Malware Families page 44 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Saint Bot downloader
- Saint Bot is a .NET downloader that has been used by Saint Bear since at least March 2021.
- Saitama Backdoor backdoor
- Also known as AMATIAS, Saitama. This in .Net witten backdoor abuses the DNS protocoll for its C2 communication.
- Sakula rat
- Also known as Sakurel, VIPER. Sakula is a remote access tool (RAT) that first surfaced in 2012 and was used in intrusions throughout 2015.
- Sakula RAT rattrojandownloader
- Also known as Sakurel. Sakula / Sakurel is a trojan horse that opens a back door and downloads potentially malicious files onto the compromised computer.
- SalatStealer credential-stealerspyware
- Crypto Stealer written in GO. Targets browsers, crypto wallets and telegram clients (Telegram Desktop, Kotatogram). Can capture webcam and…
- Salgorea rat
- Also known as BadCake. Salgorea, also known as BadCake, is a remote access trojan often used in cyber-espionage campaigns targeting government and technology…
- Sality virusbotnetrootkit
- F-Secure states that the Sality virus family has been circulating in the wild as early as 2003.
- Salsa ransomware
- Salsa is a ransomware family that encrypts files on compromised systems and demands a ransom for decryption.
- Salvador Stealer trojancredential-stealer
- According to ANY.RUN, this is a banking trojan that this collection sensitive user information, including: Registered mobile number…
- SamSam ransomware
- Also known as Samas, samsam.exe, MIKOPONI.exe. SamSam is ransomware that appeared in early 2016.
- SameCoin wiper
- SameCoin is a multi-platform wiper with Windows and Android versions that has been used by WIRTE to target entities in the Middle East…
- SamoRAT rat
- According to PCrisk, SamoRAT is a Remote Access Trojan (RAT), a type of malware that allows the cyber criminals responsible to monitor and…
- SampleCheck5000 downloader
- Also known as SC5k. SampleCheck5000 is a downloader with multiple variants that was used by OilRig including during the Outer Space campaign to download and…
- Samurai backdoorrat
- Samurai is a passive backdoor that has been used by ToddyCat since at least 2020.
- Sanction ransomware
- Ransomware Based on HiddenTear, but heavily modified keygen
- Sanctions ransomware
- Also known as Sanctions 2017. Sanctions ransomware emerged in 2017, targeting various industries including financial services and healthcare.
- Sandro RAT rat
- Sandro RAT is a remote access trojan used primarily for cyber espionage activities.
- Sanny rat
- Sanny is a remote access trojan (RAT) primarily used in cyber espionage activities.
- Santa Encryptor ransomware
- Santa Encryptor is a type of ransomware that encrypts files and demands a ransom for decryption.
- SantaStealer credential-stealerspywaretrojan
- According to Rapid7, this malware collects and exfiltrates sensitive documents, credentials, wallets, and data from a broad range of…
- Saphyra rat
- Saphyra is a remote access tool primarily used for cyber espionage activities.
- SapphireMiner cryptominer
- SapphireMiner is a cryptomining malware that focuses on unauthorized cryptocurrency mining operations, often targeting industries with…
- SapphireStealer credential-stealer
- SapphireStealer is a credential-stealing malware primarily targeting the technology and financial sectors.
- SappyCache rat
- SappyCache is a remote access tool (RAT) used in cyber espionage campaigns, primarily targeting governmental and aerospace sectors.
- Saramat ransomware
- Saramat is a type of ransomware that encrypts files on infected systems and demands a ransom for the decryption key.
- Sardonic backdoor
- Sardonic is a backdoor written in C and C++ that is known to be used by FIN8, as early as August 2021 to target a financial institution in…
- Sardoninir ransomware
- Sardoninir is a type of ransomware that encrypts files on a victim's system and demands a ransom for the decryption key.
- Sarhust ratspyware
- Also known as ENDCMD, Hussarini. Sarhust, also known as ENDCMD or Hussarini, is a remote access tool used primarily for espionage and data theft.
- Sasfis downloader
- Also known as Oficla. Sasfis acts mostly as a downloader that has been observed to download Asprox and FakeAV.
- Satacom loaderdropper
- Also known as CurlyGate, LegionLoader, RobotDropper. Satacom, also known as CurlyGate, LegionLoader, and RobotDropper, is a malware tool primarily used to load or drop additional malicious…
- Satan ransomware
- Also known as 5ss5c, DBGer, Lucky Ransomware. Satan is a ransomware that encrypts files on infected systems, demanding a ransom in cryptocurrency in exchange for decryption.
- Satan Cryptor 2.0 ransomware
- Satan Cryptor 2.0 is a ransomware variant that encrypts files on infected systems and demands a ransom payable in Bitcoin for decryption.
- Satan Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Satan's Doom Crypter ransomware
- Satan's Doom Crypter is a ransomware that encrypts victim files and demands a ransom for decryption.
- Satan666 Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- SatanCryptor Go ransomware
- SatanCryptor Go is a ransomware that encrypts victims' files using Golang.
- Satana ransomware
- Satana is a type of ransomware that encrypts victims' files and demands a ransom.
- Satellite Turla ratbackdoor
- Satellite Turla is a highly sophisticated malware attributed to the Turla group, known for its cyber espionage activities.
- Sathurbot botnet
- Sathurbot is a malware family primarily distributed via malicious torrent websites.
- Satori wormbotnet
- Satori is a variation of elf.mirai which was first detected around 2017-11-27 by 360 Netlab.
- Saturn ransomware
- Saturn is a ransomware that encrypts user files and demands a ransom for decryption.
- Satyr ransomware
- Satyr is a ransomware family that encrypts files on infected systems, demanding payment for decryption keys.
- Sauron Locker ransomware
- An Android ransomware that locks the device, changes the wallpaper, and demands money in exchange for unlocking the phone.
- SaveTheQueen ransomware
- SaveTheQueen is a ransomware variant known for encrypting files and demanding payments in cryptocurrency.
- ScammerLocker HT ransomware
- ScammerLocker HT is a ransomware variant known for encrypting files on infected computers and demanding a ransom for decryption keys.
- ScammerLocker Ph ransomware
- ScammerLocker Ph is a type of ransomware that encrypts files on the victim's device.
- ScanLine
- According to CISA, this is a command-line port scanning utility from Foundstone.
- ScanPOS credential-stealer
- ScanPOS is a type of point-of-sale malware primarily used to steal credit card information from compromised POS systems.
- Scano trojan
- Scano is a Trojan malware with limited documentation available.
- Scarab ransomware
- The Scarab ransomware is a relatively new ransomware strain that was first spotted by security researcher Michael Gillespie in June this…
- Scarab Ransomware ransomware
- Scarab Ransomware is a type of malware that encrypts files on the infected system, demanding a ransom for decryption.
- Scarabey ransomware
- Also known as MVP, Scarab, Scarab-Russian. Ransomware with ransomnote in Russian and encryption extension .scarab.
- ScareCrow ransomware
- ScareCrow is ransomware derived from the leaked Conti source code.
- Scatterbrain ransomware
- Scatterbrain is a type of ransomware that encrypts files on infected systems, demanding a ransom payment for their decryption.
- Scavenger loadercredential-stealer
- Also known as SCVNGR, scvngr. Scavenger is a stealthy, two-stage malware family first observed in July 2025 following a targeted supply chain attack on the NPM ecosystem.
- Schneiken dropperrat
- Schneiken is a VBS 'Double-dropper'. It comes with two RATs embedded in the code (Dunihi and Ratty). Entire code is Base64 encoded.
- Schwarze-Sonne-RAT rat
- Also known as SS-RAT, Schwarze Sonne. Schwarze-Sonne-RAT, also known as SS-RAT, is a Remote Access Tool commonly used in cyber-espionage campaigns targeting government and tech…
- Schwerer ransomware
- Schwerer is a ransomware family known for encrypting files and demanding payment for decryption.
- Scieron backdoor
- The Chinese threat actor has used a custom backdoor dubbed "Scieron" over years in several campaigns according to SentinelLABS.
- ScoringMathTea ratdropper
- According to ESET Research, ScoringMathTea is a RAT that offers the attackers full control over the compromised machine.
- ScorpionLocker ransomware
- ScorpionLocker is a type of ransomware that encrypts files on the infected systems, demanding a ransom for decryption.
- Scote ratspyware
- Scote is a remote access tool (RAT) known for its role in cyber espionage activities.
- Scout downloader
- A downloader that uses Windows messages to control its execution flow.
- ScoutC2 rat
- ScoutC2 is a remote access Trojan (RAT) focused on facilitating cyber espionage activities.
- Scrabber ransomware
- Scrabber is a ransomware known for encrypting victims' files and demanding a ransom.
- Scranos spywarecredential-stealer
- Scranos is a multifunctional spyware that can extract sensitive information from the victim's system, including credential theft and…
- Scraper ransomware
- Scraper is a type of ransomware that encrypts files on infected systems, demanding a ransom for decryption.
- ScreenCap keyloggerscreen-capturespyware
- SentinelOne describes this malware as capable of doing screen capture and keylogging.
- ScreenLocker ransomwarescreen-capture
- ScreenLocker is a type of ransomware that locks the user's screen and demands a ransom to unlock it.
- Scroboscope ransomware
- Scroboscope is a ransomware family that targets multiple industries by encrypting victim files and demanding a ransom for decryption keys.
- ScrubCrypt loader
- ScrubCrypt is the rebranded "Jlaive" crypter, with a unique capability of .BAT packing
- SeDll loaderdropper
- SeDll is a malware loader that is primarily used to deliver additional malicious payloads onto compromised systems.
- SeaDuke backdoor
- Also known as SeaDaddy, SeaDesk, Seadask. SeaDuke is malware that was used by APT29 from 2014 to 2015.
- Seasalt trojan
- Seasalt is malware that has been linked to APT1's 2010 operations.
- SecondHandTea rat
- SecondHandTea is a full-featured Remote Access Trojan (RAT), closely related to BackbitingTea, the flagship backdoor used in the…
- SecretSystem ransomware
- SecretSystem is a ransomware family that encrypts files on infected systems, demanding a ransom payment for decryption.
- SectopRAT ratcredential-stealer
- Also known as 1xxbot, ArechClient. SectopRAT, aka ArechClient2, is a .NET RAT with numerous capabilities including multiple stealth functions.
- SecureCryptor ransomware
- SecureCryptor is a type of ransomware that encrypts files and demands a ransom payment for decryption.
- Seecreen ratscreen-capture
- Also known as Firnass. Seecreen (previously called Firnass) is an extremely tiny (500 KB), yet powerful free remote access program that's absolutely perfect for…
- Seed RAT rattrojandownloader
- Seed is a firewall bypass plus trojan, injects into default browser and has a simple purpose: to be compact (4kb server size) and useful…
- SeginChile ransomware
- SeginChile is a ransomware family predominantly targeting organizations in Chile, including public sector and financial services.
- Sekhmet ransomware
- Ransom.Sekhmet not only encrypts a victims files, but also threatens to publish them.
- SelfMake Loader loader
- SelfMake Loader is a malware classified as a loader, designed to deliver other malicious payloads onto compromised systems.
- SendSafe botnet
- SendSafe is a malware family known for its role as a spam bot, designed to send unsolicited bulk email.
- Seoirse Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Seon ransomware
- Seon is a type of ransomware that encrypts files on infected systems, demanding a ransom for their decryption.
- SepSys ransomware
- Also known as Silvertor Ransomware. SepSys, also known as Silvertor Ransomware, is a ransomware strain that encrypts victim's data and demands a ransom for decryption.
- Sepsis ransomware
- Sepsis is a ransomware family known for targeting sensitive sectors like healthcare and financial services.
- Sepulcher rat
- Sepulcher is a Remote Access Trojan (RAT) employed by threat actors to conduct espionage operations.
- SerbRansom 2017 Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- SerialVlogger loader
- This malware is protected using VMProtect and related to the loading of KEYPLUG.
- Serpent backdoor
- According to Proofpoint, this is a backdoor written in Python, used in attacks against French entities in the construction, real estate…
- Serpent 2017 Ransomware ransomware
- Also known as Serpent Danish Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- Serpent Stealer credential-stealer
- Serpent Stealer is a malware family specialized in harvesting credentials from infected systems.
- Serpico ransomware
- Serpico is a variant of the DetoxCrypto ransomware family.
- ServHelper backdoor
- ServHelper is a backdoor first observed in late 2018.
- SessionManager webshelltrojan
- A malicious IIS module that allows up/download of files, remote command execution, and using the compromised server as a hop into the…
- Seth-Locker ransomwarerat
- Seth-Locker is a ransomware with some remote control capabilities that has been in use since at least 2021.
- Setro ransomware
- Setro is a ransomware family known for encrypting files on infected systems, demanding a ransom in exchange for the decryption key.
- Sfile ransomware
- Also known as Escal, Morseop. Sfile, also known as Escal or Morseop, is a ransomware family known for encrypting files on targeted systems to extort victims for payment.