Malware Families page 47 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Spereal trojanbackdoor
- Spereal is an evasive and persistent malware known for its capabilities to act as both a trojan and a backdoor, often linked to…
- Sphinx ransomware
- Sphinx is a ransomware family that encrypts files on infected systems and demands payment for decryption.
- Spica backdoor
- Spica is a custom backdoor written in Rust that has been used by Star Blizzard since at least 2023.
- Spicy Hot Pot rat
- Spicy Hot Pot is a remote access tool designed for espionage and data theft.
- SpicyOmelette rat
- SpicyOmelette is a JavaScript based remote access tool that has been used by Cobalt Group since at least 2018.
- Spiteful Doubletake ransomware
- Spiteful Doubletake is a ransomware family that encrypts files and demands a ransom for decryption.
- SplatCloak droppertrojan
- SplatCloak is a malware that disables EDR-related routines used by Windows Defender and Kaspersky to aid in evading detection.
- SplatDropper loaderdropper
- SplatDropper is a loader that utilizes native windows API to deliver its payload to the victim environment.
- Splinter rat
- According to Unit 42, Splinter is a post-exploitation red team tool, written in Rust.
- SpongeBob ransomware
- SpongeBob is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption.
- Spook rat
- Spook is a sophisticated remote access tool often used in cyber espionage campaigns.
- Spora ransomware
- Spora is a sophisticated ransomware known for encrypting files and offering varied decryption payment options, including partial recovery.
- Spora Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Sport ransomware
- Sport is a type of ransomware known for encrypting files on the victim's system and demanding payment for the decryption key.
- SprySOCKS rat
- SprySOCKS is a remote access trojan used by threat actors for surveillance and data exfiltration, particularly targeting government and…
- SpyBanker trojancredential-stealer
- SpyBanker is a banking trojan primarily targeting financial institutions in Brazil.
- SpyBot botnetspyware
- SpyBot is a notorious malware family known for its botnet and spyware capabilities.
- SpyC23 spywarerat
- SpyC23 is a mobile malware that has been used by APT-C-23 since at least 2017.
- SpyCronic spywaretrojan
- SpyCronic is a sophisticated spyware and trojan used primarily for cyber-espionage targeting government and technology sectors.
- SpyDealer spyware
- SpyDealer is Android malware that exfiltrates sensitive data from Android devices.
- SpyEye trojankeyloggercredential-stealer
- SpyEye is a malware targeting both Microsoft Windows browsers and Apple iOS Safari.
- SpyFRPTunnel spywarerat
- Also known as fvncBot. A sophisticated mobile surveillance implant operating as a Remote Control System (RCS).
- SpyGate rat
- This is tool that allow you to control your computer form anywhere in world with full support to unicode language.
- SpyGrace backdoorscreen-capture
- Also known as SpyGlace. A backdoor, capable of providing shell access, loading additional payloads, interacting remotely with the file system and processes, and…
- SpyMax spywarerat
- SpyMax is a popular Android surveillance tool.
- SpyNote ratkeyloggerscreen-capture
- Also known as CypherRat. According to Cleafy, SpyNote abuses Accessibility services and other Android permissions in order to: Collect SMS messages and contacts…
- SpyNote RAT rat
- SpyNote RAT (Remote Access Trojan) is a family of malicious Android apps.
- SpyPress spyware
- According to ESET, SpyPress is a set of Javascript payloads targeting different webmail frameworks (HORDE, MDAEMON, ROUNDCUBE, ZIMBRA).
- Spyder spywarebackdoor
- Spyder is a malware family known for its espionage capabilities.
- Spyder Patchwork spyware
- Spyder Patchwork is a malware associated with a cyber espionage group targeting India.
- Spymaster Pro spyware
- Spymaster Pro is a monitoring software used for surveillance purposes.
- Spynet ratspyware
- Spy-Net is a software that allow you to control any computer in world using Windows Operating System.He is back using new functions and…
- SquidLoader loader
- SquidLoader is a type of malware primarily used as a loader for delivering additional payloads.
- Squirrelwaffle loader
- Also known as DatopLoader. Squirrelwaffle is a loader that was first seen in September 2021.
- SquirtDanger botnet
- According to PaloAlto, SquirtDanger is a commodity botnet malware family that comes equipped with a number of characteristics and…
- Sshdinjector credential-stealertrojan
- Sshdinjector is a credential-stealing trojan that often targets SSH keys on Linux systems.
- SslMM backdoor
- SslMM is a full-featured backdoor used by Naikon that has multiple variants.
- Stabuniq trojan
- Stabuniq is a trojan primarily targeting organizations in the energy and financial sectors in the United States.
- StalinLocker ransomware
- Also known as StalinScreamer. StalinLocker, also known as StalinScreamer, is a ransomware that locks victims' computers with a screen showing a timer and an image of…
- StallionRAT rat
- According to BI.ZONE, StallionRAT allows attackers to execute arbitrary commands, load additional files, and exfiltrate collected data.
- Stampado ransomware
- Ransomware Coded by "The_Rainmaker" Randomly deletes a file every 6hrs up to 96hrs then deletes decryption key
- Stampedo ransomware
- Stampedo is a ransomware variant known for encrypting user files and demanding a ransom for decryption.
- Stantinko trojanbotnet
- Stantinko is a sophisticated malware family that primarily conducts click fraud and various forms of adware distribution.
- StarCruft spywaretrojan
- StarCruft is an advanced persistent threat linked to cyber-espionage activities, known for targeting government and technology sectors in…
- StarFish rat
- According to IBM X-Force, this is a simple reverse shell.
- StarProxy trojan
- StarProxy is custom malware used by Mustang Panda as a post-compromise tool, to enable proxying of traffic between the infected machine…
- Starfighter (Javascript) loaderrat
- According to the author, this is a JavaScript based Empire launcher that runs with its own embedded powershell host to not be dependent on…
- Starfighter (VBScript) loader
- According to the author, this is a JavaScript based Empire launcher that runs with its own embedded powershell host to not be dependent on…
- Starloader loader
- Starloader is a loader component that has been observed loading Felismus and associated tools.
- StarsyPound backdoortrojan
- StarsyPound is a sophisticated backdoor Trojan designed for cyber-espionage.
- StartPage spyware
- Also known as Easy Television Access Now. Potentially unwanted program that changes the startpage of browsers to induce ad impressions.
- Statc credential-stealertrojan
- Also known as Statc Stealer, Static Stealer. This malicious software gains access to a victim’s data by appearing like an authentic Google advertisement.
- StealBit ransomware
- Also known as Corrempa. StealBit is a data exfiltration tool that is developed and maintained by the operators of the the LockBit Ransomware-as-a-Service (RaaS)…
- Stealc credential-stealer
- Stealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a…
- Stealer0x3401 credential-stealer
- According to PTSecurity, this stealer harvests system information which is then RC4 encrypted and Base64 encoded before sending it to the…
- Stealerium credential-stealerkeyloggerscreen-capture
- According to SecurityScorecard, Stealerium is an open-source stealer available on GitHub.
- Stealth Mango spyware
- Stealth Mango is Android malware that has reportedly been used to successfully compromise the mobile devices of government officials…
- Stealth Soldier backdoorkeyloggerscreen-capture
- Check Point Research observed a wave of highly-targeted espionage attacks in Libya that utilize a new custom modular backdoor.
- StealthAgent rat
- StealthAgent is a sophisticated Remote Access Trojan (RAT) targeting various sectors, primarily known for its stealth capabilities and…
- StealthWorker Go credential-stealer
- According to Fortinet, StealthWorker is a brute-force malware that has been linked to a compromised e-commerce website with an embedded…
- SteamHide trojan
- Malware written in .NET that hides in Steam profile pictures.
- Steel ransomware
- Steel is a type of ransomware designed to encrypt files on an infected system and demand a ransom for the decryption key.
- StegoLoader loaderspyware
- StegoLoader is a type of spyware and loader malware that uses steganography to hide its payload in image files.
- Stinger ransomware
- Stinger is a type of ransomware known for encrypting files and demanding payment for decryption.
- Stitch rat
- Stitch is a remote access tool (RAT) that allows attackers to execute commands remotely, manage files, and capture user input.
- StoatWaffle backdoortrojan
- StoatWaffle Malware is a lightweight JavaScript-based backdoor trojan active since at least October 2025 that enables persistent, stealthy…
- StoneDrill wiper
- Also known as DROPSHOT. StoneDrill is wiper malware discovered in destructive campaigns against both Middle Eastern and European targets in association with APT33.
- StorageCrypt ransomwareworm
- Recently BleepingComputer has received a flurry of support requests for a new ransomware being named StorageCrypt that is targeting NAS…
- StorageCrypter ransomware
- Also known as SambaCry. Michael Gillespie noticed numerous submissions to ID Ransomware from South Korea for the StorageCrypter ransomware.
- Storm ransomware
- Storm is a ransomware strain that encrypts files on infected systems, demanding ransom payments for decryption keys.
- StormKittyRAT ratspyware
- According to unpac.me, StormKitty is a Remote Access Trojan (RAT), written in C#, primarily designed to perform extensive system…
- Stormous ransomware
- Stormous is a ransomware group known for targeting various industries, including government and financial services.
- Stormwind backdoorransomware
- Stormwind is a sophisticated malware family known for targeting governmental and defense sectors.
- Stration worm
- Stration, also known as Warezov, is a mass-mailing worm that spreads primarily through email attachments.
- StrawHat ransomware
- StrawHat is a ransomware malware that encrypts files on the victim's system and demands a ransom for decryption.
- StreamEx rat
- StreamEx is a malware family that has been used by Deep Panda since at least 2015.
- Streamer ransomware
- Streamer is a ransomware family known for encrypting files on infected systems and demanding ransom payments in cryptocurrency.
- StrelaStealer credential-stealer
- StrelaStealer is an information stealer malware variant first identified in November 2022 and active through late 2024.
- Stresspaint credential-stealer
- Stresspaint is a credential-stealing malware specifically targeting social media accounts.
- Strictor ransomware
- Strictor is a ransomware variant based on the EDA2 platform.
- StrifeWater rat
- StrifeWater is a remote-access tool that has been used by Moses Staff in the initial stages of their attacks since at least November 2021.
- StrifeWater RAT rat
- StrifeWater RAT is a remote access trojan used primarily for cyber espionage activities.
- StrikeSuit Gift rat
- StrikeSuit Gift is a Remote Access Trojan (RAT) primarily used for cyber espionage against government and defense targets.
- Striked ransomware
- Striked is a ransomware that targets specific industries to encrypt files and demand ransom payments.
- Stroman ransomware
- Stroman is a ransomware family known for targeting various sectors including healthcare, finance, and government.
- StrongPity spywarecredential-stealer
- StrongPity is an information stealing malware used by PROMETHIUM.
- Stupid ransomware
- Stupid ransomware is a type of malicious software designed to encrypt files on an infected system, demanding payment for decryption keys.
- StupidJapan ransomware
- StupidJapan is a ransomware variant that primarily targets organizations within Japan.
- Sturnus trojancredential-stealerscreen-capture
- According to ThreatFabric, Sturnus is a privately operated Android banking trojan.
- Stuxnet
- Stuxnet was the first publicly reported piece of malware to specifically target industrial control systems devices.
- Stuxnet wormrootkitexploit-kit
- Also known as W32.Stuxnet. Stuxnet was the first publicly reported malware to specifically target industrial control systems devices.
- Styver ransomware
- Styver is a ransomware that encrypts files on compromised systems and demands a ransom for decryption.
- Styx ransomware
- Styx is a ransomware family known for targeting critical industries such as financial services, healthcare, and technology.
- Sub7 trojanratkeylogger
- Also known as SubSeven, Sub7Server. Sub7, or SubSeven or Sub7Server, is a Trojan horse program.[1] Its name was derived by spelling NetBus backwards ("suBteN") and swapping…
- Subzero trojanspyware
- Also known as Corelump, Jumplump. Subzero is a sophisticated malware family identified for its espionage capabilities, often used to gather sensitive information.
- SuchSecurity Ransomware ransomware
- Also known as Such Security. This is most likely to affect English speaking users, since the note is written in English.
- Such_Crypt ransomware
- Such_Crypt is a ransomware family known for encrypting victim files and demanding a ransom for decryption.
- SunCrypt ransomware
- Also known as Sun. SunCrypt ransomware was discovered in October 2019 and in August 2020 it was added to Maze ransomware’s cartel.
- SunOrcal rat
- SunOrcal is a Remote Access Trojan (RAT) used primarily for cyber espionage activities targeting government and technology sectors.
- SunSeed trojan
- According to Proofpoint, this is a Lua-based malware likely used by a nation-state sponsored attacker used to target European government…