a ransomware that was first used in October 2018 and has been seen to target particularly high-value finance, government and…
PyteHole ransomware
PyteHole is a ransomware that encrypts files on the victim's system and demands a ransom for decryption.
Python ransomware
Python ransomware is a type of malicious software that encrypts files on the infected systems and demands a ransom for decryption.
QHost wormbackdoor
Also known as Tolouge. According to F-Secure, this is a network worm with backdoor capabilities, which spreads itself under Win32 systems.
QNAPCrypt ransomware
Also known as eCh0raix. QNAPCrypt, also known as eCh0raix, is a ransomware strain targeting network-attached storage (NAS) devices, particularly those from QNAP.
QNodeService backdoorcredential-stealer
According to Trend Micro, this is a Node.js based malware, that can download/upload/execute files, steal credentials from Chrome/Firefox…
QP ransomware
QP is a ransomware known for encrypting files on infected systems and demanding a ransom payment for decryption keys.
QRat ratkeyloggerscreen-capture
Also known as Quaverse RAT. QRat, also known as Quaverse RAT, was introduced in May 2015 as undetectable (because of multiple layers of obfuscation).
QSnatch credential-stealer
The malware infects QNAP NAS devices, is persisting via various mechanisms and resists cleaning by preventing firmware updates and…
QUADAGENT backdoor
QUADAGENT is a PowerShell backdoor used by OilRig.
QUARTERRIG loaderdownloaderdropper
Also known as MUSKYBEAT, STATICNOISE. A stager used by APT29 to download and run CobaltStrike.
QUICKCAFE downloaderexploit-kit
QUICKCAFE is an encrypted JavaScript downloader for QUICKRIDE.POWER that exploits the ActiveX M2Soft vulnerabilities.
QUICKMUTE downloaderloader
QuickMute is a malware developed using the C/C++ programming language.
QUIETBOARD
QUIETCANARY backdoor
Also known as Tunnus, Kapushka. QUIETCANARY is a backdoor tool written in .NET that has been used since at least 2022 to gather and exfiltrate data from victim networks.
QUIETEXIT backdoor
QUIETEXIT is a novel backdoor, based on the open-source Dropbear SSH client-server software, that has been used by APT29 since at least…
Qaccel
Qadars trojancredential-stealer
Qadars is a banking trojan primarily targeting financial institutions.
QakBot credential-stealertrojanloader
Also known as Pinkslipbot, QuackBot, QBot. QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007.
Qarallax rat
Also known as qrat. Travelers applying for a US Visa in Switzerland were recently targeted by cyber-criminals linked to a malware called QRAT.
Qarallax RAT rat
According to SpiderLabs, in May 2015 the "company" Quaverse offered a RAT known as Quaverse RAT or QRAT.
Qealler credential-stealerspyware
Also known as Pyrogenic Infostealer. Qealler, also known as Pyrogenic Infostealer, is a malware family that focuses on exfiltrating sensitive information such as credentials…
Qilin ransomware
Also known as Agenda. Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022.
Qinynore ransomware
Qinynore is a type of ransomware that encrypts data on victim machines and demands a ransom for decryption.
Qlocker ransomware
Qlocker is a ransomware that encrypts files and demands a ransom in exchange for decryption keys.
QtBot botnetrat
Also known as qtproject. QtBot is a remote access tool (RAT) often used in cyber espionage campaigns targeting various industries.
QuakeWay ransomware
QuakeWay is a type of ransomware known for encrypting files on victim systems and demanding a ransom payment in cryptocurrency to restore…
QuanPinLoader loader
According to ESET Research, this is a loader that has the Mandarin Chinese symbol (yang in the Pinyin transliteration) as an icon in the…
QuantLoader loaderdownloader
QuantLoader is a malware primarily used to load and execute additional malicious payloads onto infected systems.
QuantumLocker ransomware
Also known as Quantum, Mount Locker, DagonLocker. QuantumLocker, also known as Quantum, Mount Locker, and DagonLocker, is a ransomware family that encrypts files on infected systems to…
Quasar RAT ratkeyloggerscreen-capture
Also known as CinaRAT, QuasarRAT, Yggdrasil. Quasar RAT is a malware family written in .NET which is used by a variety of attackers.
QuasarRAT rat
Also known as xRAT. QuasarRAT is an open-source, remote access tool that has been publicly available on GitHub since at least 2014.
Quaverse ratkeyloggercredential-stealer
Also known as QRAT. Quaverse RAT or QRAT is a fairly new Remote Access Tool (RAT) introduced in May 2015.
Quick Assist rat
Quick Assist is a remote assistance tool primarily for Microsoft Windows, although a macOS version also exists.
QuickHeal
QuickHeal is a potential name collision and does not refer to a known specific malicious software in the current cybersecurity landscape…
QuietSieve credential-stealerspyware
QuietSieve is an information stealer that has been used by Gamaredon Group since at least 2021.
QuirkyLoader loader
According to X-Force, this is a loader module written in .NET languages for which ahead-of-time (AOT) compilation is used.
QuiteRAT rat
Also known as Acres. QuiteRAT is a simple remote access trojan written with the help of Qt libraries.
Qulab credential-stealerspyware
Qulab is an AutoIT Malware focusing on stealing & clipping content from victim's machines.
QvoidStealer credential-stealer
Also known as Qvoid-Token-Grabber. QvoidStealer, also known as Qvoid-Token-Grabber, is a type of credential-stealing malware that targets sensitive information like…
Qwerty Ransomware ransomware
A new ransomware has been discovered that utilizes the legitimate GnuPG, or GPG, encryption program to encrypt a victim's files.
Qweuirtksd ransomware
Qweuirtksd is a type of ransomware that encrypts files on infected systems, demanding payment in exchange for decryption.
Qyick Ransomware ransomware
Qyick Ransomware is a type of ransomware that threatens to encrypt a user's data unless a ransom is paid.
R ransomware
Also known as NM3. R is a sophisticated ransomware targeting critical industries such as financial services and healthcare.
R3store ransomware
R3store is a sophisticated ransomware family known for encrypting victims' files and demanding ransom payments in cryptocurrency.
R980 ransomware
R980 is a ransomware strain known for encrypting victim files and demanding a ransom payment.
RAA encryptor ransomware
Also known as RAA, RAA SEP. RAA encryptor is a ransomware family written entirely in JavaScript, distributed primarily through email attachments.
RAILSETTER loadertrojan
According to Trend Micro, RAILSETTER is a persistence installer component designed to work with RAILLOAD.
RAPIDPULSE webshell
RAPIDPULSE is a web shell that exists as a modification to a legitimate Pulse Secure file that has been used by APT5 since at least 2021.
RARSTONE rat
RARSTONE is malware used by the Naikon group that has some characteristics similar to PlugX.
RASTAKHIZ ransomware
Hidden Tear variant discovered in October 2016.
RATANKBA rat
Also known as QUICKRIDE. RATANKBA is a remote controller tool used by Lazarus Group.
RATAttack rat
RATAttack is a remote access trojan (RAT) that uses the Telegram protocol to support encrypted communication between the victim's machine…
RATel rat
RATel is a remote access tool (RAT) utilized in cyber espionage campaigns.
RAWDOOR backdoorrat
RAWDOOR is a backdoor malware primarily used in cyber-espionage operations.
RC2FM backdoorspyware
A family identified by ESET Research in the InvisiMole campaign.
RCS ratspywarescreen-capture
Also known as Crisis, Remote Control System. RCS, also known as Crisis or Remote Control System, is a sophisticated surveillance malware developed by Hacking Team.
RCSAndroid spywaretrojan
RCSAndroid is a sophisticated Android malware designed for surveillance and espionage.
RCSession backdoorrat
RCSession is a backdoor written in C++ that has been in use since at least 2018 by Mustang Panda and by Threat Group-3390 (Type II…