Malware Families page 43 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Ryuk ransomware ransomware
Similar to Samas and BitPaymer, Ryuk is specifically used to target enterprise environments.
S-Type backdoor
S-Type is a backdoor that was used in Operation Dust Storm since at least 2013.
S.O.V.A. trojancredential-stealer
S.O.V.A. is an Android banking trojan that was first identified in August 2021 and has subsequently been found in a variety of…
SAD ransomware
SAD is a ransomware family known for encrypting files on targeted systems and demanding a ransom for decryption keys.
SADBRIDGE loader
According to Elastic, SADBRIDGE is a malware loader packaged as an MSI executable for delivery and it uses DLL side-loading with various…
SADStory ransomware
SADStory is a ransomware variant based on the CryPy ransomware, known for encrypting files and demanding a ransom payment from victims.
SAGE ransomware
Also known as Saga. SAGE is a ransomware family known for encrypting files and demanding a ransom for decryption.
SALTWATER backdoor
According to Mandiant, SALTWATER is a module for the Barracuda SMTP daemon (bsmtpd) that has backdoor functionality.
SARansom ransomware
SARansom is a ransomware strain known for encrypting files on infected systems and demanding a ransom for unlocking them.
SAVEfiles ransomware
SAVEfiles is a ransomware family that encrypts user data, often targeting financial services, government, and healthcare sectors primarily…
SBIDIOT rat
SBIDIOT is a remote access trojan (RAT) utilized for unauthorized access and control of infected systems.
SDBbot backdoorloader
Also known as SDB bot. SDBbot is a backdoor with installer and loader components that has been used by TA505 since at least 2019.
SDelete wiper
SDelete is an application that securely deletes data in a way that makes it unrecoverable.
SEASHARPEE webshell
SEASHARPEE is a Web shell that has been used by OilRig.
SEASPY backdoor
According to CISA, this malware is a persistent backdoor that masquerades as a legitimate Barracuda Networks service.
SECONDDATE exploit-kit
SECONDDATE is a cyber espionage tool designed for intercepting and manipulating traffic.
SEND.ID.TO ransomware
SEND.ID.TO is a ransomware malware known for encrypting files on infected systems and demanding a ransom for their release.
SEXi ransomware
Also known as Formosa, Limpopo, Socotra. Ransomware, likely based on the leaked Babuk source code.
SHAPESHIFT trojanransomware
SHAPESHIFT is a sophisticated malware family primarily targeting financial services and government sectors in the United States and Russia.
SHARPKNOT rat
Also known as Bitrep. SHARPKNOT, also known as Bitrep, is a remote access Trojan (RAT) used in cyber-espionage campaigns.
SHARPSTATS backdoor
SHARPSTATS is a .NET backdoor used by MuddyWater since at least 2019.
SHATTEREDGLASS ransomware
Also known as Unidentified 081. Kaspersky Labs observed Andariel to drop this ransomware in one case within a series of attacks carried out against targets in South Korea…
SHEETCREEP backdoor
According to Zscaler, SHEETCREEP is a lightweight backdoor written in C# that uses Google Sheets for C2 communication.
SHIPSHAPE wormspyware
SHIPSHAPE is malware developed by APT30 that allows propagation and exfiltration of data over removable devices.
SHOTPUT backdoor
Also known as Backdoor.APT.CookieCutter, Pirpi, CookieCutter. SHOTPUT is a custom backdoor linked to APT3, known for conducting cyber espionage activities.
SHUTTERSPEED backdoor
SHUTTERSPEED is a backdoor malware used by the North Korean threat actor APT37, known for cyber espionage activities targeting South Korea…
SILENTTRINITY rat
SILENTTRINITY is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers…
SILENTUPLOADER loaderdropper
According to Mandiant, SILENTUPLOADER is an uploader written in MSIL that is dropped by DOSTEALER and is designed to work specifically in…
SLAPSTICK backdoor
According to FireEye, SLAPSTICK is a Solaris PAM backdoor that grants a user access to the system with a secret, hard-coded password.
SLAYSTYLE webshell
According to Mandiant, SLAYSTYLE is a webshell written in Java.
SLICKSHOES backdoor
SLICKSHOES is a backdoor malware often associated with advanced persistent threat operations.
SLIGHTPULSE webshell
SLIGHTPULSE is a web shell that was used by APT5 as early as 2020 including against Pulse Secure VPNs at US Defense Industrial Base (DIB)…
SLIMAGENT screen-capture
According to CERT-UA, this is a malware developed using the C++ programming language.
SLOTHFULMEDIA rat
Also known as JackOfHearts, QueenOfClubs. SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least…
SLOWDRIFT backdoor
SLOWDRIFT is a backdoor used by APT37 against academic and strategic victims in South Korea.
SLOWPULSE credential-stealertrojan
SLOWPULSE is a malware that was used by APT5 as early as 2020 including against U.S.
SLUB backdoor
SLUB is a malware strain known for its command-and-control communication via legitimate platforms like GitHub and Slack.
SMOKEDHAM backdoor
SMOKEDHAM is a Powershell-based .NET backdoor that was first reported in May 2021; it has been used by at least one…
SMSspy spywaretrojan
SMSspy is a type of spyware targeting mobile devices, specifically designed to intercept and steal SMS messages.
SManager ratspyware
Also known as PhantomNet. SManager, also known as PhantomNet, is a remote access tool used for espionage activities.
SNAPPYBEE rattrojan
Also known as Deed RAT, POISONPLUG.DEED. SNAPPYBEE, also known as Deed RAT or POISONPLUG.DEED, is a Remote Access Trojan used primarily for cyber espionage activities targeting…
SNC ransomware
Ransomware SNC is a ransomware who encrypts files and asks for a variable amount of Bitcoin before releasing the decryption key to your…
SNEEPY webshell
Also known as ByeByeShell. SNEEPY, also known as ByeByeShell, is a web shell used for remote access and control of compromised servers.
SNOWLIGHT dropper
According to sysdig, SNOWLIGHT is used as a dropper for its fileless payload (vshell).
SNS Locker ransomware
SNS Locker is a ransomware family known for encrypting files on the victim's system and demanding a ransom for decryption.
SNSLocker ransomware
SNSLocker is a type of ransomware based on the open-source EDA2 project.
SNUGRIDE backdoor
SNUGRIDE is a backdoor that has been used by menuPass as first stage malware.
SOLO ransomware
SOLO is a type of ransomware that encrypts files on an infected system, demanding a ransom payment for decryption.
SOREBRECT ransomware
SOREBRECT is a fileless, code-injecting ransomware known for its sophisticated techniques to avoid detection.
SOUNDBITE backdoor
Also known as denis. SOUNDBITE is a signature backdoor associated with APT32, primarily used for cyber-espionage campaigns targeting government and…
SPACESHIP worm
SPACESHIP is malware developed by APT30 that allows propagation and exfiltration of data over removable devices.
SPAWNCHIMERA backdoor
SPAWNCHIMERA is a backdoor that supports command and control and can inject malicious components into native processes.
SPAWNSNARE exploit-kit
According to Mandiant, this is a utility that is written in C and targets Linux.
SPECTRALVIPER trojanspyware
SPECTRALVIPER is an elusive piece of malware known for its information-stealing capabilities, primarily targeting government and financial…
SPHijacker rootkit
According to Trend Micro, this is a tool designed to disable security products, adopting two approaches to achieve this purpose.
SPIDERPIG RAT rat
SPIDERPIG RAT is a remote access trojan used to gain unauthorized access to systems, primarily targeting government, financial, and tech…
SQLRat rat
SQLRat is malware that executes SQL scripts to avoid leaving traditional host artifacts.
SQ_ Ransomware ransomware
Also known as VO_ Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
SSHDoor backdoor
SSHDoor is a backdoor malware primarily utilizing the SSH protocol to maintain persistent access to compromised systems.
SSHNET
SSHNET is a malware with no available description, suggesting limited public information or research on its functionality or targets.
SSLoad downloaderloader
SSLoad is a Rust-based downloader that first emerged in January 2024 and is used to deliver secondary payloads.
STARWHALE backdoorrat
Also known as CANOPY, Canopy, SloughRAT. STARWHALE is Windows Script File (WSF) backdoor that has been used by MuddyWater, possibly since at least November 2021; there is also a…
STASHLOG loaderdropper
Malware that abuses the Common Log File System (CLFS) to store/hide a second stage payload via registry transaction files.
STATICPLUGIN downloaderloader
STATICPLUGIN is a downloader known to be leveraged by Mustang Panda and was first observed utilized in 2025.
STEADYPULSE webshell
STEADYPULSE is a web shell that infects targeted Pulse Secure VPN servers through modification of a legitimate Perl script that was used…
STEALHOOK credential-stealer
STEALHOOK is a credential-stealing malware known for phishing attacks targeting financial and technology sectors.
STEELCORGI
According to FireEye, STEELCORGI is a packer for Linux ELF files that makes use of execution guardrails by sourcing decryption key…
STEELHOOK trojan
STEELHOOK is a trojan malware known for its involvement in cybercrime activities.
STONEBOAT loaderdropper
According to Mandiant, STONEBOAT is an installer for DICELOADER.
STOP ransomware
Also known as Djvu, KeyPass. STOP Djvu Ransomware it is a ransomware which encrypts user data through AES-256 and adds one of the dozen available extensions as marker…
STOP Ransomware ransomware
Emmanuel_ADC-Soft found a new STOP Ransomware variant that appends the .INFOWAIT extension and drops a ransom note named !readme.txt.
STOWAWAY backdoor
According to Mandiant, STOWAWAY is a publicly available backdoor and proxy.
STRATOFEAR ratspyware
STRATOFEAR is a sophisticated remote access Trojan (RAT) primarily used for cyber espionage.
STRRAT ratcredential-stealerkeylogger
STRRAT is a Java-based RAT, which makes extensive use of plugins to provide full remote access to an attacker, as well as credential…
SUBTLE-PAWS rat
SUBTLE-PAWS is a remote access tool (RAT) used for cyber-espionage.
SUCEFUL credential-stealer
SUCEFUL is a piece of ATM malware specifically designed to target ATM machines.
SUGARDUMP credential-stealer
SUGARDUMP is a proprietary browser credential harvesting tool that was used by UNC3890 during the C0010 campaign.
SUGARLOADER loader
SUGARLOADER is a malware loader designed to deliver various types of malicious payloads to compromised systems.
SUGARRUSH backdoor
According to Mandiant, SUGARUSH is a backdoor written to establish a connection with an embedded C2 and to execute CMD commands.
SUGARUSH backdoor
SUGARUSH is a small custom backdoor that can establish a reverse shell over TCP to a hard coded C2 address.
SUNBURST trojanbackdoor
Also known as Solorigate. SUNBURST is a trojanized DLL designed to fit within the SolarWinds Orion software update framework.
SUNSPOT loader
SUNSPOT is an implant that injected the SUNBURST backdoor into the SolarWinds Orion software update framework.
SUPERNOVA webshell
SUPERNOVA is an in-memory web shell written in .NET C#.
SVCReady loader
SVCReady is a loader that has been used since at least April 2022 in malicious spam campaigns.
SVCStealer credential-stealerbotnetscreen-capture
According to Broadcom, SVCStealer is an information stealer written in C++, targeting devices running an windows operating system.
SYNful Knock backdoorrootkit
SYNful Knock is a stealthy modification of the operating system of network devices that can be used to maintain persistence within a…
SYSCON backdoor
SYSCON is a backdoor that has been in use since at least 2017 and has been associated with campaigns involving North Korean themes.
SYSDOWN ransomware
SYSDOWN is a type of ransomware known for encrypting user files and demanding payment for decryption.
SZ40 ransomware
SZ40 is a ransomware family known for encrypting files on infected systems and demanding a ransom for decryption keys.
SZFLocker ransomware
SZFLocker is a ransomware that encrypts user files and demands payment for the decryption key.
Sabbath ransomware
Sabbath is a ransomware family known for targeting government and healthcare sectors primarily in the US and UK.
SadComputer ransomware
SadComputer is a ransomware variant known for encrypting files on infected systems.
Sadogo ransomware
Sadogo is a type of ransomware that encrypts files on infected systems and demands payment for decryption.
Saefko trojan
Saefko is a sophisticated trojan known for its ability to perform various malicious activities once it infiltrates a system.
SafeNet ratspyware
SafeNet is a remote access tool used in espionage campaigns targeting government and technology sectors.
Sage 2.0 Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Sage 2.2 ransomware
Ransomware Sage 2.2 deletes volume snapshots through vssadmin.exe, disables startup repair, uses process wscript.exe to execute a…
Sage Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Sagerunex rat
Sagerunex is a malware family exclusively associated with Lotus Blossom operations, with variants existing since at least 2016.
SaiGon backdoor
FireEye reports SaiGon as a variant of ISFB v3 (versions documented are tagged 3.50.132) that is more a generic backdoor than being…