Malware Families page 45 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Shadi ransomware
- Shadi is a ransomware family known for encrypting files and demanding payment for decryption keys.
- Shadow RAT rat
- Shadow RAT is a remote access tool primarily used for cyber espionage.
- ShadowCryptor ransomware
- ShadowCryptor is a ransomware that encrypts files on affected systems, demanding a ransom payment for decryption.
- ShadowPad backdoortrojan
- Also known as POISONPLUG.SHADOW, XShellGhost. ShadowPad is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017.
- ShadowV2 botnetworm
- According to Fortinet, this is a Mirai fork propagating through multiple vulnerabilities.
- ShadyHammock rat
- ShadyHammock is a remote access tool typically used in cyber espionage campaigns, targeting government and energy sectors.
- Shai-Hulud wormcredential-stealer
- Shai-Hulud is a supply chain worm, first reported in September 2025, that spreads through code repositories, including GitHub and NPM…
- Shakti trojan
- Shakti is an advanced persistent threat (APT) malware family used for cyber espionage, mainly targeting defense and government sectors in…
- Shamoon wiper
- Also known as Disttrack. Shamoon is wiper malware that was first used by an Iranian group known as the "Cutting Sword of Justice" in 2012.
- SharPyShell webshell
- Also known as ASPSHELL. SharPyShell is a tiny and obfuscated ASP.NET webshell that executes commands received by an encrypted channel compiling them in memory at…
- Shark backdoor
- Also known as Atom. Shark is a backdoor malware written in C# and .NET that is an updated version of Milan; it has been used by HEXANE since at least July 2021.
- SharkBot trojan
- SharkBot is a banking malware, first discovered in October 2021, that tries to initiate money transfers directly from compromised devices…
- SharpBeacon rattrojan
- .NET reimplementation of Cobalt Strike beacon/stager
- SharpBot botnettrojan
- SharpBot is a trojan and botnet malware family primarily targeting financial institutions and healthcare organizations.
- SharpDisco dropper
- SharpDisco is a dropper developed in C# that has been used by MoustachedBouncer since at least 2020 to load malicious plugins.
- SharpEye ratspyware
- SharpEye is a remote access tool often used in cyber-espionage campaigns targeting government and defense sectors.
- SharpHound credential-stealerspyware
- According to its Github repository, SharpHound is a C# Data Collector for BloodHound.
- SharpMapExec
- This tool is made to simplify penetration testing of networks and to create a Swiss-army knife that is made for running on Windows which…
- SharpRhino rat
- SharpRhino is a remote access trojan (RAT) primarily used for cyber espionage targeting government and financial services in specific…
- SharpStage backdoor
- Also known as LastConn. SharpStage is a .NET malware with backdoor capabilities.
- SharpWMI trojan
- According to its Github repository, SharpWMI is a C# implementation of various WMI functionality.
- ShellBind backdoor
- ShellBind is a Linux-based malware that functions as a backdoor, allowing attackers to gain persistent remote access to compromised systems.
- ShellClient RAT rat
- Also known as GhostShell. ShellClient RAT, also known as GhostShell, is a remote access trojan used primarily for cyber-espionage purposes.
- ShellLocker ransomware
- PCRIsk states that ShellLocker is a ransomware-type virus developed using .NET framework.
- ShellLocker Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Sheriff backdoor
- According to IBM X-Force, this is a modular backdoor that was used for targeting the defense sector of Ukraine.
- ShiftyBug spywaretrojan
- ShiftyBug is an auto-rooting adware family of malware for Android.
- Shifu trojancredential-stealer
- Shifu was originally discovered by Trusteer security researchers (Ilya Kolmanovich, Denis Laskov) in the middle of 2015.
- Shim RAT rat
- Shim RAT is a sophisticated remote access trojan primarily used for cyber espionage.
- ShimRat rat
- ShimRat has been used by the suspected China-based adversary Mofang in campaigns targeting multiple countries and sectors including…
- ShimRatReporter spywarerat
- ShimRatReporter is a tool used by suspected Chinese adversary Mofang to automatically conduct initial discovery.
- ShinigamiLocker ransomware
- ShinigamiLocker is a type of ransomware known for encrypting files on infected machines and demanding payment for the decryption key.
- ShinoLocker ransomware
- ShinoLocker is a ransomware that encrypts files on the affected system and demands a ransom for the decryption key.
- Shinra ransomware
- SHINRA ransomware is a variant of the Proton ransomware family, known for its malicious activities involving data encryption and demanding…
- Shishiga backdoordropper
- Shishiga is a modular malware family designed primarily as a dropper and backdoor.
- ShkolotaCrypt ransomware
- ShkolotaCrypt is a type of ransomware known for encrypting files on affected systems and demanding a cryptocurrency ransom for decryption…
- Shlayer trojandropper
- According to PCrisk, Shlayer is a trojan-type virus designed to proliferate various adware and other unwanted applications, and promote…
- Shopper spywaretrojan
- Also known as LeifAccess. Shopper/LeifAccess is a malicious Android app that uses Android's AccessibilityService to secretly control the device.
- ShortLeash (ELF) backdoorbotnet
- According to STRIKE, ShortLeash is a custom backdoor used to create an ORB network.
- ShortLeash (Windows) backdoor
- According to STRIKE, ShortLeash is a custom backdoor used to create an ORB network.
- ShowMyPC
- ShowMyPC is a portable and free remote access program that's nearly identical to UltraVNC but uses a password to make a connection instead…
- ShrinkLocker ransomware
- ShrinkLocker is a VBS-based malicious script that leverages the legitimate Bitlocker application to encrypt files on victim systems for…
- Shrug ransomware
- Shrug is a type of ransomware known for targeting various sectors, including financial services and healthcare.
- Shujin ransomware
- Also known as KinCrypt. Shujin, also known as KinCrypt, is a ransomware family known for encrypting files on the victim's machine and demanding a ransom payment…
- ShurL0ckr ransomware
- Security researchers uncovered a new ransomware named ShurL0ckr (detected by Trend Micro as RANSOM_GOSHIFR.B) that reportedly bypasses…
- Shurk Steal credential-stealerspyware
- Shurk Steal is a credential-stealer designed to extract sensitive information such as passwords and personal data from infected systems.
- ShutUpAndDance ransomware
- ShutUpAndDance is a ransomware strain known for encrypting files of targeted systems and demanding payment in cryptocurrency.
- Shutdown57 ransomware
- Shutdown57 is a ransomware strain known for encrypting files on infected systems, demanding a ransom for decryption.
- Shylock trojanbotnet
- Also known as Caphaw. Shylock, also known as Caphaw, is a banking trojan known for targeting financial institutions primarily in the US and UK.
- Sibot downloaderloader
- Sibot is dual-purpose malware written in VBScript designed to achieve persistence on a compromised system as well as download and execute…
- SideTwist backdoor
- SideTwist is a C-based backdoor that has been used by OilRig since at least 2021.
- SideWalk (ELF) backdoor
- SideWalk is a sophisticated backdoor used by threat actors to infiltrate targeted systems.
- SideWalk (Windows) backdoorrat
- Also known as ScrambleCross. Shellcode-based malware family that according to ESET Research was likely written by the same authors as win.crosswalk.
- SideWinder (Android) trojanspyware
- SideWinder involved a fake VPN app for Android devices published on Google Play Store along with a custom tool that filters victims for…
- SideWinder (Windows) trojanspyware
- SideWinder is a cyber-espionage-focused Advanced Persistent Threat (APT) group known for targeting government and defense sectors in…
- SiennaBlue ransomware
- Also known as H0lyGh0st, HolyLocker. Ransomware used by threat actor group DEV-0530, attributed by MSTIC to North Korean origin.
- Sierra(Alfa,Bravo, ...) wiperbackdoor
- Also known as Destover. Sierra(Alfa,Bravo,...) is commonly known as Destover, a wiper malware used in targeted destructive cyber attacks.
- SiestaGraph rat
- Also known as DRAFTGRAPH. SiestaGraph, also known as DRAFTGRAPH, is a remote access trojan (RAT) used in cyber espionage campaigns, primarily targeting government…
- SifreCikis ransomware
- SifreCikis is a form of ransomware that encrypts users' files and demands a ransom payment for decryption.
- SifreCozucu ransomware
- SifreCozucu is a type of ransomware that encrypts victims' files and demands a ransom for decryption.
- Sifreli 2017 ransomware
- Sifreli 2017 is ransomware that encrypts files on the victim's system and demands a ransom for decryption.
- Sifreli 2019 ransomware
- Sifreli 2019 is a ransomware variant that encrypts files on the victim's system and demands a ransom for the decryption key.
- SigLoader loader
- SigLoader is a sophisticated malware loader known for its ability to evade detection, often used in targeted attacks against financial and…
- Siggen6 trojan
- Siggen6 is a stealthy Trojan primarily targeting governmental and financial sectors.
- Sigma Ransomware ransomware
- Today one of our volunteers, Aura, told me about a new new malspam campaign pretending to be from Craigslist that is under way and…
- Sigrun Ransomware ransomware
- When Sigrun is executed it will first check "HKEY_CURRENT_USER\Keyboard Layout\Preload" to see if it is set to the Russian layout.
- Silence botnetloader
- Also known as TrueBot. According to PCrisk, Truebot, also known as Silence.Downloader, is a malicious program that has botnet and loader/injector capabilities.
- Silence DDoS ddos
- Silence DDoS is a malware family known for targeting financial institutions with distributed denial-of-service attacks.
- SilentGh0st backdoortrojan
- SilentGh0st is a sophisticated backdoor trojan that provides threat actors with remote access capabilities.
- SilentPrism backdoor
- According to Trend Micro, SilentPrism is a backdoor malware designed to achieve persistence, dynamically execute shell commands, and…
- SilentRaid backdoorrat
- Also known as MystRodX. According to Cisco Talos, SilentRaid is a primary implant used by UAT-7290 in intrusions meant to establish persistent access to…
- SilentSpring ransomware
- SilentSpring is a ransomware that encrypts files on the infected system and demands a ransom for decryption.
- SilentSweeper trojanspyware
- SilentSweeper is an advanced trojan and spyware malware family known for its stealth capabilities.
- Silex wiper
- Also known as silexbot. Silex, also known as silexbot, is a type of wiper malware that targets IoT devices.
- SilkBean ratspyware
- SilkBean is a piece of Android surveillanceware containing comprehensive remote access tool (RAT) functionality that has been used in…
- Silon trojan
- Silon is a banking trojan that targets online banking customers to steal financial credentials.
- Siloscape exploit-kitbackdoor
- Siloscape is malware that targets Kubernetes clusters through Windows containers.
- Siluhdur trojanbackdoor
- Siluhdur is a trojan known for targeting financial services and government sectors in North America.
- Silver Sparrow loader
- According to Red Canary, Silver Sparrow is an activity cluster that includes a binary compiled to run on Apple’s new M1 chips but has been…
- Silvertor ransomware
- Silvertor is a type of ransomware known for encrypting files on the victim's system and demanding a ransom for decryption.
- SimBad
- SimBad was a strain of adware on the Google Play Store, distributed through the RXDroider Software Development Kit.
- Simda botnetcredential-stealer
- Also known as iBank. Simda is a botnet and credential-stealing malware that primarily targets financial institutions.
- SimpleFileMover downloader
- SimpleFileMover is a malware used to facilitate unauthorized file transfers.
- SimpleTea (ELF) rat
- Also known as PondRAT, SimplexTea. SimpleTea for Linux is an HTTP(S) RAT. It was discovered in Q1 2023 as an instance of the Lazarus group's Operation DreamJob campaign for…
- SimpleTea (OS X) rat
- SimpleTea is a RAT for macOS that is based on the same object-oriented project as SimpleTea for Linux (SimplexTea).
- Simple_Encoder ransomware
- Also known as Tilde. Simple_Encoder, also known as Tilde, is a type of ransomware that encrypts files and demands a ransom for decryption.
- Sindoor rat
- Sindoor is a remote access trojan (RAT) known for its use in cyber-espionage campaigns, particularly targeting organizations in South Asia.
- Singularity rootkit
- According to its author, this is a stealthy Linux Kernel Rootkit for modern kernels (6x).
- Sinowal credential-stealerbotnetrootkit
- Also known as Anserin, Mebroot, Quarian. Sinowal, also known as Torpig or Mebroot, is a sophisticated banking Trojan known for stealing credentials from financial institutions.
- SintaLocker ransomware
- SintaLocker is a ransomware variant that encrypts files on infected systems and demands a ransom for decryption.
- Sisfader backdoor
- Sisfader is a backdoor malware used in cyber espionage campaigns.
- Skeleton Key backdoorcredential-stealer
- Skeleton Key is malware used to inject false credentials into domain controllers with the intent of creating a backdoor password.
- SkidLocker ransomware
- Also known as Pompous. SkidLocker is a ransomware variant based on the EDA2 platform.
- Skidmap cryptominerrootkit
- Skidmap is a kernel-mode rootkit used for cryptocurrency mining.
- Skimer trojan
- Skimer is a type of ATM malware that targets financial institutions by infecting ATMs and allowing attackers to steal card information and…
- SkinnyBoy backdoor
- SkinnyBoy is a backdoor malware used in cyber espionage campaigns, particularly targeting the government sector.
- Skipper downloaderbackdoor
- Also known as Kotel. Skipper, also known as Kotel, is a versatile malware family primarily used as a downloader with backdoor capabilities.
- Skuld credential-stealer
- Also known as TMPN. Skuld, also known as TMPN Stealer, is an information-stealing malware written in Golang (Go) that emerged in May 2023.
- Skull ransomware
- Skull is a type of ransomware known for encrypting files and demanding a ransom for their release.
- Skull HT ransomware
- Skull HT is a ransomware strain that encrypts files on infected systems, demanding payment for decryption.