Malware Families page 4 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Attor spywarebackdoor
Attor is a Windows-based espionage platform that has been seen in use since 2013.
AuKill ransomwarebackdoor
Also known as SophosKill. According to Sophos, the AuKill tool abuses an outdated version of the driver used by version 16.32 of the Microsoft utility, Process…
AuTo Stealer credential-stealerspyware
AuTo Stealer is malware written in C++ has been used by SideCopy since at least December 2021 to target government agencies and personnel…
AuditCred trojan
Also known as Roptimizer. AuditCred is a malicious DLL that has been used by Lazarus Group during their 2018 attacks.
August Stealer credential-stealer
August Stealer is a malware known for exfiltrating information from infected machines.
Aura Stealer credential-stealerloader
Also known as AURASTEAL. In July 2025, threat actor AuraCorp began advertising Aura Stealer as a Malware-as-a-Service (MaaS) program with multiple subscription…
Auriga rootkit
Also known as Riodrv. Auriga, also known as Riodrv, is a malware family primarily used for establishing persistent access and control on infected machines.
Aurora Ransomware ransomware
Also known as Zorro Ransomware. Typical ransom software, Aurora virus plays the role of blackmailing PC operators.
Aurora Stealer credential-stealerdownloaderloader
First advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in April 2022, Aurora Stealer is a Golang-based…
Australian-AES ransomware
The Australian-AES ransomware is designed to encrypt files on a victim's system, demanding a ransom for the decryption key.
Auto-Color trojan
According to Unit 42, Auto-Color was discovered in November 2024 named based on the file name of the initial payload.
AutoCAD Downloader downloader
Also known as Acad.Bursted, Duxfas. Small downloader composed as a Fast-AutoLoad LISP (FAS) module for AutoCAD.
AutoEncryptor ransomware
AutoEncryptor is a type of ransomware that encrypts files on an infected system and demands a ransom payment for decryption.
AutoIt backdoor backdoor
AutoIt backdoor is malware that has been used by the actors responsible for the MONSOON campaign.
AutoLocky ransomware
AutoLocky is a type of ransomware that encrypts the victim's files and demands a ransom for the decryption key.
AutoWannaCryV2 ransomwareworm
AutoWannaCryV2 is a variant of ransomware that encrypts files on infected systems demanding ransom.
Auuahk-Ouuohk ransomware
Auuahk-Ouuohk is a ransomware known for encrypting files on targeted systems and demanding a ransom for their decryption.
AvD Crypto Stealer trojancredential-stealer
Cyble Research discovered this .Net written malware dubbed "AvD Crypto Stealer".
Avaddon ransomware
Avaddon is ransomware written in C++ that has been offered as Ransomware-as-a-Service (RaaS) since at least June 2020.
AvastDisabler trojan
AvastDisabler is a trojan designed to disable or circumvent Avast antivirus software, leaving systems vulnerable to further malicious…
AvastVirusinfo Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Ave Maria credential-stealerspyware
Information stealer which uses AutoIT for wrapping.
Avenger downloader
Avenger is a downloader that has been used by BRONZE BUTLER since at least 2019.
Aveo trojan
Aveo is a type of Trojan malware known to be used in targeted attacks.
Avos ransomware
AvosLocker is a ransomware family that encrypts files on infected systems and demands a ransom for decryption.
AvosLocker ransomware
Also known as Avos. AvosLocker is ransomware written in C++ that has been offered via the Ransomware-as-a-Service (RaaS) model.
Avzhan rat
Avzhan is a remote access trojan (RAT) that has been used to infiltrate networks by providing attackers with backdoor capabilities.
Aw3s0m3Sc0t7 ransomware
Aw3s0m3Sc0t7 is a ransomware family known for encrypting files on infected systems and demanding payment for the decryption key.
AxBanker trojan
According to EnigmaSoft, AxBanker is a banking Trojan targeting Android devices specifically.
AxCrypter ransomware
AxCrypter is a type of ransomware known for encrypting files on victim machines and demanding a ransom for decryption.
Ayegent rat
Ayegent is a remote access tool (RAT) primarily used for cyber espionage.
Aytoke keylogger
Aytoke is a keylogger malware designed to record user keystrokes to steal sensitive information.
Azorult trojancredential-stealer
Also known as PuffStealer, Rultazo. Azorult is a commercial Trojan that is used to steal information from compromised hosts.
Azov Wiper wiper
According to Checkpoint, this malware is a wiper instead of ransomware as self-announced.
Aztroteam
B0 ransomware
According to Porthas, this is a ransomware written in Golang, using a time-based kill switch to limit its execution.
B1txor20 backdoor
B1txor20 is a malware that was discovered by 360 Netlab along others exploiting Log4J.
B2DR Ransomware ransomware
uses the [email protected] amd a ransom note named ScrewYou.txt
BABYMETAL rat
BABYMETAL is a command line network tunnel utility based on the TinyMet Meterpreter tool, primarily used to execute Meterpreter reverse…
BACKBEND downloader
FireEye describes BACKBEND as a secondary downloader used as a backup mechanism in the case the primary backdoor is removed.
BACKORDER downloader
According to EclecticIQ, this is a downloader written in Go, able to exclude paths from Windows Defender in order to execute fetched…
BACKSPACE backdoor
Also known as Lecna, ZRLnk. BACKSPACE is a backdoor used by APT30 that dates back to at least 2005.
BADAUDIO downloader
According to Google, BADAUDIO is a custom first-stage downloader written in C++ that downloads, decrypts, and executes an AES-encrypted…
BADBOX trojanspyware
According to BitSight, BADBOX is a large-scale cybercriminal operation selling off-brand Android TV boxes, smartphones, and other Android…
BADCALL trojan
BADCALL is a Trojan malware variant used by the group Lazarus Group.
BADCALL (Android) rat
remote access tool (RAT) payload on Android devices
BADCALL (ELF) trojan
BADCALL is a Trojan malware variant used by the group Lazarus Group.
BADCALL (Windows) backdoorrat
BADCALL is a Windows malware family known to function as a remote access tool (RAT) and backdoor.
BADFLICK backdoor
BADFLICK is a backdoor used by Leviathan in spearphishing campaigns first reported in 2018 that targeted the U.S.
BADHATCH backdoor
BADHATCH is a backdoor that has been utilized by FIN8 since at least 2019.
BADNEWS backdoorrat
BADNEWS is malware that has been used by the actors responsible for the Patchwork campaign.
BANSHEE rat
BANSHEE is a remote access tool primarily used in cyber espionage campaigns targeting the defense and government sectors.
BASICSTAR backdoorrat
BASICSTAR is a malware family primarily used for cyber-espionage activities.
BASS-FES ransomware
BASS-FES is a ransomware family that encrypts files and demands a ransom for decryption keys.
BATLOADER downloaderloader
According to PCrisk, BATLOADER is part of the infection chain where it is used to perform the initial compromise.
BB ransomware
BB is a ransomware family that encrypts files on the victim's system and demands a ransom for decryption.
BBK downloader
BBK is a downloader that has been used by BRONZE BUTLER since at least 2019.
BBS RAT rat
BBS RAT is a remote access trojan used primarily for espionage activities.
BBSRAT rat
BBSRAT is malware with remote access tool functionality that has been used in targeted compromises.
BBtok trojan
360 Security Center describes BBtok as a banking trojan targeting Mexico.
BCMPUPnP_Hunter botnetddos
BCMPUPnP_Hunter is a botnet malware exploiting vulnerabilities in UPnP implementations to enlist devices for large-scale DDoS attacks.
BD Y3K RAT rat
Also known as Back Door Y3K RAT, Y3k. BD Y3K RAT, also known as Back Door Y3K RAT or simply Y3k, is a remote access trojan used for cyber-espionage.
BDarkRAT rat
According to Threatray, BDarkRAT is a .NET RAT first discovered in 2019 that Bitter group continues to use until at least 2025.
BEARDSHELL backdoortrojan
According to CERT-UA, this is a malware developed using the C++ programming language.
BEATDROP downloader
According to Mandiant, BEATDROP is a downloader written in C that uses Atlassian's project management service Trello for C&C.
BELLHOP backdoordropper
• BELLHOP is a JavaScript backdoor interpreted using the native Windows Scripting Host(WSH).
BFG Agonizer wiper
BFG Agonizer is a wiper related to the open-source project CRYLINE-v.5.0.
BH_A006 loader
According to Volexity, a loader observed to be used with multiple malware families, among them LIGHTSPY.
BHunt credential-stealertrojan
BHunt collects the crypto wallets of its victims.
BIOPASS ratscreen-capture
BIOPASS RAT is a malware family which targets online gambling companies in China by leveraging a watering hole attack.
BISCUIT backdoor
Also known as zxdosml. BISCUIT is a backdoor that has been used by APT1 since as early as 2007.
BISTROMATH rat
BISTROMATH is a remote access tool (RAT) employed in cyber-espionage campaigns, primarily targeting government and defense sectors.
BITSAdmin downloader
BITSAdmin is a command line tool used to create and manage BITS Jobs.
BITSloth backdoorransomware
BITSloth is a backdoor and ransomware family observed targeting financial services, government sectors, and technology industries, known…
BI_D Ransomware ransomware
Small and relatively simple ransomware for Windows.
BKA Trojaner ransomwaretrojan
Also known as bwin3_bka. BKA Trojaner is a screenlocker ransomware that was active in 2011, displaying a police-themed message in German language.
BKRansomware ransomware
BKRansomware is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption.
BLACKCOFFEE webshellrat
Also known as PNGRAT, ZoxPNG, gresim. BLACKCOFFEE is malware that has been used by several Chinese groups since at least 2013.
BLINDINGCAN rat
Also known as AIRDRY, ZetaNile. BLINDINGCAN is a remote access Trojan that has been used by the North Korean government since at least early 2020 in cyber operations…
BLINDTOAD loader
BLINDTOAD is 64-bit Service DLL that loads an encrypted file from disk and executes it in memory.
BLUEHAZE loader
Mandiant associates this with UNC4191, this malware is a launcher for NCAT to establish a reverse tunnel.
BLUELIGHT rat
BLUELIGHT is a remote access Trojan used by APT37 that was first observed in early 2021.
BLUETHER trojan
Also known as CAPGELD. BLUETHER, also known as CAPGELD, is a sophisticated trojan primarily used in cyber-espionage activities.
BMANAGER backdoordownloader
BMANAGER is a sophisticated backdoor trojan primarily targeting financial and government institutions.
BOATLAUNCH loader
FIN7 uses this malware as helper module during intrusion operations.
BOK ransomware
BOK is a ransomware family known for encrypting files and demanding a ransom from its victims.
BOLDMOVE backdoor
BOLDMOVE is a type of backdoor malware written in C linked to People’s Republic of China operations from 2022 through 2023.
BOLDMOVE (ELF) backdoor
According to Mandiant, this malware family is attributed to potential chinese background and directly related to observed exploitation of…
BOLDMOVE (Windows) backdoor
According to Mandiant, this malware family is attributed to potential chinese background and its Linux variant is related to exploitation…
BONDUPDATER backdoor
Also known as Glimpse, Poison Frog. BONDUPDATER is a PowerShell backdoor used by OilRig.
BOOKWORM trojan
BOOKWORM is a modular trojan known to be leveraged by Mustang Panda and was first observed utilized in 2015.
BOOSTWRITE loader
BOOSTWRITE is a loader crafted to be launched via abuse of the DLL search order of applications used by FIN7.
BOOTRASH rootkit
BOOTRASH is a Bootkit that targets Windows operating systems.
BOOTWRECK wiper
Also known as MBRkiller. BOOTWRECK, also known as MBRkiller, is a master boot record wiper malware that can render computers unbootable by overwriting the boot…
BOULDSPY spywarerat
BOULDSPY is an Android malware, detected in early 2023, with surveillance and remote-control capabilities.
BPFDoor backdoor
Also known as JustForFun, Backdoor.Linux.BPFDOOR, Backdoor.Solaris.BPFDOOR.ZAJE. BPFDoor is a Linux based passive long-term backdoor used by China-based threat actors.
BQTlock (ELF) ransomware
BQTlock is a ransomware strain targeting Linux systems, particularly affecting sectors like financial services and healthcare.
BQTlock (Windows) ransomware
BQTlock is a ransomware family targeting systems running Windows.
BRAIN virus
BRAIN is considered to be the first computer virus created for the PC.
BRATA rat
Also known as AmexTroll, Copybara. BRATA (Brazilian Remote Access Tool, Android), is an evolving Android malware strain, detected in late 2018 and again in late 2021.