Malware Families page 45 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Shadi ransomware
Shadi is a ransomware family known for encrypting files and demanding payment for decryption keys.
Shadow RAT rat
Shadow RAT is a remote access tool primarily used for cyber espionage.
ShadowCryptor ransomware
ShadowCryptor is a ransomware that encrypts files on affected systems, demanding a ransom payment for decryption.
ShadowPad backdoortrojan
Also known as POISONPLUG.SHADOW, XShellGhost. ShadowPad is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017.
ShadowV2 botnetworm
According to Fortinet, this is a Mirai fork propagating through multiple vulnerabilities.
ShadyHammock rat
ShadyHammock is a remote access tool typically used in cyber espionage campaigns, targeting government and energy sectors.
Shai-Hulud wormcredential-stealer
Shai-Hulud is a supply chain worm, first reported in September 2025, that spreads through code repositories, including GitHub and NPM…
Shakti trojan
Shakti is an advanced persistent threat (APT) malware family used for cyber espionage, mainly targeting defense and government sectors in…
Shamoon wiper
Also known as Disttrack. Shamoon is wiper malware that was first used by an Iranian group known as the "Cutting Sword of Justice" in 2012.
SharPyShell webshell
Also known as ASPSHELL. SharPyShell is a tiny and obfuscated ASP.NET webshell that executes commands received by an encrypted channel compiling them in memory at…
Shark backdoor
Also known as Atom. Shark is a backdoor malware written in C# and .NET that is an updated version of Milan; it has been used by HEXANE since at least July 2021.
SharkBot trojan
SharkBot is a banking malware, first discovered in October 2021, that tries to initiate money transfers directly from compromised devices…
SharpBeacon rattrojan
.NET reimplementation of Cobalt Strike beacon/stager
SharpBot botnettrojan
SharpBot is a trojan and botnet malware family primarily targeting financial institutions and healthcare organizations.
SharpDisco dropper
SharpDisco is a dropper developed in C# that has been used by MoustachedBouncer since at least 2020 to load malicious plugins.
SharpEye ratspyware
SharpEye is a remote access tool often used in cyber-espionage campaigns targeting government and defense sectors.
SharpHound credential-stealerspyware
According to its Github repository, SharpHound is a C# Data Collector for BloodHound.
SharpMapExec
This tool is made to simplify penetration testing of networks and to create a Swiss-army knife that is made for running on Windows which…
SharpRhino rat
SharpRhino is a remote access trojan (RAT) primarily used for cyber espionage targeting government and financial services in specific…
SharpStage backdoor
Also known as LastConn. SharpStage is a .NET malware with backdoor capabilities.
SharpWMI trojan
According to its Github repository, SharpWMI is a C# implementation of various WMI functionality.
ShellBind backdoor
ShellBind is a Linux-based malware that functions as a backdoor, allowing attackers to gain persistent remote access to compromised systems.
ShellClient RAT rat
Also known as GhostShell. ShellClient RAT, also known as GhostShell, is a remote access trojan used primarily for cyber-espionage purposes.
ShellLocker ransomware
PCRIsk states that ShellLocker is a ransomware-type virus developed using .NET framework.
ShellLocker Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Sheriff backdoor
According to IBM X-Force, this is a modular backdoor that was used for targeting the defense sector of Ukraine.
ShiftyBug spywaretrojan
ShiftyBug is an auto-rooting adware family of malware for Android.
Shifu trojancredential-stealer
Shifu was originally discovered by Trusteer security researchers (Ilya Kolmanovich, Denis Laskov) in the middle of 2015.
Shim RAT rat
Shim RAT is a sophisticated remote access trojan primarily used for cyber espionage.
ShimRat rat
ShimRat has been used by the suspected China-based adversary Mofang in campaigns targeting multiple countries and sectors including…
ShimRatReporter spywarerat
ShimRatReporter is a tool used by suspected Chinese adversary Mofang to automatically conduct initial discovery.
ShinigamiLocker ransomware
ShinigamiLocker is a type of ransomware known for encrypting files on infected machines and demanding payment for the decryption key.
ShinoLocker ransomware
ShinoLocker is a ransomware that encrypts files on the affected system and demands a ransom for the decryption key.
Shinra ransomware
SHINRA ransomware is a variant of the Proton ransomware family, known for its malicious activities involving data encryption and demanding…
Shishiga backdoordropper
Shishiga is a modular malware family designed primarily as a dropper and backdoor.
ShkolotaCrypt ransomware
ShkolotaCrypt is a type of ransomware known for encrypting files on affected systems and demanding a cryptocurrency ransom for decryption…
Shlayer trojandropper
According to PCrisk, Shlayer is a trojan-type virus designed to proliferate various adware and other unwanted applications, and promote…
Shopper spywaretrojan
Also known as LeifAccess. Shopper/LeifAccess is a malicious Android app that uses Android's AccessibilityService to secretly control the device.
ShortLeash (ELF) backdoorbotnet
According to STRIKE, ShortLeash is a custom backdoor used to create an ORB network.
ShortLeash (Windows) backdoor
According to STRIKE, ShortLeash is a custom backdoor used to create an ORB network.
ShowMyPC
ShowMyPC is a portable and free remote access program that's nearly identical to UltraVNC but uses a password to make a connection instead…
ShrinkLocker ransomware
ShrinkLocker is a VBS-based malicious script that leverages the legitimate Bitlocker application to encrypt files on victim systems for…
Shrug ransomware
Shrug is a type of ransomware known for targeting various sectors, including financial services and healthcare.
Shujin ransomware
Also known as KinCrypt. Shujin, also known as KinCrypt, is a ransomware family known for encrypting files on the victim's machine and demanding a ransom payment…
ShurL0ckr ransomware
Security researchers uncovered a new ransomware named ShurL0ckr (detected by Trend Micro as RANSOM_GOSHIFR.B) that reportedly bypasses…
Shurk Steal credential-stealerspyware
Shurk Steal is a credential-stealer designed to extract sensitive information such as passwords and personal data from infected systems.
ShutUpAndDance ransomware
ShutUpAndDance is a ransomware strain known for encrypting files of targeted systems and demanding payment in cryptocurrency.
Shutdown57 ransomware
Shutdown57 is a ransomware strain known for encrypting files on infected systems, demanding a ransom for decryption.
Shylock trojanbotnet
Also known as Caphaw. Shylock, also known as Caphaw, is a banking trojan known for targeting financial institutions primarily in the US and UK.
Sibot downloaderloader
Sibot is dual-purpose malware written in VBScript designed to achieve persistence on a compromised system as well as download and execute…
SideTwist backdoor
SideTwist is a C-based backdoor that has been used by OilRig since at least 2021.
SideWalk (ELF) backdoor
SideWalk is a sophisticated backdoor used by threat actors to infiltrate targeted systems.
SideWalk (Windows) backdoorrat
Also known as ScrambleCross. Shellcode-based malware family that according to ESET Research was likely written by the same authors as win.crosswalk.
SideWinder (Android) trojanspyware
SideWinder involved a fake VPN app for Android devices published on Google Play Store along with a custom tool that filters victims for…
SideWinder (Windows) trojanspyware
SideWinder is a cyber-espionage-focused Advanced Persistent Threat (APT) group known for targeting government and defense sectors in…
SiennaBlue ransomware
Also known as H0lyGh0st, HolyLocker. Ransomware used by threat actor group DEV-0530, attributed by MSTIC to North Korean origin.
Sierra(Alfa,Bravo, ...) wiperbackdoor
Also known as Destover. Sierra(Alfa,Bravo,...) is commonly known as Destover, a wiper malware used in targeted destructive cyber attacks.
SiestaGraph rat
Also known as DRAFTGRAPH. SiestaGraph, also known as DRAFTGRAPH, is a remote access trojan (RAT) used in cyber espionage campaigns, primarily targeting government…
SifreCikis ransomware
SifreCikis is a form of ransomware that encrypts users' files and demands a ransom payment for decryption.
SifreCozucu ransomware
SifreCozucu is a type of ransomware that encrypts victims' files and demands a ransom for decryption.
Sifreli 2017 ransomware
Sifreli 2017 is ransomware that encrypts files on the victim's system and demands a ransom for decryption.
Sifreli 2019 ransomware
Sifreli 2019 is a ransomware variant that encrypts files on the victim's system and demands a ransom for the decryption key.
SigLoader loader
SigLoader is a sophisticated malware loader known for its ability to evade detection, often used in targeted attacks against financial and…
Siggen6 trojan
Siggen6 is a stealthy Trojan primarily targeting governmental and financial sectors.
Sigma Ransomware ransomware
Today one of our volunteers, Aura, told me about a new new malspam campaign pretending to be from Craigslist that is under way and…
Sigrun Ransomware ransomware
When Sigrun is executed it will first check "HKEY_CURRENT_USER\Keyboard Layout\Preload" to see if it is set to the Russian layout.
Silence botnetloader
Also known as TrueBot. According to PCrisk, Truebot, also known as Silence.Downloader, is a malicious program that has botnet and loader/injector capabilities.
Silence DDoS ddos
Silence DDoS is a malware family known for targeting financial institutions with distributed denial-of-service attacks.
SilentGh0st backdoortrojan
SilentGh0st is a sophisticated backdoor trojan that provides threat actors with remote access capabilities.
SilentPrism backdoor
According to Trend Micro, SilentPrism is a backdoor malware designed to achieve persistence, dynamically execute shell commands, and…
SilentRaid backdoorrat
Also known as MystRodX. According to Cisco Talos, SilentRaid is a primary implant used by UAT-7290 in intrusions meant to establish persistent access to…
SilentSpring ransomware
SilentSpring is a ransomware that encrypts files on the infected system and demands a ransom for decryption.
SilentSweeper trojanspyware
SilentSweeper is an advanced trojan and spyware malware family known for its stealth capabilities.
Silex wiper
Also known as silexbot. Silex, also known as silexbot, is a type of wiper malware that targets IoT devices.
SilkBean ratspyware
SilkBean is a piece of Android surveillanceware containing comprehensive remote access tool (RAT) functionality that has been used in…
Silon trojan
Silon is a banking trojan that targets online banking customers to steal financial credentials.
Siloscape exploit-kitbackdoor
Siloscape is malware that targets Kubernetes clusters through Windows containers.
Siluhdur trojanbackdoor
Siluhdur is a trojan known for targeting financial services and government sectors in North America.
Silver Sparrow loader
According to Red Canary, Silver Sparrow is an activity cluster that includes a binary compiled to run on Apple’s new M1 chips but has been…
Silvertor ransomware
Silvertor is a type of ransomware known for encrypting files on the victim's system and demanding a ransom for decryption.
SimBad
SimBad was a strain of adware on the Google Play Store, distributed through the RXDroider Software Development Kit.
Simda botnetcredential-stealer
Also known as iBank. Simda is a botnet and credential-stealing malware that primarily targets financial institutions.
SimpleFileMover downloader
SimpleFileMover is a malware used to facilitate unauthorized file transfers.
SimpleTea (ELF) rat
Also known as PondRAT, SimplexTea. SimpleTea for Linux is an HTTP(S) RAT. It was discovered in Q1 2023 as an instance of the Lazarus group's Operation DreamJob campaign for…
SimpleTea (OS X) rat
SimpleTea is a RAT for macOS that is based on the same object-oriented project as SimpleTea for Linux (SimplexTea).
Simple_Encoder ransomware
Also known as Tilde. Simple_Encoder, also known as Tilde, is a type of ransomware that encrypts files and demands a ransom for decryption.
Sindoor rat
Sindoor is a remote access trojan (RAT) known for its use in cyber-espionage campaigns, particularly targeting organizations in South Asia.
Singularity rootkit
According to its author, this is a stealthy Linux Kernel Rootkit for modern kernels (6x).
Sinowal credential-stealerbotnetrootkit
Also known as Anserin, Mebroot, Quarian. Sinowal, also known as Torpig or Mebroot, is a sophisticated banking Trojan known for stealing credentials from financial institutions.
SintaLocker ransomware
SintaLocker is a ransomware variant that encrypts files on infected systems and demands a ransom for decryption.
Sisfader backdoor
Sisfader is a backdoor malware used in cyber espionage campaigns.
Skeleton Key backdoorcredential-stealer
Skeleton Key is malware used to inject false credentials into domain controllers with the intent of creating a backdoor password.
SkidLocker ransomware
Also known as Pompous. SkidLocker is a ransomware variant based on the EDA2 platform.
Skidmap cryptominerrootkit
Skidmap is a kernel-mode rootkit used for cryptocurrency mining.
Skimer trojan
Skimer is a type of ATM malware that targets financial institutions by infecting ATMs and allowing attackers to steal card information and…
SkinnyBoy backdoor
SkinnyBoy is a backdoor malware used in cyber espionage campaigns, particularly targeting the government sector.
Skipper downloaderbackdoor
Also known as Kotel. Skipper, also known as Kotel, is a versatile malware family primarily used as a downloader with backdoor capabilities.
Skuld credential-stealer
Also known as TMPN. Skuld, also known as TMPN Stealer, is an information-stealing malware written in Golang (Go) that emerged in May 2023.
Skull ransomware
Skull is a type of ransomware known for encrypting files and demanding a ransom for their release.
Skull HT ransomware
Skull HT is a ransomware strain that encrypts files on infected systems, demanding payment for decryption.