Malware Families page 47 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Spereal trojanbackdoor
Spereal is an evasive and persistent malware known for its capabilities to act as both a trojan and a backdoor, often linked to…
Sphinx ransomware
Sphinx is a ransomware family that encrypts files on infected systems and demands payment for decryption.
Spica backdoor
Spica is a custom backdoor written in Rust that has been used by Star Blizzard since at least 2023.
Spicy Hot Pot rat
Spicy Hot Pot is a remote access tool designed for espionage and data theft.
SpicyOmelette rat
SpicyOmelette is a JavaScript based remote access tool that has been used by Cobalt Group since at least 2018.
Spiteful Doubletake ransomware
Spiteful Doubletake is a ransomware family that encrypts files and demands a ransom for decryption.
SplatCloak droppertrojan
SplatCloak is a malware that disables EDR-related routines used by Windows Defender and Kaspersky to aid in evading detection.
SplatDropper loaderdropper
SplatDropper is a loader that utilizes native windows API to deliver its payload to the victim environment.
Splinter rat
According to Unit 42, Splinter is a post-exploitation red team tool, written in Rust.
SpongeBob ransomware
SpongeBob is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption.
Spook rat
Spook is a sophisticated remote access tool often used in cyber espionage campaigns.
Spora ransomware
Spora is a sophisticated ransomware known for encrypting files and offering varied decryption payment options, including partial recovery.
Spora Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Sport ransomware
Sport is a type of ransomware known for encrypting files on the victim's system and demanding payment for the decryption key.
SprySOCKS rat
SprySOCKS is a remote access trojan used by threat actors for surveillance and data exfiltration, particularly targeting government and…
SpyBanker trojancredential-stealer
SpyBanker is a banking trojan primarily targeting financial institutions in Brazil.
SpyBot botnetspyware
SpyBot is a notorious malware family known for its botnet and spyware capabilities.
SpyC23 spywarerat
SpyC23 is a mobile malware that has been used by APT-C-23 since at least 2017.
SpyCronic spywaretrojan
SpyCronic is a sophisticated spyware and trojan used primarily for cyber-espionage targeting government and technology sectors.
SpyDealer spyware
SpyDealer is Android malware that exfiltrates sensitive data from Android devices.
SpyEye trojankeyloggercredential-stealer
SpyEye is a malware targeting both Microsoft Windows browsers and Apple iOS Safari.
SpyFRPTunnel spywarerat
Also known as fvncBot. A sophisticated mobile surveillance implant operating as a Remote Control System (RCS).
SpyGate rat
This is tool that allow you to control your computer form anywhere in world with full support to unicode language.
SpyGrace backdoorscreen-capture
Also known as SpyGlace. A backdoor, capable of providing shell access, loading additional payloads, interacting remotely with the file system and processes, and…
SpyMax spywarerat
SpyMax is a popular Android surveillance tool.
SpyNote ratkeyloggerscreen-capture
Also known as CypherRat. According to Cleafy, SpyNote abuses Accessibility services and other Android permissions in order to: Collect SMS messages and contacts…
SpyNote RAT rat
SpyNote RAT (Remote Access Trojan) is a family of malicious Android apps.
SpyPress spyware
According to ESET, SpyPress is a set of Javascript payloads targeting different webmail frameworks (HORDE, MDAEMON, ROUNDCUBE, ZIMBRA).
Spyder spywarebackdoor
Spyder is a malware family known for its espionage capabilities.
Spyder Patchwork spyware
Spyder Patchwork is a malware associated with a cyber espionage group targeting India.
Spymaster Pro spyware
Spymaster Pro is a monitoring software used for surveillance purposes.
Spynet ratspyware
Spy-Net is a software that allow you to control any computer in world using Windows Operating System.He is back using new functions and…
SquidLoader loader
SquidLoader is a type of malware primarily used as a loader for delivering additional payloads.
Squirrelwaffle loader
Also known as DatopLoader. Squirrelwaffle is a loader that was first seen in September 2021.
SquirtDanger botnet
According to PaloAlto, SquirtDanger is a commodity botnet malware family that comes equipped with a number of characteristics and…
Sshdinjector credential-stealertrojan
Sshdinjector is a credential-stealing trojan that often targets SSH keys on Linux systems.
SslMM backdoor
SslMM is a full-featured backdoor used by Naikon that has multiple variants.
Stabuniq trojan
Stabuniq is a trojan primarily targeting organizations in the energy and financial sectors in the United States.
StalinLocker ransomware
Also known as StalinScreamer. StalinLocker, also known as StalinScreamer, is a ransomware that locks victims' computers with a screen showing a timer and an image of…
StallionRAT rat
According to BI.ZONE, StallionRAT allows attackers to execute arbitrary commands, load additional files, and exfiltrate collected data.
Stampado ransomware
Ransomware Coded by "The_Rainmaker" Randomly deletes a file every 6hrs up to 96hrs then deletes decryption key
Stampedo ransomware
Stampedo is a ransomware variant known for encrypting user files and demanding a ransom for decryption.
Stantinko trojanbotnet
Stantinko is a sophisticated malware family that primarily conducts click fraud and various forms of adware distribution.
StarCruft spywaretrojan
StarCruft is an advanced persistent threat linked to cyber-espionage activities, known for targeting government and technology sectors in…
StarFish rat
According to IBM X-Force, this is a simple reverse shell.
StarProxy trojan
StarProxy is custom malware used by Mustang Panda as a post-compromise tool, to enable proxying of traffic between the infected machine…
Starfighter (Javascript) loaderrat
According to the author, this is a JavaScript based Empire launcher that runs with its own embedded powershell host to not be dependent on…
Starfighter (VBScript) loader
According to the author, this is a JavaScript based Empire launcher that runs with its own embedded powershell host to not be dependent on…
Starloader loader
Starloader is a loader component that has been observed loading Felismus and associated tools.
StarsyPound backdoortrojan
StarsyPound is a sophisticated backdoor Trojan designed for cyber-espionage.
StartPage spyware
Also known as Easy Television Access Now. Potentially unwanted program that changes the startpage of browsers to induce ad impressions.
Statc credential-stealertrojan
Also known as Statc Stealer, Static Stealer. This malicious software gains access to a victim’s data by appearing like an authentic Google advertisement.
StealBit ransomware
Also known as Corrempa. StealBit is a data exfiltration tool that is developed and maintained by the operators of the the LockBit Ransomware-as-a-Service (RaaS)…
Stealc credential-stealer
Stealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a…
Stealer0x3401 credential-stealer
According to PTSecurity, this stealer harvests system information which is then RC4 encrypted and Base64 encoded before sending it to the…
Stealerium credential-stealerkeyloggerscreen-capture
According to SecurityScorecard, Stealerium is an open-source stealer available on GitHub.
Stealth Mango spyware
Stealth Mango is Android malware that has reportedly been used to successfully compromise the mobile devices of government officials…
Stealth Soldier backdoorkeyloggerscreen-capture
Check Point Research observed a wave of highly-targeted espionage attacks in Libya that utilize a new custom modular backdoor.
StealthAgent rat
StealthAgent is a sophisticated Remote Access Trojan (RAT) targeting various sectors, primarily known for its stealth capabilities and…
StealthWorker Go credential-stealer
According to Fortinet, StealthWorker is a brute-force malware that has been linked to a compromised e-commerce website with an embedded…
SteamHide trojan
Malware written in .NET that hides in Steam profile pictures.
Steel ransomware
Steel is a type of ransomware designed to encrypt files on an infected system and demand a ransom for the decryption key.
StegoLoader loaderspyware
StegoLoader is a type of spyware and loader malware that uses steganography to hide its payload in image files.
Stinger ransomware
Stinger is a type of ransomware known for encrypting files and demanding payment for decryption.
Stitch rat
Stitch is a remote access tool (RAT) that allows attackers to execute commands remotely, manage files, and capture user input.
StoatWaffle backdoortrojan
StoatWaffle Malware is a lightweight JavaScript-based backdoor trojan active since at least October 2025 that enables persistent, stealthy…
StoneDrill wiper
Also known as DROPSHOT. StoneDrill is wiper malware discovered in destructive campaigns against both Middle Eastern and European targets in association with APT33.
StorageCrypt ransomwareworm
Recently BleepingComputer has received a flurry of support requests for a new ransomware being named StorageCrypt that is targeting NAS…
StorageCrypter ransomware
Also known as SambaCry. Michael Gillespie noticed numerous submissions to ID Ransomware from South Korea for the StorageCrypter ransomware.
Storm ransomware
Storm is a ransomware strain that encrypts files on infected systems, demanding ransom payments for decryption keys.
StormKittyRAT ratspyware
According to unpac.me, StormKitty is a Remote Access Trojan (RAT), written in C#, primarily designed to perform extensive system…
Stormous ransomware
Stormous is a ransomware group known for targeting various industries, including government and financial services.
Stormwind backdoorransomware
Stormwind is a sophisticated malware family known for targeting governmental and defense sectors.
Stration worm
Stration, also known as Warezov, is a mass-mailing worm that spreads primarily through email attachments.
StrawHat ransomware
StrawHat is a ransomware malware that encrypts files on the victim's system and demands a ransom for decryption.
StreamEx rat
StreamEx is a malware family that has been used by Deep Panda since at least 2015.
Streamer ransomware
Streamer is a ransomware family known for encrypting files on infected systems and demanding ransom payments in cryptocurrency.
StrelaStealer credential-stealer
StrelaStealer is an information stealer malware variant first identified in November 2022 and active through late 2024.
Stresspaint credential-stealer
Stresspaint is a credential-stealing malware specifically targeting social media accounts.
Strictor ransomware
Strictor is a ransomware variant based on the EDA2 platform.
StrifeWater rat
StrifeWater is a remote-access tool that has been used by Moses Staff in the initial stages of their attacks since at least November 2021.
StrifeWater RAT rat
StrifeWater RAT is a remote access trojan used primarily for cyber espionage activities.
StrikeSuit Gift rat
StrikeSuit Gift is a Remote Access Trojan (RAT) primarily used for cyber espionage against government and defense targets.
Striked ransomware
Striked is a ransomware that targets specific industries to encrypt files and demand ransom payments.
Stroman ransomware
Stroman is a ransomware family known for targeting various sectors including healthcare, finance, and government.
StrongPity spywarecredential-stealer
StrongPity is an information stealing malware used by PROMETHIUM.
Stupid ransomware
Stupid ransomware is a type of malicious software designed to encrypt files on an infected system, demanding payment for decryption keys.
StupidJapan ransomware
StupidJapan is a ransomware variant that primarily targets organizations within Japan.
Sturnus trojancredential-stealerscreen-capture
According to ThreatFabric, Sturnus is a privately operated Android banking trojan.
Stuxnet
Stuxnet was the first publicly reported piece of malware to specifically target industrial control systems devices.
Stuxnet wormrootkitexploit-kit
Also known as W32.Stuxnet. Stuxnet was the first publicly reported malware to specifically target industrial control systems devices.
Styver ransomware
Styver is a ransomware that encrypts files on compromised systems and demands a ransom for decryption.
Styx ransomware
Styx is a ransomware family known for targeting critical industries such as financial services, healthcare, and technology.
Sub7 trojanratkeylogger
Also known as SubSeven, Sub7Server. Sub7, or SubSeven or Sub7Server, is a Trojan horse program.[1] Its name was derived by spelling NetBus backwards ("suBteN") and swapping…
Subzero trojanspyware
Also known as Corelump, Jumplump. Subzero is a sophisticated malware family identified for its espionage capabilities, often used to gather sensitive information.
SuchSecurity Ransomware ransomware
Also known as Such Security. This is most likely to affect English speaking users, since the note is written in English.
Such_Crypt ransomware
Such_Crypt is a ransomware family known for encrypting victim files and demanding a ransom for decryption.
SunCrypt ransomware
Also known as Sun. SunCrypt ransomware was discovered in October 2019 and in August 2020 it was added to Maze ransomware’s cartel.
SunOrcal rat
SunOrcal is a Remote Access Trojan (RAT) used primarily for cyber espionage activities targeting government and technology sectors.
SunSeed trojan
According to Proofpoint, this is a Lua-based malware likely used by a nation-state sponsored attacker used to target European government…