Malware Families page 44 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Saint Bot downloader
Saint Bot is a .NET downloader that has been used by Saint Bear since at least March 2021.
Saitama Backdoor backdoor
Also known as AMATIAS, Saitama. This in .Net witten backdoor abuses the DNS protocoll for its C2 communication.
Sakula rat
Also known as Sakurel, VIPER. Sakula is a remote access tool (RAT) that first surfaced in 2012 and was used in intrusions throughout 2015.
Sakula RAT rattrojandownloader
Also known as Sakurel. Sakula / Sakurel is a trojan horse that opens a back door and downloads potentially malicious files onto the compromised computer.
SalatStealer credential-stealerspyware
Crypto Stealer written in GO. Targets browsers, crypto wallets and telegram clients (Telegram Desktop, Kotatogram). Can capture webcam and…
Salgorea rat
Also known as BadCake. Salgorea, also known as BadCake, is a remote access trojan often used in cyber-espionage campaigns targeting government and technology…
Sality virusbotnetrootkit
F-Secure states that the Sality virus family has been circulating in the wild as early as 2003.
Salsa ransomware
Salsa is a ransomware family that encrypts files on compromised systems and demands a ransom for decryption.
Salvador Stealer trojancredential-stealer
According to ANY.RUN, this is a banking trojan that this collection sensitive user information, including: Registered mobile number…
SamSam ransomware
Also known as Samas, samsam.exe, MIKOPONI.exe. SamSam is ransomware that appeared in early 2016.
SameCoin wiper
SameCoin is a multi-platform wiper with Windows and Android versions that has been used by WIRTE to target entities in the Middle East…
SamoRAT rat
According to PCrisk, SamoRAT is a Remote Access Trojan (RAT), a type of malware that allows the cyber criminals responsible to monitor and…
SampleCheck5000 downloader
Also known as SC5k. SampleCheck5000 is a downloader with multiple variants that was used by OilRig including during the Outer Space campaign to download and…
Samurai backdoorrat
Samurai is a passive backdoor that has been used by ToddyCat since at least 2020.
Sanction ransomware
Ransomware Based on HiddenTear, but heavily modified keygen
Sanctions ransomware
Also known as Sanctions 2017. Sanctions ransomware emerged in 2017, targeting various industries including financial services and healthcare.
Sandro RAT rat
Sandro RAT is a remote access trojan used primarily for cyber espionage activities.
Sanny rat
Sanny is a remote access trojan (RAT) primarily used in cyber espionage activities.
Santa Encryptor ransomware
Santa Encryptor is a type of ransomware that encrypts files and demands a ransom for decryption.
SantaStealer credential-stealerspywaretrojan
According to Rapid7, this malware collects and exfiltrates sensitive documents, credentials, wallets, and data from a broad range of…
Saphyra rat
Saphyra is a remote access tool primarily used for cyber espionage activities.
SapphireMiner cryptominer
SapphireMiner is a cryptomining malware that focuses on unauthorized cryptocurrency mining operations, often targeting industries with…
SapphireStealer credential-stealer
SapphireStealer is a credential-stealing malware primarily targeting the technology and financial sectors.
SappyCache rat
SappyCache is a remote access tool (RAT) used in cyber espionage campaigns, primarily targeting governmental and aerospace sectors.
Saramat ransomware
Saramat is a type of ransomware that encrypts files on infected systems and demands a ransom for the decryption key.
Sardonic backdoor
Sardonic is a backdoor written in C and C++ that is known to be used by FIN8, as early as August 2021 to target a financial institution in…
Sardoninir ransomware
Sardoninir is a type of ransomware that encrypts files on a victim's system and demands a ransom for the decryption key.
Sarhust ratspyware
Also known as ENDCMD, Hussarini. Sarhust, also known as ENDCMD or Hussarini, is a remote access tool used primarily for espionage and data theft.
Sasfis downloader
Also known as Oficla. Sasfis acts mostly as a downloader that has been observed to download Asprox and FakeAV.
Satacom loaderdropper
Also known as CurlyGate, LegionLoader, RobotDropper. Satacom, also known as CurlyGate, LegionLoader, and RobotDropper, is a malware tool primarily used to load or drop additional malicious…
Satan ransomware
Also known as 5ss5c, DBGer, Lucky Ransomware. Satan is a ransomware that encrypts files on infected systems, demanding a ransom in cryptocurrency in exchange for decryption.
Satan Cryptor 2.0 ransomware
Satan Cryptor 2.0 is a ransomware variant that encrypts files on infected systems and demands a ransom payable in Bitcoin for decryption.
Satan Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Satan's Doom Crypter ransomware
Satan's Doom Crypter is a ransomware that encrypts victim files and demands a ransom for decryption.
Satan666 Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
SatanCryptor Go ransomware
SatanCryptor Go is a ransomware that encrypts victims' files using Golang.
Satana ransomware
Satana is a type of ransomware that encrypts victims' files and demands a ransom.
Satellite Turla ratbackdoor
Satellite Turla is a highly sophisticated malware attributed to the Turla group, known for its cyber espionage activities.
Sathurbot botnet
Sathurbot is a malware family primarily distributed via malicious torrent websites.
Satori wormbotnet
Satori is a variation of elf.mirai which was first detected around 2017-11-27 by 360 Netlab.
Saturn ransomware
Saturn is a ransomware that encrypts user files and demands a ransom for decryption.
Satyr ransomware
Satyr is a ransomware family that encrypts files on infected systems, demanding payment for decryption keys.
Sauron Locker ransomware
An Android ransomware that locks the device, changes the wallpaper, and demands money in exchange for unlocking the phone.
SaveTheQueen ransomware
SaveTheQueen is a ransomware variant known for encrypting files and demanding payments in cryptocurrency.
ScammerLocker HT ransomware
ScammerLocker HT is a ransomware variant known for encrypting files on infected computers and demanding a ransom for decryption keys.
ScammerLocker Ph ransomware
ScammerLocker Ph is a type of ransomware that encrypts files on the victim's device.
ScanLine
According to CISA, this is a command-line port scanning utility from Foundstone.
ScanPOS credential-stealer
ScanPOS is a type of point-of-sale malware primarily used to steal credit card information from compromised POS systems.
Scano trojan
Scano is a Trojan malware with limited documentation available.
Scarab ransomware
The Scarab ransomware is a relatively new ransomware strain that was first spotted by security researcher Michael Gillespie in June this…
Scarab Ransomware ransomware
Scarab Ransomware is a type of malware that encrypts files on the infected system, demanding a ransom for decryption.
Scarabey ransomware
Also known as MVP, Scarab, Scarab-Russian. Ransomware with ransomnote in Russian and encryption extension .scarab.
ScareCrow ransomware
ScareCrow is ransomware derived from the leaked Conti source code.
Scatterbrain ransomware
Scatterbrain is a type of ransomware that encrypts files on infected systems, demanding a ransom payment for their decryption.
Scavenger loadercredential-stealer
Also known as SCVNGR, scvngr. Scavenger is a stealthy, two-stage malware family first observed in July 2025 following a targeted supply chain attack on the NPM ecosystem.
Schneiken dropperrat
Schneiken is a VBS 'Double-dropper'. It comes with two RATs embedded in the code (Dunihi and Ratty). Entire code is Base64 encoded.
Schwarze-Sonne-RAT rat
Also known as SS-RAT, Schwarze Sonne. Schwarze-Sonne-RAT, also known as SS-RAT, is a Remote Access Tool commonly used in cyber-espionage campaigns targeting government and tech…
Schwerer ransomware
Schwerer is a ransomware family known for encrypting files and demanding payment for decryption.
Scieron backdoor
The Chinese threat actor has used a custom backdoor dubbed "Scieron" over years in several campaigns according to SentinelLABS.
ScoringMathTea ratdropper
According to ESET Research, ScoringMathTea is a RAT that offers the attackers full control over the compromised machine.
ScorpionLocker ransomware
ScorpionLocker is a type of ransomware that encrypts files on the infected systems, demanding a ransom for decryption.
Scote ratspyware
Scote is a remote access tool (RAT) known for its role in cyber espionage activities.
Scout downloader
A downloader that uses Windows messages to control its execution flow.
ScoutC2 rat
ScoutC2 is a remote access Trojan (RAT) focused on facilitating cyber espionage activities.
Scrabber ransomware
Scrabber is a ransomware known for encrypting victims' files and demanding a ransom.
Scranos spywarecredential-stealer
Scranos is a multifunctional spyware that can extract sensitive information from the victim's system, including credential theft and…
Scraper ransomware
Scraper is a type of ransomware that encrypts files on infected systems, demanding a ransom for decryption.
ScreenCap keyloggerscreen-capturespyware
SentinelOne describes this malware as capable of doing screen capture and keylogging.
ScreenLocker ransomwarescreen-capture
ScreenLocker is a type of ransomware that locks the user's screen and demands a ransom to unlock it.
Scroboscope ransomware
Scroboscope is a ransomware family that targets multiple industries by encrypting victim files and demanding a ransom for decryption keys.
ScrubCrypt loader
ScrubCrypt is the rebranded "Jlaive" crypter, with a unique capability of .BAT packing
SeDll loaderdropper
SeDll is a malware loader that is primarily used to deliver additional malicious payloads onto compromised systems.
SeaDuke backdoor
Also known as SeaDaddy, SeaDesk, Seadask. SeaDuke is malware that was used by APT29 from 2014 to 2015.
Seasalt trojan
Seasalt is malware that has been linked to APT1's 2010 operations.
SecondHandTea rat
SecondHandTea is a full-featured Remote Access Trojan (RAT), closely related to BackbitingTea, the flagship backdoor used in the…
SecretSystem ransomware
SecretSystem is a ransomware family that encrypts files on infected systems, demanding a ransom payment for decryption.
SectopRAT ratcredential-stealer
Also known as 1xxbot, ArechClient. SectopRAT, aka ArechClient2, is a .NET RAT with numerous capabilities including multiple stealth functions.
SecureCryptor ransomware
SecureCryptor is a type of ransomware that encrypts files and demands a ransom payment for decryption.
Seecreen ratscreen-capture
Also known as Firnass. Seecreen (previously called Firnass) is an extremely tiny (500 KB), yet powerful free remote access program that's absolutely perfect for…
Seed RAT rattrojandownloader
Seed is a firewall bypass plus trojan, injects into default browser and has a simple purpose: to be compact (4kb server size) and useful…
SeginChile ransomware
SeginChile is a ransomware family predominantly targeting organizations in Chile, including public sector and financial services.
Sekhmet ransomware
Ransom.Sekhmet not only encrypts a victims files, but also threatens to publish them.
SelfMake Loader loader
SelfMake Loader is a malware classified as a loader, designed to deliver other malicious payloads onto compromised systems.
SendSafe botnet
SendSafe is a malware family known for its role as a spam bot, designed to send unsolicited bulk email.
Seoirse Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Seon ransomware
Seon is a type of ransomware that encrypts files on infected systems, demanding a ransom for their decryption.
SepSys ransomware
Also known as Silvertor Ransomware. SepSys, also known as Silvertor Ransomware, is a ransomware strain that encrypts victim's data and demands a ransom for decryption.
Sepsis ransomware
Sepsis is a ransomware family known for targeting sensitive sectors like healthcare and financial services.
Sepulcher rat
Sepulcher is a Remote Access Trojan (RAT) employed by threat actors to conduct espionage operations.
SerbRansom 2017 Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
SerialVlogger loader
This malware is protected using VMProtect and related to the loading of KEYPLUG.
Serpent backdoor
According to Proofpoint, this is a backdoor written in Python, used in attacks against French entities in the construction, real estate…
Serpent 2017 Ransomware ransomware
Also known as Serpent Danish Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
Serpent Stealer credential-stealer
Serpent Stealer is a malware family specialized in harvesting credentials from infected systems.
Serpico ransomware
Serpico is a variant of the DetoxCrypto ransomware family.
ServHelper backdoor
ServHelper is a backdoor first observed in late 2018.
SessionManager webshelltrojan
A malicious IIS module that allows up/download of files, remote command execution, and using the compromised server as a hop into the…
Seth-Locker ransomwarerat
Seth-Locker is a ransomware with some remote control capabilities that has been in use since at least 2021.
Setro ransomware
Setro is a ransomware family known for encrypting files on infected systems, demanding a ransom in exchange for the decryption key.
Sfile ransomware
Also known as Escal, Morseop. Sfile, also known as Escal or Morseop, is a ransomware family known for encrypting files on targeted systems to extort victims for payment.