Malware Families page 4 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Attor spywarebackdoor
- Attor is a Windows-based espionage platform that has been seen in use since 2013.
- AuKill ransomwarebackdoor
- Also known as SophosKill. According to Sophos, the AuKill tool abuses an outdated version of the driver used by version 16.32 of the Microsoft utility, Process…
- AuTo Stealer credential-stealerspyware
- AuTo Stealer is malware written in C++ has been used by SideCopy since at least December 2021 to target government agencies and personnel…
- AuditCred trojan
- Also known as Roptimizer. AuditCred is a malicious DLL that has been used by Lazarus Group during their 2018 attacks.
- August Stealer credential-stealer
- August Stealer is a malware known for exfiltrating information from infected machines.
- Aura Stealer credential-stealerloader
- Also known as AURASTEAL. In July 2025, threat actor AuraCorp began advertising Aura Stealer as a Malware-as-a-Service (MaaS) program with multiple subscription…
- Auriga rootkit
- Also known as Riodrv. Auriga, also known as Riodrv, is a malware family primarily used for establishing persistent access and control on infected machines.
- Aurora Ransomware ransomware
- Also known as Zorro Ransomware. Typical ransom software, Aurora virus plays the role of blackmailing PC operators.
- Aurora Stealer credential-stealerdownloaderloader
- First advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in April 2022, Aurora Stealer is a Golang-based…
- Australian-AES ransomware
- The Australian-AES ransomware is designed to encrypt files on a victim's system, demanding a ransom for the decryption key.
- Auto-Color trojan
- According to Unit 42, Auto-Color was discovered in November 2024 named based on the file name of the initial payload.
- AutoCAD Downloader downloader
- Also known as Acad.Bursted, Duxfas. Small downloader composed as a Fast-AutoLoad LISP (FAS) module for AutoCAD.
- AutoEncryptor ransomware
- AutoEncryptor is a type of ransomware that encrypts files on an infected system and demands a ransom payment for decryption.
- AutoIt backdoor backdoor
- AutoIt backdoor is malware that has been used by the actors responsible for the MONSOON campaign.
- AutoLocky ransomware
- AutoLocky is a type of ransomware that encrypts the victim's files and demands a ransom for the decryption key.
- AutoWannaCryV2 ransomwareworm
- AutoWannaCryV2 is a variant of ransomware that encrypts files on infected systems demanding ransom.
- Auuahk-Ouuohk ransomware
- Auuahk-Ouuohk is a ransomware known for encrypting files on targeted systems and demanding a ransom for their decryption.
- AvD Crypto Stealer trojancredential-stealer
- Cyble Research discovered this .Net written malware dubbed "AvD Crypto Stealer".
- Avaddon ransomware
- Avaddon is ransomware written in C++ that has been offered as Ransomware-as-a-Service (RaaS) since at least June 2020.
- AvastDisabler trojan
- AvastDisabler is a trojan designed to disable or circumvent Avast antivirus software, leaving systems vulnerable to further malicious…
- AvastVirusinfo Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Ave Maria credential-stealerspyware
- Information stealer which uses AutoIT for wrapping.
- Avenger downloader
- Avenger is a downloader that has been used by BRONZE BUTLER since at least 2019.
- Aveo trojan
- Aveo is a type of Trojan malware known to be used in targeted attacks.
- Avos ransomware
- AvosLocker is a ransomware family that encrypts files on infected systems and demands a ransom for decryption.
- AvosLocker ransomware
- Also known as Avos. AvosLocker is ransomware written in C++ that has been offered via the Ransomware-as-a-Service (RaaS) model.
- Avzhan rat
- Avzhan is a remote access trojan (RAT) that has been used to infiltrate networks by providing attackers with backdoor capabilities.
- Aw3s0m3Sc0t7 ransomware
- Aw3s0m3Sc0t7 is a ransomware family known for encrypting files on infected systems and demanding payment for the decryption key.
- AxBanker trojan
- According to EnigmaSoft, AxBanker is a banking Trojan targeting Android devices specifically.
- AxCrypter ransomware
- AxCrypter is a type of ransomware known for encrypting files on victim machines and demanding a ransom for decryption.
- Ayegent rat
- Ayegent is a remote access tool (RAT) primarily used for cyber espionage.
- Aytoke keylogger
- Aytoke is a keylogger malware designed to record user keystrokes to steal sensitive information.
- Azorult trojancredential-stealer
- Also known as PuffStealer, Rultazo. Azorult is a commercial Trojan that is used to steal information from compromised hosts.
- Azov Wiper wiper
- According to Checkpoint, this malware is a wiper instead of ransomware as self-announced.
- Aztroteam
- B0 ransomware
- According to Porthas, this is a ransomware written in Golang, using a time-based kill switch to limit its execution.
- B1txor20 backdoor
- B1txor20 is a malware that was discovered by 360 Netlab along others exploiting Log4J.
- B2DR Ransomware ransomware
- uses the [email protected] amd a ransom note named ScrewYou.txt
- BABYMETAL rat
- BABYMETAL is a command line network tunnel utility based on the TinyMet Meterpreter tool, primarily used to execute Meterpreter reverse…
- BACKBEND downloader
- FireEye describes BACKBEND as a secondary downloader used as a backup mechanism in the case the primary backdoor is removed.
- BACKORDER downloader
- According to EclecticIQ, this is a downloader written in Go, able to exclude paths from Windows Defender in order to execute fetched…
- BACKSPACE backdoor
- Also known as Lecna, ZRLnk. BACKSPACE is a backdoor used by APT30 that dates back to at least 2005.
- BADAUDIO downloader
- According to Google, BADAUDIO is a custom first-stage downloader written in C++ that downloads, decrypts, and executes an AES-encrypted…
- BADBOX trojanspyware
- According to BitSight, BADBOX is a large-scale cybercriminal operation selling off-brand Android TV boxes, smartphones, and other Android…
- BADCALL trojan
- BADCALL is a Trojan malware variant used by the group Lazarus Group.
- BADCALL (Android) rat
- remote access tool (RAT) payload on Android devices
- BADCALL (ELF) trojan
- BADCALL is a Trojan malware variant used by the group Lazarus Group.
- BADCALL (Windows) backdoorrat
- BADCALL is a Windows malware family known to function as a remote access tool (RAT) and backdoor.
- BADFLICK backdoor
- BADFLICK is a backdoor used by Leviathan in spearphishing campaigns first reported in 2018 that targeted the U.S.
- BADHATCH backdoor
- BADHATCH is a backdoor that has been utilized by FIN8 since at least 2019.
- BADNEWS backdoorrat
- BADNEWS is malware that has been used by the actors responsible for the Patchwork campaign.
- BANSHEE rat
- BANSHEE is a remote access tool primarily used in cyber espionage campaigns targeting the defense and government sectors.
- BASICSTAR backdoorrat
- BASICSTAR is a malware family primarily used for cyber-espionage activities.
- BASS-FES ransomware
- BASS-FES is a ransomware family that encrypts files and demands a ransom for decryption keys.
- BATLOADER downloaderloader
- According to PCrisk, BATLOADER is part of the infection chain where it is used to perform the initial compromise.
- BB ransomware
- BB is a ransomware family that encrypts files on the victim's system and demands a ransom for decryption.
- BBK downloader
- BBK is a downloader that has been used by BRONZE BUTLER since at least 2019.
- BBS RAT rat
- BBS RAT is a remote access trojan used primarily for espionage activities.
- BBSRAT rat
- BBSRAT is malware with remote access tool functionality that has been used in targeted compromises.
- BBtok trojan
- 360 Security Center describes BBtok as a banking trojan targeting Mexico.
- BCMPUPnP_Hunter botnetddos
- BCMPUPnP_Hunter is a botnet malware exploiting vulnerabilities in UPnP implementations to enlist devices for large-scale DDoS attacks.
- BD Y3K RAT rat
- Also known as Back Door Y3K RAT, Y3k. BD Y3K RAT, also known as Back Door Y3K RAT or simply Y3k, is a remote access trojan used for cyber-espionage.
- BDarkRAT rat
- According to Threatray, BDarkRAT is a .NET RAT first discovered in 2019 that Bitter group continues to use until at least 2025.
- BEARDSHELL backdoortrojan
- According to CERT-UA, this is a malware developed using the C++ programming language.
- BEATDROP downloader
- According to Mandiant, BEATDROP is a downloader written in C that uses Atlassian's project management service Trello for C&C.
- BELLHOP backdoordropper
- • BELLHOP is a JavaScript backdoor interpreted using the native Windows Scripting Host(WSH).
- BFG Agonizer wiper
- BFG Agonizer is a wiper related to the open-source project CRYLINE-v.5.0.
- BH_A006 loader
- According to Volexity, a loader observed to be used with multiple malware families, among them LIGHTSPY.
- BHunt credential-stealertrojan
- BHunt collects the crypto wallets of its victims.
- BIOPASS ratscreen-capture
- BIOPASS RAT is a malware family which targets online gambling companies in China by leveraging a watering hole attack.
- BISCUIT backdoor
- Also known as zxdosml. BISCUIT is a backdoor that has been used by APT1 since as early as 2007.
- BISTROMATH rat
- BISTROMATH is a remote access tool (RAT) employed in cyber-espionage campaigns, primarily targeting government and defense sectors.
- BITSAdmin downloader
- BITSAdmin is a command line tool used to create and manage BITS Jobs.
- BITSloth backdoorransomware
- BITSloth is a backdoor and ransomware family observed targeting financial services, government sectors, and technology industries, known…
- BI_D Ransomware ransomware
- Small and relatively simple ransomware for Windows.
- BKA Trojaner ransomwaretrojan
- Also known as bwin3_bka. BKA Trojaner is a screenlocker ransomware that was active in 2011, displaying a police-themed message in German language.
- BKRansomware ransomware
- BKRansomware is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption.
- BLACKCOFFEE webshellrat
- Also known as PNGRAT, ZoxPNG, gresim. BLACKCOFFEE is malware that has been used by several Chinese groups since at least 2013.
- BLINDINGCAN rat
- Also known as AIRDRY, ZetaNile. BLINDINGCAN is a remote access Trojan that has been used by the North Korean government since at least early 2020 in cyber operations…
- BLINDTOAD loader
- BLINDTOAD is 64-bit Service DLL that loads an encrypted file from disk and executes it in memory.
- BLUEHAZE loader
- Mandiant associates this with UNC4191, this malware is a launcher for NCAT to establish a reverse tunnel.
- BLUELIGHT rat
- BLUELIGHT is a remote access Trojan used by APT37 that was first observed in early 2021.
- BLUETHER trojan
- Also known as CAPGELD. BLUETHER, also known as CAPGELD, is a sophisticated trojan primarily used in cyber-espionage activities.
- BMANAGER backdoordownloader
- BMANAGER is a sophisticated backdoor trojan primarily targeting financial and government institutions.
- BOATLAUNCH loader
- FIN7 uses this malware as helper module during intrusion operations.
- BOK ransomware
- BOK is a ransomware family known for encrypting files and demanding a ransom from its victims.
- BOLDMOVE backdoor
- BOLDMOVE is a type of backdoor malware written in C linked to People’s Republic of China operations from 2022 through 2023.
- BOLDMOVE (ELF) backdoor
- According to Mandiant, this malware family is attributed to potential chinese background and directly related to observed exploitation of…
- BOLDMOVE (Windows) backdoor
- According to Mandiant, this malware family is attributed to potential chinese background and its Linux variant is related to exploitation…
- BONDUPDATER backdoor
- Also known as Glimpse, Poison Frog. BONDUPDATER is a PowerShell backdoor used by OilRig.
- BOOKWORM trojan
- BOOKWORM is a modular trojan known to be leveraged by Mustang Panda and was first observed utilized in 2015.
- BOOSTWRITE loader
- BOOSTWRITE is a loader crafted to be launched via abuse of the DLL search order of applications used by FIN7.
- BOOTRASH rootkit
- BOOTRASH is a Bootkit that targets Windows operating systems.
- BOOTWRECK wiper
- Also known as MBRkiller. BOOTWRECK, also known as MBRkiller, is a master boot record wiper malware that can render computers unbootable by overwriting the boot…
- BOULDSPY spywarerat
- BOULDSPY is an Android malware, detected in early 2023, with surveillance and remote-control capabilities.
- BPFDoor backdoor
- Also known as JustForFun, Backdoor.Linux.BPFDOOR, Backdoor.Solaris.BPFDOOR.ZAJE. BPFDoor is a Linux based passive long-term backdoor used by China-based threat actors.
- BQTlock (ELF) ransomware
- BQTlock is a ransomware strain targeting Linux systems, particularly affecting sectors like financial services and healthcare.
- BQTlock (Windows) ransomware
- BQTlock is a ransomware family targeting systems running Windows.
- BRAIN virus
- BRAIN is considered to be the first computer virus created for the PC.
- BRATA rat
- Also known as AmexTroll, Copybara. BRATA (Brazilian Remote Access Tool, Android), is an evolving Android malware strain, detected in late 2018 and again in late 2021.