Malware Families page 39 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- PsExec
- PsExec is a free Microsoft tool that can be used to execute a program on another computer.
- PseudoManuscrypt spyware
- According to PCrisk, PseudoManuscrypt is the name of the malware that spies on victims.
- PshCrypt ransomware
- PshCrypt is a type of ransomware that encrypts victim files and demands a ransom for decryption.
- PsiX botnetkeyloggerransomware
- Also known as PsiXBot. According to Matthew Mesa, this is a modular bot.
- Psylo trojan
- Psylo is a shellcode-based Trojan that has been used by Scarlet Mimic.
- Pteranodon backdoor
- Also known as Pterodo. Pteranodon is a custom backdoor used by Gamaredon Group.
- PteroGraphin rat
- PteroGraphin is a remote access tool (RAT) used for cyber espionage.
- Pterois loader
- According to Seqrite, this is a loader for a follow-up side-loaded and in memory-staged Cobalt Strike Beacon.
- PubNubRAT rat
- PubNubRAT is a remote access trojan (RAT) known for leveraging the PubNub real-time cloud messaging API for communication.
- PulpFictionQuote ransomware
- PulpFictionQuote is a ransomware known for encrypting files and demanding payment for their release.
- Pulpy ransomware
- Pulpy is a type of ransomware that encrypts victim data and demands a ransom for decryption.
- Pulsar RAT ratcredential-stealerkeylogger
- According to Broadcom, Pulsar RAT is a derivation of Quasar RAT, which has miscellaneous functionality including keylogging…
- PulsarTea backdoor
- PulsarTea is a backdoor malware believed to be used by Chinese threat actors.
- PumaBot botnetddos
- PumaBot is a botnet malware known for distributing denial-of-service attacks against financial services, government, and…
- Pump ransomware
- Pump ransomware is known for encrypting files on an infected system and demanding a ransom for decryption.
- Punisher RAT rat
- Punisher RAT is a remote administration tool used primarily for cyber-espionage.
- Punkey POS credential-stealer
- Also known as poscardstealer, pospunk, punkeypos. Punkey POS is a type of malware that specifically targets point-of-sale systems to steal credit card information.
- Pupy rat
- Pupy is an open source, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool.
- PureCrypter loader
- PureCrypter is a fully-featured malware loader, developed by a threat actor called “PureCoder," that has been in use since at least 2021…
- PureLocker ransomware
- PureLocker is a sophisticated ransomware that has been known to target primarily the financial services and healthcare industries.
- PureLogs Stealer credential-stealer
- PureLogs, also known as PureLog Stealer, is an infostealer malware from the Pure family that aims to steal sensitive information from…
- PureRAT rat
- Also known as PureHVNC, ResolverRAT. According to Morphisec, this RAT combines advanced in-memory execution, API and resource resolution at runtime, and layered evasion…
- Pureland credential-stealer
- According to SentinelOne, this is an infostealer, targeting among other things the encrypted database of Zoom.
- PurpleFox rootkitloader
- Purple Fox uses msi.dll function, 'MsiInstallProductA', to download and execute its payload.
- PurpleWave credential-stealerdownloader
- ZScaler reported on a new Infostealer called PurpleWave, which is written in C++ and silently installs itself onto a user’s system.
- Pushdo downloader
- Pushdo is usually classified as a "downloader" trojan - meaning its true purpose is to download and install additional malicious software.
- Putabmow
- No information is currently available for this malware named Putabmow, including its purpose or impacted sectors.
- PvzOut backdoorrat
- PvzOut is a sophisticated remote access trojan (RAT) known for targeting government, financial, and tech sectors.
- PwndLocker ransomware
- Also known as ProLock. PwndLocker, also known as ProLock, is a ransomware family that targets various industries, encrypting data and demanding ransom payments…
- Pwnet cryptominer
- Cryptocurrency miner that was distributed masquerading as a Counter-Strike: Global Offensive hack.
- PyAesLoader loader
- PyAesLoader is a malware loader utilized by various cyber espionage groups to deploy additional payloads.
- PyArk trojancredential-stealer
- PyArk is a trojan designed primarily for credential theft, targeting various sectors including government and financial services.
- PyCL Ransomware ransomware
- Also known as Dxh26wam. PyCL Ransomware is a type of malicious software designed to encrypt files on a victim's system, demanding a ransom for decryption.
- PyDCrypt droppertrojan
- PyDCrypt is malware written in Python designed to deliver DCSrv.
- PyL33T Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- PyLocky ransomware
- Also known as Locky Locker. PyLocky is a ransomware that tries to pass off as Locky in its ransom note.
- PyVil rat
- PyVil RAT is a Remote Access Trojan known for its ability to steal sensitive information and provide remote access capabilities to the…
- PyXie ratkeyloggercredential-stealer
- Also known as PyXie RAT. Full-featured Python RAT compiled into an executable.
- Pykspa wormspyware
- According to Akamai, Pykspa is a worm that spreads via Skype by sending messages to other Skype users with download links.
- PylangGhost rat
- Also known as WeaselStore. PylangGhost, also known as WeaselStore, is a RAT reimplemented in Python from its original Golang version.
- Pyramid rat
- According to its author, Pyramid is a post exploitation framework written in Python, capable of executing offensive tooling from a signed…
- Pysa ransomware
- Also known as Mespinoza, Pyza. Pysa is a ransomware that was first used in October 2018 and has been seen to target particularly high-value finance, government and…
- PyteHole ransomware
- PyteHole is a ransomware that encrypts files on the victim's system and demands a ransom for decryption.
- Python ransomware
- Python ransomware is a type of malicious software that encrypts files on the infected systems and demands a ransom for decryption.
- QHost wormbackdoor
- Also known as Tolouge. According to F-Secure, this is a network worm with backdoor capabilities, which spreads itself under Win32 systems.
- QNAPCrypt ransomware
- Also known as eCh0raix. QNAPCrypt, also known as eCh0raix, is a ransomware strain targeting network-attached storage (NAS) devices, particularly those from QNAP.
- QNodeService backdoorcredential-stealer
- According to Trend Micro, this is a Node.js based malware, that can download/upload/execute files, steal credentials from Chrome/Firefox…
- QP ransomware
- QP is a ransomware known for encrypting files on infected systems and demanding a ransom payment for decryption keys.
- QRat ratkeyloggerscreen-capture
- Also known as Quaverse RAT. QRat, also known as Quaverse RAT, was introduced in May 2015 as undetectable (because of multiple layers of obfuscation).
- QSnatch credential-stealer
- The malware infects QNAP NAS devices, is persisting via various mechanisms and resists cleaning by preventing firmware updates and…
- QUADAGENT backdoor
- QUADAGENT is a PowerShell backdoor used by OilRig.
- QUARTERRIG loaderdownloaderdropper
- Also known as MUSKYBEAT, STATICNOISE. A stager used by APT29 to download and run CobaltStrike.
- QUICKCAFE downloaderexploit-kit
- QUICKCAFE is an encrypted JavaScript downloader for QUICKRIDE.POWER that exploits the ActiveX M2Soft vulnerabilities.
- QUICKMUTE downloaderloader
- QuickMute is a malware developed using the C/C++ programming language.
- QUIETBOARD
- QUIETCANARY backdoor
- Also known as Tunnus, Kapushka. QUIETCANARY is a backdoor tool written in .NET that has been used since at least 2022 to gather and exfiltrate data from victim networks.
- QUIETEXIT backdoor
- QUIETEXIT is a novel backdoor, based on the open-source Dropbear SSH client-server software, that has been used by APT29 since at least…
- Qaccel
- Qadars trojancredential-stealer
- Qadars is a banking trojan primarily targeting financial institutions.
- QakBot credential-stealertrojanloader
- Also known as Pinkslipbot, QuackBot, QBot. QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007.
- Qarallax rat
- Also known as qrat. Travelers applying for a US Visa in Switzerland were recently targeted by cyber-criminals linked to a malware called QRAT.
- Qarallax RAT rat
- According to SpiderLabs, in May 2015 the "company" Quaverse offered a RAT known as Quaverse RAT or QRAT.
- Qealler credential-stealerspyware
- Also known as Pyrogenic Infostealer. Qealler, also known as Pyrogenic Infostealer, is a malware family that focuses on exfiltrating sensitive information such as credentials…
- Qilin ransomware
- Also known as Agenda. Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022.
- Qinynore ransomware
- Qinynore is a type of ransomware that encrypts data on victim machines and demands a ransom for decryption.
- Qlocker ransomware
- Qlocker is a ransomware that encrypts files and demands a ransom in exchange for decryption keys.
- QtBot botnetrat
- Also known as qtproject. QtBot is a remote access tool (RAT) often used in cyber espionage campaigns targeting various industries.
- QuakeWay ransomware
- QuakeWay is a type of ransomware known for encrypting files on victim systems and demanding a ransom payment in cryptocurrency to restore…
- QuanPinLoader loader
- According to ESET Research, this is a loader that has the Mandarin Chinese symbol (yang in the Pinyin transliteration) as an icon in the…
- QuantLoader loaderdownloader
- QuantLoader is a malware primarily used to load and execute additional malicious payloads onto infected systems.
- QuantumLocker ransomware
- Also known as Quantum, Mount Locker, DagonLocker. QuantumLocker, also known as Quantum, Mount Locker, and DagonLocker, is a ransomware family that encrypts files on infected systems to…
- Quasar RAT ratkeyloggerscreen-capture
- Also known as CinaRAT, QuasarRAT, Yggdrasil. Quasar RAT is a malware family written in .NET which is used by a variety of attackers.
- QuasarRAT rat
- Also known as xRAT. QuasarRAT is an open-source, remote access tool that has been publicly available on GitHub since at least 2014.
- Quaverse ratkeyloggercredential-stealer
- Also known as QRAT. Quaverse RAT or QRAT is a fairly new Remote Access Tool (RAT) introduced in May 2015.
- Quick Assist rat
- Quick Assist is a remote assistance tool primarily for Microsoft Windows, although a macOS version also exists.
- QuickHeal
- QuickHeal is a potential name collision and does not refer to a known specific malicious software in the current cybersecurity landscape…
- QuietSieve credential-stealerspyware
- QuietSieve is an information stealer that has been used by Gamaredon Group since at least 2021.
- QuirkyLoader loader
- According to X-Force, this is a loader module written in .NET languages for which ahead-of-time (AOT) compilation is used.
- QuiteRAT rat
- Also known as Acres. QuiteRAT is a simple remote access trojan written with the help of Qt libraries.
- Qulab credential-stealerspyware
- Qulab is an AutoIT Malware focusing on stealing & clipping content from victim's machines.
- QvoidStealer credential-stealer
- Also known as Qvoid-Token-Grabber. QvoidStealer, also known as Qvoid-Token-Grabber, is a type of credential-stealing malware that targets sensitive information like…
- Qwerty Ransomware ransomware
- A new ransomware has been discovered that utilizes the legitimate GnuPG, or GPG, encryption program to encrypt a victim's files.
- Qweuirtksd ransomware
- Qweuirtksd is a type of ransomware that encrypts files on infected systems, demanding payment in exchange for decryption.
- Qyick Ransomware ransomware
- Qyick Ransomware is a type of ransomware that threatens to encrypt a user's data unless a ransom is paid.
- R ransomware
- Also known as NM3. R is a sophisticated ransomware targeting critical industries such as financial services and healthcare.
- R3store ransomware
- R3store is a sophisticated ransomware family known for encrypting victims' files and demanding ransom payments in cryptocurrency.
- R980 ransomware
- R980 is a ransomware strain known for encrypting victim files and demanding a ransom payment.
- RAA encryptor ransomware
- Also known as RAA, RAA SEP. RAA encryptor is a ransomware family written entirely in JavaScript, distributed primarily through email attachments.
- RAILSETTER loadertrojan
- According to Trend Micro, RAILSETTER is a persistence installer component designed to work with RAILLOAD.
- RAPIDPULSE webshell
- RAPIDPULSE is a web shell that exists as a modification to a legitimate Pulse Secure file that has been used by APT5 since at least 2021.
- RARSTONE rat
- RARSTONE is malware used by the Naikon group that has some characteristics similar to PlugX.
- RASTAKHIZ ransomware
- Hidden Tear variant discovered in October 2016.
- RATANKBA rat
- Also known as QUICKRIDE. RATANKBA is a remote controller tool used by Lazarus Group.
- RATAttack rat
- RATAttack is a remote access trojan (RAT) that uses the Telegram protocol to support encrypted communication between the victim's machine…
- RATel rat
- RATel is a remote access tool (RAT) utilized in cyber espionage campaigns.
- RAWDOOR backdoorrat
- RAWDOOR is a backdoor malware primarily used in cyber-espionage operations.
- RC2FM backdoorspyware
- A family identified by ESET Research in the InvisiMole campaign.
- RCS ratspywarescreen-capture
- Also known as Crisis, Remote Control System. RCS, also known as Crisis or Remote Control System, is a sophisticated surveillance malware developed by Hacking Team.
- RCSAndroid spywaretrojan
- RCSAndroid is a sophisticated Android malware designed for surveillance and espionage.
- RCSession backdoorrat
- RCSession is a backdoor written in C++ that has been in use since at least 2018 by Mustang Panda and by Threat Group-3390 (Type II…