Malware Families page 40 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- RCtrl rat
- RCtrl is a remote access tool (RAT) used for unauthorized access and control over infected systems.
- RDAT backdoor
- Also known as GREYSTUFF. RDAT is a backdoor used by the suspected Iranian threat group OilRig.
- RDFSNIFFER spywaretrojan
- RDFSNIFFER is a module loaded by BOOSTWRITE which allows an attacker to monitor and tamper with legitimate connections made via an…
- REDPEPPER rat
- Also known as Adupib. REDPEPPER, also known as Adupib, is a remote access tool (RAT) often associated with state-sponsored actors targeting the government and…
- REDSALT backdoorrat
- Also known as Dipsind. REDSALT, also known as Dipsind, is a backdoor used primarily for cyber espionage activities.
- REDSHAWL trojan
- REDSHAWL is a session hijacking utility that starts a new process as another user currently logged on to the same system via command-line.
- REPTILE rootkitbackdoor
- REPTILE is an open-source Linux rootkit with multiple components that provides backdoor access and functionality.
- REvil ransomware
- Also known as Sodin, Sodinokibi. REvil is a ransomware family that has been linked to the GOLD SOUTHFIELD group and operated as ransomware-as-a-service (RaaS) since at…
- REvil (ELF) ransomware
- Also known as REvix. ELF version of win.revil targeting VMware ESXi hypervisors.
- RGDoor backdoor
- RGDoor is a malicious Internet Information Services (IIS) backdoor developed in the C++ language.
- RHOMBUS rat
- RHOMBUS is a remote access trojan (RAT) that has been observed targeting financial services, government, and technology sectors primarily…
- RHttpCtrl rat
- RHttpCtrl is a malware that functions as a remote access tool (RAT) commonly used in cyber espionage campaigns.
- RIFLESPINE backdoor
- RIFLESPINE is a cross-platform backdoor that leverages Google Drive for file transfer and command execution.
- RIP (Phoenix) Ransomware ransomware
- Also known as RIP, Phoenix. It’s directed to English speaking users, therefore is able to infect worldwide.
- RIPTIDE backdoor
- RIPTIDE is a proxy-aware backdoor used by APT12 to conduct cyber espionage.
- RM3 trojancredential-stealer
- RM3 is a banking trojan developed from the codebase of Gozi/ISFB.
- RMOT downloaderdropper
- According to Trellix, this is a first-stage, powershell-based malware dropped via Excel/VBS.
- RMS rat
- Also known as Gussdoor, Remote Manipulator System, RuRAT. CyberInt states that Remote Manipulator System (RMS) is a legitimate tool developed by Russian organization TektonIT and has been observed…
- RN Stealer credential-stealer
- RN Stealer is a malware family known for targeting credentials, with a focus on stealing sensitive information from victims, primarily in…
- RNS ransomware
- RNS is ransomware that encrypts files on infected systems, demanding a ransom payment for decryption.
- ROADSWEEP ransomware
- ROADSWEEP is a ransomware that was deployed against Albanian government networks during HomeLand Justice along with the CHIMNEYSWEEP…
- ROADTools spyware
- ROADTools is a framework for enumerating Azure Active Directory environments.
- ROAMINGHOUSE dropper
- ROAMINGHOUSE is a dropper malware used by MirrorFace to extract and execute embedded payloads including UPPERCUT components.
- ROCKBOOT rootkit
- ROCKBOOT is a Bootkit that has been used by an unidentified, suspected China-based group.
- ROKRAT rat
- Also known as DOGCALL. ROKRAT is a cloud-based remote access tool (RAT) used by APT37 to target victims in South Korea.
- ROLLCOAST ransomware
- Also known as Arcane, S4bb47h, Sabbath. ROLLCOAST is a ransomware program that encrypts files on logical drives attached to a system.
- ROMCOM RAT rat
- Also known as PEAPOD, SingleCamper, SnipBot. Unit 42 observed threat actor Tropical Scorpius using this RAT in operations where also Cuba ransomware was deployed.
- RONINGLOADER loader
- RONINGLOADER is a malware loader used primarily to deliver other malicious payloads.
- RSA-NI ransomware
- RSA-NI is a type of ransomware known for encrypting files on targeted systems and demanding a ransom payment for decryption keys.
- RSA2048Pro ransomware
- RSA2048Pro is a type of ransomware that encrypts files on the victim's device and demands a ransom payment for decryption.
- RSAUtil ransomware
- Also known as Vagger, DONTSLIP. RSAUtil is distributed by the developer hacking into remote desktop services and uploading a package of files.
- RTM trojancredential-stealer
- Also known as Redaman. RTM is custom malware written in Delphi. It is used by the group of the same name (RTM). Newer versions of the malware have been reported…
- RTM trojancredential-stealer
- Also known as Redaman. RTM Banker also known as Redaman was first blogged about in February 2017 by ESET.
- RURansom wiper
- RURansom shows characteristics of typical ransomware, but despite its name, TrendMicro's assumptions after analysis showed that this…
- RWX RAT rat
- RWX RAT is a remote access tool used by threat actors to gain unauthorized access to compromised systems.
- Ra ransomware
- Ra is a ransomware that encrypts files on victims' systems and demands a ransom payment for decryption keys.
- RaRuCrypt ransomware
- RaRuCrypt is a ransomware strain known for encrypting files on infected systems and demanding a ransom for decryption.
- RaTRon rat
- RaTRon is a Java-based remote access trojan (RAT) that provides attackers with unauthorized control over infected systems.
- RabbitFox ransomware
- RabbitFox is a ransomware that encrypts files and demands a ransom for decryption.
- Rabion ransomware
- Rabion is a ransomware-as-a-service (RaaS) variant that closely mimics the functionality and behavior of the Ranion ransomware.
- Raccoon credential-stealerspyware
- Also known as Mohazo, RaccoonStealer, Racealer. Raccoon Stealer is a malware reportedly sold for $75 a week or $200 a month.
- Raccoon Stealer credential-stealer
- Raccoon Stealer is an information stealer malware family active since at least 2019 as a malware-as-a-service offering sold in underground…
- Racket Downloader downloader
- Racket Downloader is an HTTP(S) downloader.
- Rad rat
- Rad is a remote access trojan (RAT) used for persistent access and data exfiltration activities.
- RadRAT rat
- RadRAT is a remote access trojan (RAT) that offers various capabilities for spying and control, making it a versatile tool for cyber…
- Radamant ransomware
- Radamant is a ransomware that encrypts users' files and demands a ransom for decryption.
- Rafel RAT rat
- Rafel RAT is a remote access trojan that provides attackers with unauthorized access and control over targeted systems.
- Ragnar Locker ransomware
- Also known as RagnarLocker. Ragnar Locker is a ransomware that has been in use since at least December 2019.
- RagnarLocker (ELF) ransomware
- RagnarLocker is a ransomware family known for encrypting files on systems and demanding a ransom for decryption keys.
- RagnarLocker (Windows) ransomware
- RagnarLocker is a sophisticated ransomware targeting large organizations across various industries, particularly in Europe and North…
- Ragnarok ransomware
- Ragnarok is is a ransomware that targetscorporate networks in Big Game Huntingtargeted attacks.
- Ragnatela rat
- Malwarebytes Lab identified a new variant of the BADNEWS RAT called Ragnatela.
- Raindrop loader
- Raindrop is a loader used by APT29 that was discovered on some victim machines during investigations related to the SolarWinds Compromise.
- RainyDay backdoor
- RainyDay is a backdoor tool that has been used by Naikon since at least 2020.
- Rakhni ransomwaretrojandropper
- Rakhni is a multi-functional malware primarily known for its ransomware capabilities.
- Rakos botnetcryptominer
- Rakos is a malware family that primarily targets IoT devices to form a botnet, which can be used for various malicious activities…
- RambleOn rat
- RambleOn is a remote access trojan (RAT) that provides attackers with a persistent presence in targets' systems.
- Rambo trojanrat
- Also known as brebsd. Rambo is a remote access Trojan (RAT) known for its espionage activities targeting government and defense sectors.
- Ramdo botnet
- Ramdo is a botnet malware primarily involved in ad fraud by manipulating web traffic to generate illicit advertising revenue.
- Ramnit trojancredential-stealer
- Also known as Nimnul. According to Check Point, Ramnit is primarily a banking trojan, meaning that its purpose is to steal login credentials for online banking…
- Ramp ransomware
- Ramp is a known ransomware family targeting various industries.
- Ramsay spywaretrojan
- Ramsay is an information stealing malware framework designed to collect and exfiltrate sensitive documents, including from air-gapped…
- Ramsey ransomware
- Ramsey is a ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
- Ramsomeer ransomware
- Ramsomeer is a ransomware variant based on the DUMB ransomware.
- RanRan ransomware
- Also known as ZXZ. RanRan is a ransomware known for targeting government institutions, particularly in the Middle East.
- RanRans ransomware
- RanRans is a type of ransomware that encrypts files on infected systems, demanding a ransom payment for decryption keys.
- Rana
- Rana is a lesser-known malware with limited documentation available about its specific functionality, targeting, and delivery methods.
- Ranbyus credential-stealertrojan
- Ranbyus is a malware family known for targeting financial institutions.
- Random30 ransomware
- Random30 is a ransomware strain that encrypts victim files and demands a ransom payment for decryption.
- RandomLocker ransomware
- RandomLocker is a type of ransomware that encrypts files on a victim's computer and demands a ransom for the decryption key.
- RandomQuery (Powershell) rattrojan
- A set of powershell scripts, using services like Google Docs and Dropbox as C2.
- RandomQuery (VBScript) spywaretrojan
- According to SentinelLabs, this is a VisualBasic-based malware that gathers system and file information and exfiltrates the data using…
- Ranion RaasRansomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Rannoh ransomware
- Rannoh is a type of ransomware that encrypts files on the victim's machine and demands a ransom for decryption.
- Rans0mLocked ransomware
- Rans0mLocked is a ransomware variant known for encrypting victims' files and demanding a ransom for decryption.
- Ranscam ransomwarewiper
- Ranscam is a ransomware that deletes the victim's files instead of encrypting them while demanding a ransom.
- Ransed ransomware
- Ransed is a ransomware strain that encrypts files on infected systems, demanding a ransom payment for data decryption.
- Ransoc ransomware
- Ransoc is a type of ransomware that targets individuals, particularly those using media and entertainment platforms.
- Ransom Prank ransomware
- Ransom Prank is a ransomware strain known for encrypting files on infected systems, rendering them inaccessible until a ransom is paid.
- Ransom102 ransomware
- Ransom102 is a type of ransomware known for encrypting files on the victim's system and demanding a ransom for decryption keys.
- Ransom32 ransomware
- Ransomware no extension change, Javascript Ransomware
- RansomAES ransomware
- RansomAES is a type of ransomware known for encrypting user files and demanding a ransom for decryption.
- RansomBlox ransomware
- RansomBlox is a type of ransomware known for encrypting user files and demanding a ransom in cryptocurrency.
- RansomCuck ransomware
- RansomCuck is a ransomware variant known for encrypting files and demanding a ransom for decryption.
- RansomEXX ransomwaretrojan
- Also known as Ransom X, Defray777, Defray-777. We recently discovered a new file-encrypting Trojan built as an ELF executable and intended to encrypt data on machines controlled by…
- RansomEXX (ELF) ransomware
- Also known as Defray777. According to SentineOne, RansomEXX (aka Defray, Defray777), a multi-pronged extortion threat, has been observed in the wild since late 2020.
- RansomExx2 ransomware
- According to IBM Security X-Force, this is a new but functionally very similar version of RansomExx, fully rewritten in Rust and…
- RansomHub ransomware
- RansomHub is a ransomware-as-a-service (RaaS) offering with Windows, ESXi, Linux, and FreeBSD versions that has been in use since at least…
- RansomLock ransomware
- Also known as WinLock. RansomLock, also known as WinLock, is a form of ransomware known for locking the desktop of infected computers.
- RansomMine ransomware
- RansomMine is a type of ransomware that encrypts data and demands a ransom payment for decryption.
- RansomPlus ransomware
- Author of this ransomware is sergej. Ransom is 0.25 bitcoins for the return of files. Originated in English. Used worldwide. This…
- RansomUserLocker ransomware
- RansomUserLocker is a ransomware strain that encrypts files on infected systems, demanding a ransom payment for decryption keys.
- RansomWarrior ransomware
- RansomWarrior is a type of ransomware known for encrypting victims' files and demanding a ransom for decryption.
- Ransomcartel ransomware
- Ransomcartel is a ransomware family known for encrypting victim files and demanding ransom payments in cryptocurrency.
- Ransomhouse ransomware
- Ransomhouse is a ransomware group known for encrypting victim data and demanding a ransom for decryption keys.
- Ransomnix ransomware
- Ransomnix is a ransomware strain that encrypts the victim's files and demands a ransom for decryption keys.
- Ranzy ransomware
- Ranzy is a ransomware family that targets various industries to encrypt victim data and demands a ransom for decryption.
- Rapid ransomware
- Rapid is a ransomware that encrypts files on the victim's machine and demands a ransom for decryption.
- Rapid 2.0 ransomware
- Rapid 2.0 is a strain of ransomware notorious for swiftly encrypting files on infected systems.
- Rapid 3.0 ransomware
- Rapid 3.0 is a sophisticated ransomware strain targeting numerous industries.