Malware Families page 43 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Ryuk ransomware ransomware
- Similar to Samas and BitPaymer, Ryuk is specifically used to target enterprise environments.
- S-Type backdoor
- S-Type is a backdoor that was used in Operation Dust Storm since at least 2013.
- S.O.V.A. trojancredential-stealer
- S.O.V.A. is an Android banking trojan that was first identified in August 2021 and has subsequently been found in a variety of…
- SAD ransomware
- SAD is a ransomware family known for encrypting files on targeted systems and demanding a ransom for decryption keys.
- SADBRIDGE loader
- According to Elastic, SADBRIDGE is a malware loader packaged as an MSI executable for delivery and it uses DLL side-loading with various…
- SADStory ransomware
- SADStory is a ransomware variant based on the CryPy ransomware, known for encrypting files and demanding a ransom payment from victims.
- SAGE ransomware
- Also known as Saga. SAGE is a ransomware family known for encrypting files and demanding a ransom for decryption.
- SALTWATER backdoor
- According to Mandiant, SALTWATER is a module for the Barracuda SMTP daemon (bsmtpd) that has backdoor functionality.
- SARansom ransomware
- SARansom is a ransomware strain known for encrypting files on infected systems and demanding a ransom for unlocking them.
- SAVEfiles ransomware
- SAVEfiles is a ransomware family that encrypts user data, often targeting financial services, government, and healthcare sectors primarily…
- SBIDIOT rat
- SBIDIOT is a remote access trojan (RAT) utilized for unauthorized access and control of infected systems.
- SDBbot backdoorloader
- Also known as SDB bot. SDBbot is a backdoor with installer and loader components that has been used by TA505 since at least 2019.
- SDelete wiper
- SDelete is an application that securely deletes data in a way that makes it unrecoverable.
- SEASHARPEE webshell
- SEASHARPEE is a Web shell that has been used by OilRig.
- SEASPY backdoor
- According to CISA, this malware is a persistent backdoor that masquerades as a legitimate Barracuda Networks service.
- SECONDDATE exploit-kit
- SECONDDATE is a cyber espionage tool designed for intercepting and manipulating traffic.
- SEND.ID.TO ransomware
- SEND.ID.TO is a ransomware malware known for encrypting files on infected systems and demanding a ransom for their release.
- SEXi ransomware
- Also known as Formosa, Limpopo, Socotra. Ransomware, likely based on the leaked Babuk source code.
- SHAPESHIFT trojanransomware
- SHAPESHIFT is a sophisticated malware family primarily targeting financial services and government sectors in the United States and Russia.
- SHARPKNOT rat
- Also known as Bitrep. SHARPKNOT, also known as Bitrep, is a remote access Trojan (RAT) used in cyber-espionage campaigns.
- SHARPSTATS backdoor
- SHARPSTATS is a .NET backdoor used by MuddyWater since at least 2019.
- SHATTEREDGLASS ransomware
- Also known as Unidentified 081. Kaspersky Labs observed Andariel to drop this ransomware in one case within a series of attacks carried out against targets in South Korea…
- SHEETCREEP backdoor
- According to Zscaler, SHEETCREEP is a lightweight backdoor written in C# that uses Google Sheets for C2 communication.
- SHIPSHAPE wormspyware
- SHIPSHAPE is malware developed by APT30 that allows propagation and exfiltration of data over removable devices.
- SHOTPUT backdoor
- Also known as Backdoor.APT.CookieCutter, Pirpi, CookieCutter. SHOTPUT is a custom backdoor linked to APT3, known for conducting cyber espionage activities.
- SHUTTERSPEED backdoor
- SHUTTERSPEED is a backdoor malware used by the North Korean threat actor APT37, known for cyber espionage activities targeting South Korea…
- SILENTTRINITY rat
- SILENTTRINITY is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers…
- SILENTUPLOADER loaderdropper
- According to Mandiant, SILENTUPLOADER is an uploader written in MSIL that is dropped by DOSTEALER and is designed to work specifically in…
- SLAPSTICK backdoor
- According to FireEye, SLAPSTICK is a Solaris PAM backdoor that grants a user access to the system with a secret, hard-coded password.
- SLAYSTYLE webshell
- According to Mandiant, SLAYSTYLE is a webshell written in Java.
- SLICKSHOES backdoor
- SLICKSHOES is a backdoor malware often associated with advanced persistent threat operations.
- SLIGHTPULSE webshell
- SLIGHTPULSE is a web shell that was used by APT5 as early as 2020 including against Pulse Secure VPNs at US Defense Industrial Base (DIB)…
- SLIMAGENT screen-capture
- According to CERT-UA, this is a malware developed using the C++ programming language.
- SLOTHFULMEDIA rat
- Also known as JackOfHearts, QueenOfClubs. SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least…
- SLOWDRIFT backdoor
- SLOWDRIFT is a backdoor used by APT37 against academic and strategic victims in South Korea.
- SLOWPULSE credential-stealertrojan
- SLOWPULSE is a malware that was used by APT5 as early as 2020 including against U.S.
- SLUB backdoor
- SLUB is a malware strain known for its command-and-control communication via legitimate platforms like GitHub and Slack.
- SMOKEDHAM backdoor
- SMOKEDHAM is a Powershell-based .NET backdoor that was first reported in May 2021; it has been used by at least one…
- SMSspy spywaretrojan
- SMSspy is a type of spyware targeting mobile devices, specifically designed to intercept and steal SMS messages.
- SManager ratspyware
- Also known as PhantomNet. SManager, also known as PhantomNet, is a remote access tool used for espionage activities.
- SNAPPYBEE rattrojan
- Also known as Deed RAT, POISONPLUG.DEED. SNAPPYBEE, also known as Deed RAT or POISONPLUG.DEED, is a Remote Access Trojan used primarily for cyber espionage activities targeting…
- SNC ransomware
- Ransomware SNC is a ransomware who encrypts files and asks for a variable amount of Bitcoin before releasing the decryption key to your…
- SNEEPY webshell
- Also known as ByeByeShell. SNEEPY, also known as ByeByeShell, is a web shell used for remote access and control of compromised servers.
- SNOWLIGHT dropper
- According to sysdig, SNOWLIGHT is used as a dropper for its fileless payload (vshell).
- SNS Locker ransomware
- SNS Locker is a ransomware family known for encrypting files on the victim's system and demanding a ransom for decryption.
- SNSLocker ransomware
- SNSLocker is a type of ransomware based on the open-source EDA2 project.
- SNUGRIDE backdoor
- SNUGRIDE is a backdoor that has been used by menuPass as first stage malware.
- SOLO ransomware
- SOLO is a type of ransomware that encrypts files on an infected system, demanding a ransom payment for decryption.
- SOREBRECT ransomware
- SOREBRECT is a fileless, code-injecting ransomware known for its sophisticated techniques to avoid detection.
- SOUNDBITE backdoor
- Also known as denis. SOUNDBITE is a signature backdoor associated with APT32, primarily used for cyber-espionage campaigns targeting government and…
- SPACESHIP worm
- SPACESHIP is malware developed by APT30 that allows propagation and exfiltration of data over removable devices.
- SPAWNCHIMERA backdoor
- SPAWNCHIMERA is a backdoor that supports command and control and can inject malicious components into native processes.
- SPAWNSNARE exploit-kit
- According to Mandiant, this is a utility that is written in C and targets Linux.
- SPECTRALVIPER trojanspyware
- SPECTRALVIPER is an elusive piece of malware known for its information-stealing capabilities, primarily targeting government and financial…
- SPHijacker rootkit
- According to Trend Micro, this is a tool designed to disable security products, adopting two approaches to achieve this purpose.
- SPIDERPIG RAT rat
- SPIDERPIG RAT is a remote access trojan used to gain unauthorized access to systems, primarily targeting government, financial, and tech…
- SQLRat rat
- SQLRat is malware that executes SQL scripts to avoid leaving traditional host artifacts.
- SQ_ Ransomware ransomware
- Also known as VO_ Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- SSHDoor backdoor
- SSHDoor is a backdoor malware primarily utilizing the SSH protocol to maintain persistent access to compromised systems.
- SSHNET
- SSHNET is a malware with no available description, suggesting limited public information or research on its functionality or targets.
- SSLoad downloaderloader
- SSLoad is a Rust-based downloader that first emerged in January 2024 and is used to deliver secondary payloads.
- STARWHALE backdoorrat
- Also known as CANOPY, Canopy, SloughRAT. STARWHALE is Windows Script File (WSF) backdoor that has been used by MuddyWater, possibly since at least November 2021; there is also a…
- STASHLOG loaderdropper
- Malware that abuses the Common Log File System (CLFS) to store/hide a second stage payload via registry transaction files.
- STATICPLUGIN downloaderloader
- STATICPLUGIN is a downloader known to be leveraged by Mustang Panda and was first observed utilized in 2025.
- STEADYPULSE webshell
- STEADYPULSE is a web shell that infects targeted Pulse Secure VPN servers through modification of a legitimate Perl script that was used…
- STEALHOOK credential-stealer
- STEALHOOK is a credential-stealing malware known for phishing attacks targeting financial and technology sectors.
- STEELCORGI
- According to FireEye, STEELCORGI is a packer for Linux ELF files that makes use of execution guardrails by sourcing decryption key…
- STEELHOOK trojan
- STEELHOOK is a trojan malware known for its involvement in cybercrime activities.
- STONEBOAT loaderdropper
- According to Mandiant, STONEBOAT is an installer for DICELOADER.
- STOP ransomware
- Also known as Djvu, KeyPass. STOP Djvu Ransomware it is a ransomware which encrypts user data through AES-256 and adds one of the dozen available extensions as marker…
- STOP Ransomware ransomware
- Emmanuel_ADC-Soft found a new STOP Ransomware variant that appends the .INFOWAIT extension and drops a ransom note named !readme.txt.
- STOWAWAY backdoor
- According to Mandiant, STOWAWAY is a publicly available backdoor and proxy.
- STRATOFEAR ratspyware
- STRATOFEAR is a sophisticated remote access Trojan (RAT) primarily used for cyber espionage.
- STRRAT ratcredential-stealerkeylogger
- STRRAT is a Java-based RAT, which makes extensive use of plugins to provide full remote access to an attacker, as well as credential…
- SUBTLE-PAWS rat
- SUBTLE-PAWS is a remote access tool (RAT) used for cyber-espionage.
- SUCEFUL credential-stealer
- SUCEFUL is a piece of ATM malware specifically designed to target ATM machines.
- SUGARDUMP credential-stealer
- SUGARDUMP is a proprietary browser credential harvesting tool that was used by UNC3890 during the C0010 campaign.
- SUGARLOADER loader
- SUGARLOADER is a malware loader designed to deliver various types of malicious payloads to compromised systems.
- SUGARRUSH backdoor
- According to Mandiant, SUGARUSH is a backdoor written to establish a connection with an embedded C2 and to execute CMD commands.
- SUGARUSH backdoor
- SUGARUSH is a small custom backdoor that can establish a reverse shell over TCP to a hard coded C2 address.
- SUNBURST trojanbackdoor
- Also known as Solorigate. SUNBURST is a trojanized DLL designed to fit within the SolarWinds Orion software update framework.
- SUNSPOT loader
- SUNSPOT is an implant that injected the SUNBURST backdoor into the SolarWinds Orion software update framework.
- SUPERNOVA webshell
- SUPERNOVA is an in-memory web shell written in .NET C#.
- SVCReady loader
- SVCReady is a loader that has been used since at least April 2022 in malicious spam campaigns.
- SVCStealer credential-stealerbotnetscreen-capture
- According to Broadcom, SVCStealer is an information stealer written in C++, targeting devices running an windows operating system.
- SYNful Knock backdoorrootkit
- SYNful Knock is a stealthy modification of the operating system of network devices that can be used to maintain persistence within a…
- SYSCON backdoor
- SYSCON is a backdoor that has been in use since at least 2017 and has been associated with campaigns involving North Korean themes.
- SYSDOWN ransomware
- SYSDOWN is a type of ransomware known for encrypting user files and demanding payment for decryption.
- SZ40 ransomware
- SZ40 is a ransomware family known for encrypting files on infected systems and demanding a ransom for decryption keys.
- SZFLocker ransomware
- SZFLocker is a ransomware that encrypts user files and demands payment for the decryption key.
- Sabbath ransomware
- Sabbath is a ransomware family known for targeting government and healthcare sectors primarily in the US and UK.
- SadComputer ransomware
- SadComputer is a ransomware variant known for encrypting files on infected systems.
- Sadogo ransomware
- Sadogo is a type of ransomware that encrypts files on infected systems and demands payment for decryption.
- Saefko trojan
- Saefko is a sophisticated trojan known for its ability to perform various malicious activities once it infiltrates a system.
- SafeNet ratspyware
- SafeNet is a remote access tool used in espionage campaigns targeting government and technology sectors.
- Sage 2.0 Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Sage 2.2 ransomware
- Ransomware Sage 2.2 deletes volume snapshots through vssadmin.exe, disables startup repair, uses process wscript.exe to execute a…
- Sage Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Sagerunex rat
- Sagerunex is a malware family exclusively associated with Lotus Blossom operations, with variants existing since at least 2016.
- SaiGon backdoor
- FireEye reports SaiGon as a variant of ISFB v3 (versions documented are tagged 3.50.132) that is more a generic backdoor than being…