Malware Families page 40 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

RCtrl rat
RCtrl is a remote access tool (RAT) used for unauthorized access and control over infected systems.
RDAT backdoor
Also known as GREYSTUFF. RDAT is a backdoor used by the suspected Iranian threat group OilRig.
RDFSNIFFER spywaretrojan
RDFSNIFFER is a module loaded by BOOSTWRITE which allows an attacker to monitor and tamper with legitimate connections made via an…
REDPEPPER rat
Also known as Adupib. REDPEPPER, also known as Adupib, is a remote access tool (RAT) often associated with state-sponsored actors targeting the government and…
REDSALT backdoorrat
Also known as Dipsind. REDSALT, also known as Dipsind, is a backdoor used primarily for cyber espionage activities.
REDSHAWL trojan
REDSHAWL is a session hijacking utility that starts a new process as another user currently logged on to the same system via command-line.
REPTILE rootkitbackdoor
REPTILE is an open-source Linux rootkit with multiple components that provides backdoor access and functionality.
REvil ransomware
Also known as Sodin, Sodinokibi. REvil is a ransomware family that has been linked to the GOLD SOUTHFIELD group and operated as ransomware-as-a-service (RaaS) since at…
REvil (ELF) ransomware
Also known as REvix. ELF version of win.revil targeting VMware ESXi hypervisors.
RGDoor backdoor
RGDoor is a malicious Internet Information Services (IIS) backdoor developed in the C++ language.
RHOMBUS rat
RHOMBUS is a remote access trojan (RAT) that has been observed targeting financial services, government, and technology sectors primarily…
RHttpCtrl rat
RHttpCtrl is a malware that functions as a remote access tool (RAT) commonly used in cyber espionage campaigns.
RIFLESPINE backdoor
RIFLESPINE is a cross-platform backdoor that leverages Google Drive for file transfer and command execution.
RIP (Phoenix) Ransomware ransomware
Also known as RIP, Phoenix. It’s directed to English speaking users, therefore is able to infect worldwide.
RIPTIDE backdoor
RIPTIDE is a proxy-aware backdoor used by APT12 to conduct cyber espionage.
RM3 trojancredential-stealer
RM3 is a banking trojan developed from the codebase of Gozi/ISFB.
RMOT downloaderdropper
According to Trellix, this is a first-stage, powershell-based malware dropped via Excel/VBS.
RMS rat
Also known as Gussdoor, Remote Manipulator System, RuRAT. CyberInt states that Remote Manipulator System (RMS) is a legitimate tool developed by Russian organization TektonIT and has been observed…
RN Stealer credential-stealer
RN Stealer is a malware family known for targeting credentials, with a focus on stealing sensitive information from victims, primarily in…
RNS ransomware
RNS is ransomware that encrypts files on infected systems, demanding a ransom payment for decryption.
ROADSWEEP ransomware
ROADSWEEP is a ransomware that was deployed against Albanian government networks during HomeLand Justice along with the CHIMNEYSWEEP…
ROADTools spyware
ROADTools is a framework for enumerating Azure Active Directory environments.
ROAMINGHOUSE dropper
ROAMINGHOUSE is a dropper malware used by MirrorFace to extract and execute embedded payloads including UPPERCUT components.
ROCKBOOT rootkit
ROCKBOOT is a Bootkit that has been used by an unidentified, suspected China-based group.
ROKRAT rat
Also known as DOGCALL. ROKRAT is a cloud-based remote access tool (RAT) used by APT37 to target victims in South Korea.
ROLLCOAST ransomware
Also known as Arcane, S4bb47h, Sabbath. ROLLCOAST is a ransomware program that encrypts files on logical drives attached to a system.
ROMCOM RAT rat
Also known as PEAPOD, SingleCamper, SnipBot. Unit 42 observed threat actor Tropical Scorpius using this RAT in operations where also Cuba ransomware was deployed.
RONINGLOADER loader
RONINGLOADER is a malware loader used primarily to deliver other malicious payloads.
RSA-NI ransomware
RSA-NI is a type of ransomware known for encrypting files on targeted systems and demanding a ransom payment for decryption keys.
RSA2048Pro ransomware
RSA2048Pro is a type of ransomware that encrypts files on the victim's device and demands a ransom payment for decryption.
RSAUtil ransomware
Also known as Vagger, DONTSLIP. RSAUtil is distributed by the developer hacking into remote desktop services and uploading a package of files.
RTM trojancredential-stealer
Also known as Redaman. RTM is custom malware written in Delphi. It is used by the group of the same name (RTM). Newer versions of the malware have been reported…
RTM trojancredential-stealer
Also known as Redaman. RTM Banker also known as Redaman was first blogged about in February 2017 by ESET.
RURansom wiper
RURansom shows characteristics of typical ransomware, but despite its name, TrendMicro's assumptions after analysis showed that this…
RWX RAT rat
RWX RAT is a remote access tool used by threat actors to gain unauthorized access to compromised systems.
Ra ransomware
Ra is a ransomware that encrypts files on victims' systems and demands a ransom payment for decryption keys.
RaRuCrypt ransomware
RaRuCrypt is a ransomware strain known for encrypting files on infected systems and demanding a ransom for decryption.
RaTRon rat
RaTRon is a Java-based remote access trojan (RAT) that provides attackers with unauthorized control over infected systems.
RabbitFox ransomware
RabbitFox is a ransomware that encrypts files and demands a ransom for decryption.
Rabion ransomware
Rabion is a ransomware-as-a-service (RaaS) variant that closely mimics the functionality and behavior of the Ranion ransomware.
Raccoon credential-stealerspyware
Also known as Mohazo, RaccoonStealer, Racealer. Raccoon Stealer is a malware reportedly sold for $75 a week or $200 a month.
Raccoon Stealer credential-stealer
Raccoon Stealer is an information stealer malware family active since at least 2019 as a malware-as-a-service offering sold in underground…
Racket Downloader downloader
Racket Downloader is an HTTP(S) downloader.
Rad rat
Rad is a remote access trojan (RAT) used for persistent access and data exfiltration activities.
RadRAT rat
RadRAT is a remote access trojan (RAT) that offers various capabilities for spying and control, making it a versatile tool for cyber…
Radamant ransomware
Radamant is a ransomware that encrypts users' files and demands a ransom for decryption.
Rafel RAT rat
Rafel RAT is a remote access trojan that provides attackers with unauthorized access and control over targeted systems.
Ragnar Locker ransomware
Also known as RagnarLocker. Ragnar Locker is a ransomware that has been in use since at least December 2019.
RagnarLocker (ELF) ransomware
RagnarLocker is a ransomware family known for encrypting files on systems and demanding a ransom for decryption keys.
RagnarLocker (Windows) ransomware
RagnarLocker is a sophisticated ransomware targeting large organizations across various industries, particularly in Europe and North…
Ragnarok ransomware
Ragnarok is is a ransomware that targetscorporate networks in Big Game Huntingtargeted attacks.
Ragnatela rat
Malwarebytes Lab identified a new variant of the BADNEWS RAT called Ragnatela.
Raindrop loader
Raindrop is a loader used by APT29 that was discovered on some victim machines during investigations related to the SolarWinds Compromise.
RainyDay backdoor
RainyDay is a backdoor tool that has been used by Naikon since at least 2020.
Rakhni ransomwaretrojandropper
Rakhni is a multi-functional malware primarily known for its ransomware capabilities.
Rakos botnetcryptominer
Rakos is a malware family that primarily targets IoT devices to form a botnet, which can be used for various malicious activities…
RambleOn rat
RambleOn is a remote access trojan (RAT) that provides attackers with a persistent presence in targets' systems.
Rambo trojanrat
Also known as brebsd. Rambo is a remote access Trojan (RAT) known for its espionage activities targeting government and defense sectors.
Ramdo botnet
Ramdo is a botnet malware primarily involved in ad fraud by manipulating web traffic to generate illicit advertising revenue.
Ramnit trojancredential-stealer
Also known as Nimnul. According to Check Point, Ramnit is primarily a banking trojan, meaning that its purpose is to steal login credentials for online banking…
Ramp ransomware
Ramp is a known ransomware family targeting various industries.
Ramsay spywaretrojan
Ramsay is an information stealing malware framework designed to collect and exfiltrate sensitive documents, including from air-gapped…
Ramsey ransomware
Ramsey is a ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
Ramsomeer ransomware
Ramsomeer is a ransomware variant based on the DUMB ransomware.
RanRan ransomware
Also known as ZXZ. RanRan is a ransomware known for targeting government institutions, particularly in the Middle East.
RanRans ransomware
RanRans is a type of ransomware that encrypts files on infected systems, demanding a ransom payment for decryption keys.
Rana
Rana is a lesser-known malware with limited documentation available about its specific functionality, targeting, and delivery methods.
Ranbyus credential-stealertrojan
Ranbyus is a malware family known for targeting financial institutions.
Random30 ransomware
Random30 is a ransomware strain that encrypts victim files and demands a ransom payment for decryption.
RandomLocker ransomware
RandomLocker is a type of ransomware that encrypts files on a victim's computer and demands a ransom for the decryption key.
RandomQuery (Powershell) rattrojan
A set of powershell scripts, using services like Google Docs and Dropbox as C2.
RandomQuery (VBScript) spywaretrojan
According to SentinelLabs, this is a VisualBasic-based malware that gathers system and file information and exfiltrates the data using…
Ranion RaasRansomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Rannoh ransomware
Rannoh is a type of ransomware that encrypts files on the victim's machine and demands a ransom for decryption.
Rans0mLocked ransomware
Rans0mLocked is a ransomware variant known for encrypting victims' files and demanding a ransom for decryption.
Ranscam ransomwarewiper
Ranscam is a ransomware that deletes the victim's files instead of encrypting them while demanding a ransom.
Ransed ransomware
Ransed is a ransomware strain that encrypts files on infected systems, demanding a ransom payment for data decryption.
Ransoc ransomware
Ransoc is a type of ransomware that targets individuals, particularly those using media and entertainment platforms.
Ransom Prank ransomware
Ransom Prank is a ransomware strain known for encrypting files on infected systems, rendering them inaccessible until a ransom is paid.
Ransom102 ransomware
Ransom102 is a type of ransomware known for encrypting files on the victim's system and demanding a ransom for decryption keys.
Ransom32 ransomware
Ransomware no extension change, Javascript Ransomware
RansomAES ransomware
RansomAES is a type of ransomware known for encrypting user files and demanding a ransom for decryption.
RansomBlox ransomware
RansomBlox is a type of ransomware known for encrypting user files and demanding a ransom in cryptocurrency.
RansomCuck ransomware
RansomCuck is a ransomware variant known for encrypting files and demanding a ransom for decryption.
RansomEXX ransomwaretrojan
Also known as Ransom X, Defray777, Defray-777. We recently discovered a new file-encrypting Trojan built as an ELF executable and intended to encrypt data on machines controlled by…
RansomEXX (ELF) ransomware
Also known as Defray777. According to SentineOne, RansomEXX (aka Defray, Defray777), a multi-pronged extortion threat, has been observed in the wild since late 2020.
RansomExx2 ransomware
According to IBM Security X-Force, this is a new but functionally very similar version of RansomExx, fully rewritten in Rust and…
RansomHub ransomware
RansomHub is a ransomware-as-a-service (RaaS) offering with Windows, ESXi, Linux, and FreeBSD versions that has been in use since at least…
RansomLock ransomware
Also known as WinLock. RansomLock, also known as WinLock, is a form of ransomware known for locking the desktop of infected computers.
RansomMine ransomware
RansomMine is a type of ransomware that encrypts data and demands a ransom payment for decryption.
RansomPlus ransomware
Author of this ransomware is sergej. Ransom is 0.25 bitcoins for the return of files. Originated in English. Used worldwide. This…
RansomUserLocker ransomware
RansomUserLocker is a ransomware strain that encrypts files on infected systems, demanding a ransom payment for decryption keys.
RansomWarrior ransomware
RansomWarrior is a type of ransomware known for encrypting victims' files and demanding a ransom for decryption.
Ransomcartel ransomware
Ransomcartel is a ransomware family known for encrypting victim files and demanding ransom payments in cryptocurrency.
Ransomhouse ransomware
Ransomhouse is a ransomware group known for encrypting victim data and demanding a ransom for decryption keys.
Ransomnix ransomware
Ransomnix is a ransomware strain that encrypts the victim's files and demands a ransom for decryption keys.
Ranzy ransomware
Ranzy is a ransomware family that targets various industries to encrypt victim data and demands a ransom for decryption.
Rapid ransomware
Rapid is a ransomware that encrypts files on the victim's machine and demands a ransom for decryption.
Rapid 2.0 ransomware
Rapid 2.0 is a strain of ransomware notorious for swiftly encrypting files on infected systems.
Rapid 3.0 ransomware
Rapid 3.0 is a sophisticated ransomware strain targeting numerous industries.