Malware Families page 41 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Rapid Ransom ransomware
InfinityGroup notes that Rapid Ransomware, unlike regular Ransomware, stays active on the computer after initially encrypting the systems…
Rapid-Gillette ransomware
Rapid-Gillette is a type of ransomware that encrypts files on a victim's system to demand a ransom for decryption.
RapidStealer spywaretrojan
A spy trojan is a type of malware that has the capability to gather information from the infected system without consent from the user.
RapperBot botnet
RapperBot is a variant of the Mirai botnet primarily focused on brute-forcing SSH servers to gain unauthorized access to devices.
RarVault ransomware
RarVault is a type of ransomware that encrypts files on an infected system, demanding a ransom payment for decryption keys.
Rarog cryptominer
Rarog is a trojan primarily used to mine cryptocurrency on infected systems.
Raspberry Robin wormloaderdropper
Also known as LINK_MSIEXEC, QNAP-Worm, RaspberryRobin. Raspberry Robin is initial access malware first identified in September 2021, and active through early 2024.
RaspberryPiBotnet botnetddos
RaspberryPiBotnet is a malicious botnet that compromises vulnerable Raspberry Pi devices to perform various activities such as DDoS…
RatMilad ratspyware
RatMilad is an Android remote access tool (RAT) with spyware functionality that has been used to target enterprise mobile devices in the…
RatOn rat
According to ThreatFabric, this RAT can perform NFC relay attacks and has Automated Transfer ystem (ATS) capabilities
RatSnif ratspyware
RatSnif is a multifunctional remote access tool that allows attackers to capture network traffic and perform various surveillance…
RatankbaPOS trojan
RatankbaPOS is a point-of-sale malware family designed to steal credit card information from POS systems.
RatonRAT rat
RatonRAT is a remote access trojan used for cyber espionage.
Ratty rat
Ratty is an open source Java RAT, made available on GitHub and promoted heavily on HackForums.
Raven Stealer credential-stealer
Raven Stealer is a credential-stealing malware family that primarily targets financial service industries.
RawDisk wiper
RawDisk is a legitimate commercial driver from the EldoS Corporation that is used for interacting with files, disks, and partitions.
RawPOS credential-stealer
Also known as FIENDCRY, DUEBREW, DRIFTWOOD. RawPOS is a point-of-sale (POS) malware family that searches for cardholder data on victims.
Raxir rattrojan
Raxir is a sophisticated remote access trojan (RAT) primarily targeting financial institutions and government sectors in the US and UK.
Razor ransomware
Razor was discovered by dnwls0719, it is a part of Garrantydecrypt ransomware family.
Razr ransomware ransomware
Razr ransomware is a type of malicious software designed to encrypt files on the victim's computer, demanding a ransom for decryption keys.
Razy ransomware
Razy is a form of ransomware that is designed to encrypt files on the infected system and demand payment for decryption.
Rclone ransomwaredownloader
Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA.
ReactorBot botnettrojan
Please note: ReactorBot in its naming is often mistakenly labeled as Rovnix.
RealVNC rat
Also known as VNC Connect, VNC Viewer. The software consists of a server and client application for the Virtual Network Computing (VNC) protocol to control another
Reaver trojan
Reaver is a malware family that has been in the wild since at least late 2016.
RecordBreaker credential-stealer
This malware is a successor to Raccoon Stealer (also referred to as Raccoon Stealer 2.0), which is however a full rewrite in C/C++.
Rector ransomware
Rector is a ransomware that encrypts files on infected systems, demanding a ransom for decryption.
Red Alert ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Red Alert 2.0 trojancredential-stealer
Red Alert 2.0 is a banking trojan that masquerades as a VPN client.
Red Gambler trojanspyware
Red Gambler is a sophisticated trojan malware family designed for financial espionage and data theft, primarily targeting sectors like…
RedAlert ransomware
RedAlert is a ransomware that encrypts files on the victim's system, demanding a ransom for decryption.
RedAlert Ransomware ransomware
Also known as N13V. Ransomware that targets Linux VMware ESXi servers.
RedAlert2 credential-stealertrojan
RedAlert 2 is an new Android malware used by an attacker to gain access to login credentials of various e-banking apps.
RedAlpha spyware
RedAlpha is a cyber espionage malware family primarily used by a nation-state actor.
RedAnts Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
RedBoot ransomwarewiper
RedBoot is a type of ransomware with wiper characteristics, known to encrypt files and modify system partitions, preventing systems from…
RedCap backdoorcredential-stealer
According to Trend Micro, this backdoor receives valid domain credentials as an argument and uses it to log on to the Exchange Server and…
RedCurl spywaretrojan
RedCurl is a known cyber-espionage group that operates in multiple sectors, conducting corporate espionage through phishing campaigns and…
RedDrop spywaretrojan
RedDrop is an Android malware family that exfiltrates sensitive data from devices.
RedEnergy Stealer credential-stealerransomware
According to Zscaler ThreatLabz, RedEnergy stealer uses a fake update campaign to target multiple industry verticals and possesses the…
RedEye ransomwarewiper
Jakub Kroustek discovered the RedEye Ransomware, which appends the .RedEye extension and wipes the contents of the files.
RedFox ransomware
RedFox is a ransomware family that encrypts the files of its victims and demands a ransom for decryption.
RedHat Hacker WebShell webshell
RedHat Hacker WebShell is a malicious script used to gain unauthorized access to web servers.
RedLeaves rat
Also known as BUGJUICE. RedLeaves is a malware family used by menuPass.
RedLine Stealer credential-stealerspyware
Also known as RECORDSTEALER. RedLine Stealer is an information-stealer malware variant first identified in 2020.
RedRoman ransomware
RedRoman is a ransomware family known for encrypting valuable files and demanding ransom payments in cryptocurrency for decryption.
RedRum ransomware
Also known as Grinch, Thanos, Tycoon. RedRum is a ransomware variant also known under the aliases Grinch, Thanos, and Tycoon.
RedTail cryptominer
RedTail is a cryptomining malware, which is based on the open-source XMRIG mining software.
RedTiger Stealer credential-stealer
Also known as RedTiger Ste4ler, redtiger, redtiger-tools. RedTiger Stealer is a malicious software aimed at stealing sensitive information such as credentials from targeted systems.
RedXOR backdoorrootkit
RedXOR is a sophisticated backdoor targeting Linux systems disguised as polkit daemon and utilizing network data encoding based on XOR.
Redkeeper ransomware
Redkeeper is a type of ransomware that encrypts victims' files, demanding a ransom for decryption.
Redosdru downloader
Redosdru is a malware family that primarily acts as a downloader.
Redshot ransomware
Redshot is a type of ransomware that encrypts files on the victim's machine, demanding a ransom for decryption.
Redyms trojan
Redyms is a trojan malware primarily targeting financial institutions and government sectors.
ReedBed backdoor
ReedBed, identified as a malware proxy backdoor, is suspected to be developed by QAKBOT devs, and was deployed by the threat actor…
Reetner ransomware
Reetner is a type of ransomware that encrypts files on infected systems, demanding a ransom from victims to restore access.
Reg
Also known as reg.exe. Reg is a Windows utility used to interact with the Windows Registry.
RegDuke backdoorratloader
RegDuke is a first stage implant written in .NET and used by APT29 since at least 2017.
RegPhantom rootkit
According to Nexttron Systems, RegPhantom is a stealthy Windows kernel rootkit designed to give attackers code execution in kernel mode…
Regin backdoorspywarerootkit
Regin is a malware platform that has targeted victims in a range of industries, including telecom, government, and financial institutions.
RegretLocker ransomware
RegretLocker is a new ransomware that has been found in the wild in the last month that does not only encrypt normal files on disk like…
RekenSom ransomware
Also known as GHack Ransomware. RekenSom, also known as GHack Ransomware, is a type of ransomware that encrypts victims' data, demanding payment for the decryption key.
Rekoobe trojan
A Trojan for Linux intended to infect machines with the SPARC architecture and Intel x86, x86-64 computers.
Rekt Loader loader
Rekt Loader is a malware that serves as an initial access vector for other malicious payloads.
RektLocker ransomware
RektLocker is a ransomware family known for encrypting victim files and demanding a ransom for decryption.
Rektware ransomware
Also known as PRZT Ransomware. GrujaRS discovered a new ransomware called Rektware that appends the .CQScSFy extension
Relic rat
Relic is a remote access tool (RAT) known for its use in cyber espionage operations, particularly against government and defense sectors.
RelicRace rat
RelicRace is a remote access trojan (RAT) often used in cyber-espionage operations.
Relock ransomware
Relock is a ransomware program, designed to encrypt files on a victim's system and demand payment for decryption keys.
RemCom rat
Also known as RemoteCommandExecution. RemCom is a remote administration tool known for enabling attackers to execute commands on infected systems.
RemRAT rat
RemRAT is a remote access trojan used primarily for espionage activities.
Remcos ratkeyloggerspyware
Also known as RemcosRAT, Remvio, Socmer. Remcos is a closed-source tool that is marketed as a remote control and surveillance software by a company called Breaking Security.
Remexi trojan
Also known as CACHEMONEY. Remexi is a Windows-based Trojan that was developed in the C programming language.
RemindMe ransomware
RemindMe is a ransomware family known for encrypting files on victim systems and demanding a ransom for the decryption key.
Remo rat
Also known as PlayPraetor. Remo, also known as PlayPraetor, is a Remote Access Trojan (RAT) used primarily for espionage activities.
Remote Utilities rat
Remote Utilities is a free remote access program with some really great features.
RemoteAdmin rat
RemoteAdmin is a remote access tool (RAT) used by threat actors to gain control over targeted systems.
RemoteCMD rat
RemoteCMD is a custom tool used by APT3 to execute commands on a remote system similar to SysInternal's PSEXEC functionality.
RemoteControl rat
Also known as remotecontrolclient. RemoteControl is a remote access trojan (RAT) that allows attackers to gain unauthorized access and execute commands on compromised systems.
RemotePC rat
RemotePC, for good or bad, is a more simple free remote desktop program.
RemoteUtilities rat
RemoteUtilities is a legitimate remote administration tool that has been used by MuddyWater since at least 2021 for execution on target…
Remsec backdoorspyware
Also known as Backdoor.Remsec, ProjectSauron. Remsec is a modular backdoor that has been used by Strider and appears to have been designed primarily for espionage purposes.
Remus credential-stealerspyware
According to Gen, this is most likely the 64bit evolution of Lumma Stealer.
Remy trojanrat
Also known as WINDSHIELD. Remy, also known as WINDSHIELD, is a remote access trojan (RAT) that facilitates unauthorized access and control over affected systems.
RenLocker Ransomware (FAKE) ransomware
It is spread using email spam, fake updates, attachments and so on.
RenameX12 ransomware
RenameX12 is a ransomware that encrypts files on affected systems and demands a ransom for decryption keys.
RensenWare ransomware
RensenWare is a ransomware that encrypts files and demands users to score a specific point value in the game 'TH12 ~ Undefined Fantastic…
Rentyr ransomware
Rentyr is a type of ransomware that encrypts files on a victim's system, demanding a ransom for decryption.
Rerdom downloader
Rerdom is a downloader malware known for facilitating the delivery of additional malicious payloads.
Reshell webshell
Reshell is a web shell malware that provides attackers with remote access to compromised servers.
Resident backdoor
According to Cisco Talos, Resident is a backdoor likely developed by the same author as win.warmcookie, and it was observed being…
ResidentBat rat
ResidentBat is a Remote Access Trojan (RAT) that allows attackers to gain unauthorized access and control over compromised systems.
Responder credential-stealer
Also known as SpiderLabs Responder. Responder is an open source tool used for LLMNR, NBT-NS and MDNS poisoning, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication…
RestoLocker ransomware
RestoLocker is a type of ransomware designed to encrypt files on a victim's system, demanding payment for decryption keys.
Resurrection ransomware
ransomware
RetMyData ransomware
RetMyData is a ransomware strain targeting various sectors including healthcare, finance, and government.
Retadup cryptominerworm
Retadup is a malware primarily known for spreading as a worm and deploying a cryptocurrency miner on infected systems.
Retefe (Android) credential-stealertrojan
The Android app using for Retefe is a SMS stealer, used to forward mTAN codes to the threat actor.
Retefe (Windows) credential-stealertrojandownloader
Also known as Tsukuba, Werdlod. Retefe is a Windows Banking Trojan that can also download and install additional malware onto the system using Windows PowerShell.
Retis ransomware
Retis is a type of ransomware targeting multiple industries.