Malware Families page 46 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Sky Wyder backdoorrat
- Sky Wyder is a remote access tool utilized for cyber espionage activities primarily targeting defense and government sectors.
- SkyFile backdoorrat
- SkyFile is a sophisticated malware family known for its capabilities as a remote access tool (RAT), primarily targeting energy and…
- SkyName Ransomware ransomware
- Also known as Blablabla Ransomware. It’s directed to Czechoslovakianspeaking users.
- SkyStars ransomware
- SkyStars is a ransomware strain that encrypts files on infected systems and demands a ransom for decryption.
- Skygofree spywarerat
- Skygofree is Android spyware that is believed to have been developed in 2014 and used through at least 2017.
- Skynet botnetddos
- Skynet is a botnet malware family, primarily used to conduct distributed denial-of-service (DDoS) attacks.
- Skyplex ratspyware
- Skyplex is a sophisticated remote access trojan (RAT) used primarily in cyber-espionage campaigns.
- SlankCryptor ransomware
- SlankCryptor is a ransomware strain that targets sensitive sectors such as financial services and healthcare.
- Slave
- The Slave malware is an obscure or lesser-known threat with no detailed public documentation available concerning its behavior, targeted…
- Slempo credential-stealer
- Also known as SlemBunk. Slempo, also known as SlemBunk, is a known banking trojan targeting mobile devices.
- Slimhem Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Slingshot rootkitspyware
- - 2012 first sighted - Attack vector via compromised Mikrotik routers where victims get infection when they connect to Mikrotik router…
- SlipScreen loader
- According to Proofpoint, SlipScreen is a first stage loader and has variants written in Rust and in C++.
- Sliver rat
- Sliver is an open source, cross-platform, red team command and control (C2) framework written in Golang.
- Slocker ransomware
- Also known as Jisut, Simple Locker. Slocker also known as jisut and pigetrl, is a screen locker that is distributed through telegram groups.
- SloppyMIO backdoorrattrojan
- According to HarfangLab, SloppyMIO is written in C#.
- SlowStepper backdoor
- According to ESET, SlowStepper is a feature-rich backdoor with a toolkit of more than 30 components, programmed in C++, Python, and Go.
- Smackdown ransomware
- Smackdown is a ransomware family known for targeting financial services and government sectors.
- Small Sieve backdoor
- Also known as GRAMDOOR. Small Sieve is a Telegram Bot API-based Python backdoor that has been distributed using a Nullsoft Scriptable Install System (NSIS)…
- Small-Net rat
- Also known as SmallNet. Small-Net is a Remote Access Trojan (RAT) known for its capabilities in cyber espionage.
- SmartApeSG ratcredential-stealerdownloader
- Also known as HANEYMANEY, ZPHP. According to Proofpoint, this is a cluster of fake update campaigns delivering payloads like NetSupportManager RAT and Lumma Stealer.
- SmartEyes ratspyware
- SmartEyes is a sophisticated remote access trojan (RAT) used primarily for espionage purposes, targeting government and defense sectors.
- SmartLoader loader
- SmartLoader is a malware strain primarily used as a loader to facilitate the delivery of other malicious payloads.
- Smash! ransomware
- Smash! is a type of ransomware designed to encrypt files on infected systems and demand a ransom for decryption.
- Smaug ransomware
- The Smaug ransomware is a malware family that targets various industries, encrypting files and demanding a ransom for decryption.
- Smoke Loader loaderbotnetcredential-stealer
- Also known as Dofoil, Sharik, Smoke. Smoke Loader is a malicious bot application that can be used to load other malware.
- Smokest Stealer credential-stealer
- Smokest Stealer is a type of credential-stealing malware targeting a broad range of industries including finance and technology.
- Smominru botnetcryptominerworm
- Also known as Ismo. Smominru, also known as Ismo, is a malware family primarily associated with illicit cryptocurrency mining and botnet activities.
- Smrss32 ransomware
- Smrss32 is a ransomware that encrypts files on an infected system and demands a ransom for the decryption key.
- SmsAgent trojandownloader
- SMSAgent appears as a game application, but silently performs malicious routines in the background.
- Sn0wsLogger keyloggercredential-stealer
- Sn0wsLogger is a keylogger and credential-stealing malware designed to extract sensitive information from infected machines.
- Snake Ransomware ransomware
- Snake ransomware first attracted the attention of malware analysts in January 2020 when they observed the crypto-malware family targeting…
- Snake-Ekans ransomware
- Snake-Ekans is a ransomware family primarily targeting industrial control systems.
- SnakeDisk wormdropper
- According to X-Force, SnakeDisk is a USB worm, dropping further payloads
- SnakeLocker ransomware
- SnakeLocker is a type of ransomware that encrypts files on an infected system and demands a ransom payment for decryption.
- SnakeStealer credential-stealerkeyloggerscreen-capture
- The SnakeStealer (currently advertised under an inaccurate name Snake Keylogger) is information stealing malware with many capabilities.
- SnappyClient ratbackdoor
- According to Zscaler, SnappyClient was first observed in December 2025.
- SnappyTCP webshell
- SnappyTCP is a web shell used by Sea Turtle between 2021 and 2023 against multiple victims.
- Snatch ransomware
- Snatch is a ransomware family that encrypts files and demands a ransom for decryption.
- SnatchCrypto rattrojan
- Also known as BackbitingTea, msoRAT. Malware observed in the SnatchCrypto campaign, attributed by Kaspersky Labs to BlueNoroff with high confidence.
- SnatchLoader downloadertrojancredential-stealer
- A downloader trojan with some infostealer capabilities focused on the browser.
- Snip3 loader
- Snip3 is a sophisticated crypter-as-a-service that has been used since at least 2021 to obfuscate and load numerous strains of malware…
- SnipVex viruscredential-stealer
- SnipVex is a virus that infects files with .exe extension via prepending itself to the host.
- Snojan rat
- Snojan is a remote access trojan primarily used for cyber espionage.
- Snoopy rat
- Snoopy is a Remote Administration Tool. Software for controlling user computer remotely from other computer on local network or Internet.
- SnowFlake Stealer credential-stealer
- SnowFlake Stealer is an information-stealing malware written in Rust, known for its efficiency in extracting credentials and other…
- SnowPicnic ransomware
- SnowPicnic is a ransomware strain known for encrypting victim data and demanding payment for decryption keys.
- Snowdoor backdoortrojan
- Also known as Backdoor.Blizzard, Backdoor.Fxdoor, Backdoor.Snowdoor. Backdoor.Snowdoor is a Backdoor Trojan Horse that allows unauthorized access to an infected computer.
- Snugy rat
- Snugy is a remote access tool (RAT) used in cyber-espionage campaigns.
- SoFucked ransomware
- SoFucked is a type of ransomware used to encrypt victim's data, demanding payment for decryption keys.
- SoWaT botnet
- This is an implant used by APT31 on home routers to utilize them as ORBs.
- Sobaken rat
- According to ESET, this RAT was derived from (the open-source) Quasar RAT.
- Sobig worm
- Also known as Palyh. Sobig is a highly infectious mass-mailing computer worm that spreads through email attachments and network shares.
- SocGholish loaderdownloader
- Also known as FakeUpdates, FakeUpdate, GhoLoader. SocGholish is a JavaScript-based loader malware that has been used since at least 2017.
- Socelars credential-stealer
- Socelars is an infostealer with main focus on: * Facebook Stealer (ads/manager) * Cookie Stealer | AdsCreditCard {Amazon}
- Sockbot backdoor
- Sockbot is a customized and in Go written fork of the Ligolo reverse tunneling open-source tool.
- Socket23 trojanvirus
- SOCKET23 was launched from his web site and immedi- ately infected major French corporations between August and October 1998.
- SocketPlayer ratdownloader
- The RAT is written in .NET, it uses socket.io for communication.
- Socks5 Systemz botnet
- Also known as ProxyBox. The Socks5 Systemz malware is a proxy botnet distributed via the PrivateLoader and Amadey loaders.
- Socksbot backdoor
- Also known as BIRDDOG, Nadrac. Socksbot is a backdoor that abuses Socket Secure (SOCKS) proxies.
- SodaMaster downloaderloader
- Also known as DARKTOWN, dfls, DelfsCake. SodaMaster is a fileless malware used by menuPass to download and execute payloads since at least 2020.
- Solar backdoor
- Solar is a C#/.NET backdoor that was used by OilRig during the Outer Space campaign to download, execute, and exfiltrate files.
- Solarbot botnetcredential-stealer
- Also known as Napolar. Solarbot, also known as Napolar, is a malware family primarily used to build botnets and steal credentials.
- Solidbit ransomware
- Solidbit is a ransomware strain developed using the .NET framework.
- Solider ransomware
- Solider is a type of ransomware known for encrypting files on victims' systems and demanding ransom payments for file decryption.
- Solve ransomware
- Solve is a type of ransomware that encrypts victim files and demands payment for decryption.
- SombRAT backdoorrat
- SombRAT is a modular backdoor written in C++ that has been used since at least 2019 to download and execute malicious payloads, including…
- Somik1 ransomware
- Somik1 is a ransomware strain that targets various industries, encrypting files on compromised systems and demanding a ransom for…
- Somnia ransomware
- Somnia is a ransomware strain known for encrypting victim files without providing a decryption option, effectively rendering data…
- Sorano rat
- Sorano is a remote access trojan (RAT) used for cyber espionage.
- Sordeal-Stealer credential-stealer
- Also known as Sordeal, Sordeal Stealer. Sordeal-Stealer is a Python-based credential stealer that targets platforms such as Discord and Steam.
- SoreFang downloader
- SoreFang is first stage downloader used by APT29 for exfiltration and to load other malware.
- Sorgu trojan
- Sorgu is a trojan that primarily targets the financial-services and technology sectors.
- Sorillus RAT rat
- Sorillus is a Java-based multifunctional remote access trojan (RAT) that targets Linux, macOS, and Windows operating systems.
- Sorry HT ransomware
- Sorry HT is a type of ransomware that encrypts files on the victim's system and demands a ransom payment for decryption keys.
- Soul ratspyware
- Also known as SoulSearcher. Soul is a remote access trojan used primarily for cyber-espionage purposes.
- SoulSearcher loader
- SoulSearcher is a second-stage loader responsible for executing the Soul backdoor main module and parsing its configuration.
- SoumniBot botnet
- SoumniBot is a botnet malware primarily aimed at compromising government and technology sectors to facilitate distributed…
- SoundBill loader
- According to Cisco Talos, this is a customized shellcode loader that has been observed to stage Mimikatz and CobaltStrike.
- SpaceColon ransomwaretrojan
- According to ESET, Spacecolon is a collection of malware written in Delphi, consisting of ScRansom, ScHackTool, ScInstaller, ScService…
- SpaceCow rat
- SpaceCow is a remote access trojan (RAT) believed to be used in cyber espionage operations primarily targeting defense and government…
- Spamtorte trojan
- Spamtorte is a trojan malware known for its use in spam email campaigns targeting financial services.
- Spark backdoor
- Spark is a Windows backdoor and has been in use since as early as 2017.
- SparkRAT rat
- SparkRAT is a cross-platform, open-source Remote Administration Tool (RAT) written in Go and released on GitHub in 2022.
- Sparkle ratspyware
- Sparkle is a remote access tool (RAT) often used in cyber espionage campaigns.
- Sparksrv rat
- Sparksrv is a remote access trojan (RAT) associated with cyber espionage activities.
- SparrowDoor backdoor
- SparrowDoor is a sophisticated backdoor used in cyber-espionage campaigns targeting government and defense industries.
- SpartCrypt ransomware
- SpartCrypt is a ransomware that encrypts files on infected systems and demands a ransom for decryption.
- Sparta rat
- Sparta is a sophisticated remote access tool (RAT) used mainly for cyber-espionage.
- Sparta RAT rat
- Sparta RAT is a remote access trojan primarily used for espionage activities targeting sensitive sectors such as government, energy, and…
- Spartacus ransomware
- Spartacus is ransomware written in .NET and emerged in the first half of 2018.
- Spartacus Ransomware ransomware
- Spartacus Ransomware is a type of malicious software designed to encrypt files on a victim's device, demanding a ransom for decryption.
- SpeakUp trojanbackdoor
- SpeakUp is a Trojan backdoor that targets both Linux and OSX devices.
- Specter backdoor
- Specter is an advanced persistent threat backdoor used for espionage purposes.
- SpectralBlur (ELF) ratbackdoor
- SpectralBlur is a Linux-based malware primarily used for remote access and control.
- SpectralBlur (OS X) backdoorspyware
- SpectralBlur is a macOS malware primarily used for cyberespionage.
- Spectre ransomware
- Spectre is a type of ransomware that encrypts files on infected systems, demanding a ransom for the decryption key.
- Spectre Rat ratbotnet
- Mixed RAT and Botnet malware sold in underground forums.
- Speculoos backdoor
- Speculoos is a backdoor malware primarily targeting technology, telecommunications, and government sectors.
- Spedear rat
- Spedear is believed to be a remote access trojan used primarily in cyber-espionage campaigns targeting government and technology sectors…