Malware Families page 41 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Rapid Ransom ransomware
- InfinityGroup notes that Rapid Ransomware, unlike regular Ransomware, stays active on the computer after initially encrypting the systems…
- Rapid-Gillette ransomware
- Rapid-Gillette is a type of ransomware that encrypts files on a victim's system to demand a ransom for decryption.
- RapidStealer spywaretrojan
- A spy trojan is a type of malware that has the capability to gather information from the infected system without consent from the user.
- RapperBot botnet
- RapperBot is a variant of the Mirai botnet primarily focused on brute-forcing SSH servers to gain unauthorized access to devices.
- RarVault ransomware
- RarVault is a type of ransomware that encrypts files on an infected system, demanding a ransom payment for decryption keys.
- Rarog cryptominer
- Rarog is a trojan primarily used to mine cryptocurrency on infected systems.
- Raspberry Robin wormloaderdropper
- Also known as LINK_MSIEXEC, QNAP-Worm, RaspberryRobin. Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024.
- RaspberryPiBotnet botnetddos
- RaspberryPiBotnet is a malicious botnet that compromises vulnerable Raspberry Pi devices to perform various activities such as DDoS…
- RatMilad ratspyware
- RatMilad is an Android remote access tool (RAT) with spyware functionality that has been used to target enterprise mobile devices in the…
- RatOn rat
- According to ThreatFabric, this RAT can perform NFC relay attacks and has Automated Transfer ystem (ATS) capabilities
- RatSnif ratspyware
- RatSnif is a multifunctional remote access tool that allows attackers to capture network traffic and perform various surveillance…
- RatankbaPOS trojan
- RatankbaPOS is a point-of-sale malware family designed to steal credit card information from POS systems.
- RatonRAT rat
- RatonRAT is a remote access trojan used for cyber espionage.
- Ratty rat
- Ratty is an open source Java RAT, made available on GitHub and promoted heavily on HackForums.
- Raven Stealer credential-stealer
- Raven Stealer is a credential-stealing malware family that primarily targets financial service industries.
- RawDisk wiper
- RawDisk is a legitimate commercial driver from the EldoS Corporation that is used for interacting with files, disks, and partitions.
- RawPOS credential-stealer
- Also known as FIENDCRY, DUEBREW, DRIFTWOOD. RawPOS is a point-of-sale (POS) malware family that searches for cardholder data on victims.
- Raxir rattrojan
- Raxir is a sophisticated remote access trojan (RAT) primarily targeting financial institutions and government sectors in the US and UK.
- Razor ransomware
- Razor was discovered by dnwls0719, it is a part of Garrantydecrypt ransomware family.
- Razr ransomware ransomware
- Razr ransomware is a type of malicious software designed to encrypt files on the victim's computer, demanding a ransom for decryption keys.
- Razy ransomware
- Razy is a form of ransomware that is designed to encrypt files on the infected system and demand payment for decryption.
- Rclone ransomwaredownloader
- Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA.
- ReactorBot botnettrojan
- Please note: ReactorBot in its naming is often mistakenly labeled as Rovnix.
- RealVNC rat
- Also known as VNC Connect, VNC Viewer. The software consists of a server and client application for the Virtual Network Computing (VNC) protocol to control another
- Reaver trojan
- Reaver is a malware family that has been in the wild since at least late 2016.
- RecordBreaker credential-stealer
- This malware is a successor to Raccoon Stealer (also referred to as Raccoon Stealer 2.0), which is however a full rewrite in C/C++.
- Rector ransomware
- Rector is a ransomware that encrypts files on infected systems, demanding a ransom for decryption.
- Red Alert ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Red Alert 2.0 trojancredential-stealer
- Red Alert 2.0 is a banking trojan that masquerades as a VPN client.
- Red Gambler trojanspyware
- Red Gambler is a sophisticated trojan malware family designed for financial espionage and data theft, primarily targeting sectors like…
- RedAlert ransomware
- RedAlert is a ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
- RedAlert Ransomware ransomware
- Also known as N13V. Ransomware that targets Linux VMware ESXi servers.
- RedAlert2 credential-stealertrojan
- RedAlert 2 is an new Android malware used by an attacker to gain access to login credentials of various e-banking apps.
- RedAlpha spyware
- RedAlpha is a cyber espionage malware family primarily used by a nation-state actor.
- RedAnts Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- RedBoot ransomwarewiper
- RedBoot is a type of ransomware with wiper characteristics, known to encrypt files and modify system partitions, preventing systems from…
- RedCap backdoorcredential-stealer
- According to Trend Micro, this backdoor receives valid domain credentials as an argument and uses it to log on to the Exchange Server and…
- RedCurl spywaretrojan
- RedCurl is a known cyber-espionage group that operates in multiple sectors, conducting corporate espionage through phishing campaigns and…
- RedDrop spywaretrojan
- RedDrop is an Android malware family that exfiltrates sensitive data from devices.
- RedEnergy Stealer credential-stealerransomware
- According to Zscaler ThreatLabz, RedEnergy stealer uses a fake update campaign to target multiple industry verticals and possesses the…
- RedEye ransomwarewiper
- Jakub Kroustek discovered the RedEye Ransomware, which appends the .RedEye extension and wipes the contents of the files.
- RedFox ransomware
- RedFox is a ransomware family that encrypts the files of its victims and demands a ransom for decryption.
- RedHat Hacker WebShell webshell
- RedHat Hacker WebShell is a malicious script used to gain unauthorized access to web servers.
- RedLeaves rat
- Also known as BUGJUICE. RedLeaves is a malware family used by menuPass.
- RedLine Stealer credential-stealerspyware
- Also known as RECORDSTEALER. RedLine Stealer is an information-stealer malware variant first identified in 2020.
- RedRoman ransomware
- RedRoman is a ransomware family known for encrypting valuable files and demanding ransom payments in cryptocurrency for decryption.
- RedRum ransomware
- Also known as Grinch, Thanos, Tycoon. RedRum is a ransomware variant also known under the aliases Grinch, Thanos, and Tycoon.
- RedTail cryptominer
- RedTail is a cryptomining malware, which is based on the open-source XMRIG mining software.
- RedTiger Stealer credential-stealer
- Also known as RedTiger Ste4ler, redtiger, redtiger-tools. RedTiger Stealer is a malicious software aimed at stealing sensitive information such as credentials from targeted systems.
- RedXOR backdoorrootkit
- RedXOR is a sophisticated backdoor targeting Linux systems disguised as polkit daemon and utilizing network data encoding based on XOR.
- Redkeeper ransomware
- Redkeeper is a type of ransomware that encrypts victims' files, demanding a ransom for decryption.
- Redosdru downloader
- Redosdru is a malware family that primarily acts as a downloader.
- Redshot ransomware
- Redshot is a type of ransomware that encrypts files on the victim's machine, demanding a ransom for decryption.
- Redyms trojan
- Redyms is a trojan malware primarily targeting financial institutions and government sectors.
- ReedBed backdoor
- ReedBed, identified as a malware proxy backdoor, is suspected to be developed by QAKBOT devs, and was deployed by the threat actor…
- Reetner ransomware
- Reetner is a type of ransomware that encrypts files on infected systems, demanding a ransom from victims to restore access.
- Reg
- Also known as reg.exe. Reg is a Windows utility used to interact with the Windows Registry.
- RegDuke backdoorratloader
- RegDuke is a first stage implant written in .NET and used by APT29 since at least 2017.
- RegPhantom rootkit
- According to Nexttron Systems, RegPhantom is a stealthy Windows kernel rootkit designed to give attackers code execution in kernel mode…
- Regin backdoorspywarerootkit
- Regin is a malware platform that has targeted victims in a range of industries, including telecom, government, and financial institutions.
- RegretLocker ransomware
- RegretLocker is a new ransomware that has been found in the wild in the last month that does not only encrypt normal files on disk like…
- RekenSom ransomware
- Also known as GHack Ransomware. RekenSom, also known as GHack Ransomware, is a type of ransomware that encrypts victims' data, demanding payment for the decryption key.
- Rekoobe trojan
- A Trojan for Linux intended to infect machines with the SPARC architecture and Intel x86, x86-64 computers.
- Rekt Loader loader
- Rekt Loader is a malware that serves as an initial access vector for other malicious payloads.
- RektLocker ransomware
- RektLocker is a ransomware family known for encrypting victim files and demanding a ransom for decryption.
- Rektware ransomware
- Also known as PRZT Ransomware. GrujaRS discovered a new ransomware called Rektware that appends the .CQScSFy extension
- Relic rat
- Relic is a remote access tool (RAT) known for its use in cyber espionage operations, particularly against government and defense sectors.
- RelicRace rat
- RelicRace is a remote access trojan (RAT) often used in cyber-espionage operations.
- Relock ransomware
- Relock is a ransomware program, designed to encrypt files on a victim's system and demand payment for decryption keys.
- RemCom rat
- Also known as RemoteCommandExecution. RemCom is a remote administration tool known for enabling attackers to execute commands on infected systems.
- RemRAT rat
- RemRAT is a remote access trojan used primarily for espionage activities.
- Remcos ratkeyloggerspyware
- Also known as RemcosRAT, Remvio, Socmer. Remcos is a closed-source tool that is marketed as a remote control and surveillance software by a company called Breaking Security.
- Remexi trojan
- Also known as CACHEMONEY. Remexi is a Windows-based Trojan that was developed in the C programming language.
- RemindMe ransomware
- RemindMe is a ransomware family known for encrypting files on victim systems and demanding a ransom for the decryption key.
- Remo rat
- Also known as PlayPraetor. Remo, also known as PlayPraetor, is a Remote Access Trojan (RAT) used primarily for espionage activities.
- Remote Utilities rat
- Remote Utilities is a free remote access program with some really great features.
- RemoteAdmin rat
- RemoteAdmin is a remote access tool (RAT) used by threat actors to gain control over targeted systems.
- RemoteCMD rat
- RemoteCMD is a custom tool used by APT3 to execute commands on a remote system similar to SysInternal's PSEXEC functionality.
- RemoteControl rat
- Also known as remotecontrolclient. RemoteControl is a remote access trojan (RAT) that allows attackers to gain unauthorized access and execute commands on compromised systems.
- RemotePC rat
- RemotePC, for good or bad, is a more simple free remote desktop program.
- RemoteUtilities rat
- RemoteUtilities is a legitimate remote administration tool that has been used by MuddyWater since at least 2021 for execution on target…
- Remsec backdoorspyware
- Also known as Backdoor.Remsec, ProjectSauron. Remsec is a modular backdoor that has been used by Strider and appears to have been designed primarily for espionage purposes.
- Remus credential-stealerspyware
- According to Gen, this is most likely the 64bit evolution of Lumma Stealer.
- Remy trojanrat
- Also known as WINDSHIELD. Remy, also known as WINDSHIELD, is a remote access trojan (RAT) that facilitates unauthorized access and control over affected systems.
- RenLocker Ransomware (FAKE) ransomware
- It is spread using email spam, fake updates, attachments and so on.
- RenameX12 ransomware
- RenameX12 is a ransomware that encrypts files on affected systems and demands a ransom for decryption keys.
- RensenWare ransomware
- RensenWare is a ransomware that encrypts files and demands users to score a specific point value in the game 'TH12 ~ Undefined Fantastic…
- Rentyr ransomware
- Rentyr is a type of ransomware that encrypts files on a victim's system, demanding a ransom for decryption.
- Rerdom downloader
- Rerdom is a downloader malware known for facilitating the delivery of additional malicious payloads.
- Reshell webshell
- Reshell is a web shell malware that provides attackers with remote access to compromised servers.
- Resident backdoor
- According to Cisco Talos, Resident is a backdoor likely developed by the same author as win.warmcookie, and it was observed being…
- ResidentBat rat
- ResidentBat is a Remote Access Trojan (RAT) that allows attackers to gain unauthorized access and control over compromised systems.
- Responder credential-stealer
- Also known as SpiderLabs Responder. Responder is an open source tool used for LLMNR, NBT-NS and MDNS poisoning, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication…
- RestoLocker ransomware
- RestoLocker is a type of ransomware designed to encrypt files on a victim's system, demanding payment for decryption keys.
- Resurrection ransomware
- ransomware
- RetMyData ransomware
- RetMyData is a ransomware strain targeting various sectors including healthcare, finance, and government.
- Retadup cryptominerworm
- Retadup is a malware primarily known for spreading as a worm and deploying a cryptocurrency miner on infected systems.
- Retefe (Android) credential-stealertrojan
- The Android app using for Retefe is a SMS stealer, used to forward mTAN codes to the threat actor.
- Retefe (Windows) credential-stealertrojandownloader
- Also known as Tsukuba, Werdlod. Retefe is a Windows Banking Trojan that can also download and install additional malware onto the system using Windows PowerShell.
- Retis ransomware
- Retis is a type of ransomware targeting multiple industries.