Malware Families page 48 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Sunbird spyware
Sunbird is one of two mobile malware families known to be used by the APT Confucius.
Sunless ransomwaretrojan
Sunless is a ransomware family known for targeting government and financial sectors with its dual capability of encryption and data…
SuperB ransomware
SuperB is a notable ransomware family that encrypts files on compromised systems, demanding payment for decryption keys.
SuperBear RAT rat
SuperBear RAT is a remote access tool used for cyber-espionage, primarily targeting government and technology sectors in the United…
SuperCrypt ransomware
SuperCrypt is a ransomware family known for encrypting victims' files and demanding ransom payments typically in cryptocurrency.
Supper backdoorrattrojan
Also known as SocksShell, ZAPCAT. Supper is a 64-bit Windows backdoor and tunnelling utility first observed in the wild in July 2024.
SuppoBox botnettrojan
Also known as Bayrob, Nivdort, pizd. SuppoBox, also known as Bayrob or Nivdort, is a malware family associated with cybercrime operations, often targeting financial…
SupremeBot botnetddos
Also known as BlazeBot. SupremeBot, also known as BlazeBot, is a malware family known for its botnet capabilities used in distributed denial-of-service (DDoS)…
SureRansom Ransomeware (Fake) ransomware
It’s directed to English speaking users, therefore is able to strike worldwide.
Suri ransomware
Suri is a type of ransomware designed to encrypt files and demand a ransom for their decryption.
Surprise ransomware
Surprise ransomware is based on the open-source EDA2 project.
Survey ransomware
Ransomware Still in development, shows FileIce survey
Suterusu rootkit
Also known as HCRootkit. Suterusu, also known as HCRootkit, is a Linux kernel rootkit known for its advanced stealth techniques, which can help attackers hide…
Svpeng credential-stealertrojan
Svpeng is a malicious banking trojan targeting Android devices, and it poses a significant threat to both mobile users and the developers…
SwaetRAT rat
SwaetRAT is a remote access tool used for cyber espionage.
SweetSpecter spywaretrojan
SweetSpecter is a sophisticated malware family primarily utilized for espionage purposes.
Swid ransomware
Swid is a type of ransomware that encrypts files on the infected system and demands a ransom payment from the victim.
SwiftSlicer wiper
Also known as JaguarBlade. According to ESET, this is a wiper written in Go, that was deployed against an Ukrainian organization on January 25th 2023 through Group…
Switcher trojan
Switcher is a form of Android malware that targets users in China by hijacking router DNS settings.
Sword trojan
Sword is a sophisticated malware family known for its use in espionage campaigns targeting the defense and government sectors.
Sword2033 backdoortrojan
Sword2033 is a sophisticated malware used in cyber-espionage campaigns, predominantly targeting government and defense sectors in specific…
Swrort Stager loadertrojan
Swrort Stager is a loader malware known for its role in delivering secondary payloads in targeted attacks.
Sykipot trojan
Also known as Wkysol, getkys. Sykipot is malware that has been used in spearphishing campaigns since approximately 2007 against victims primarily in the US.
Syla trojanspyware
Syla is a sophisticated malware family utilized primarily for cyber-espionage activities.
Symbiom ransomware
Symbiom is a ransomware strain known for encrypting sensitive data in targeted sectors, demanding a ransom for decryption keys.
Symbiote backdoorcredential-stealerrootkit
A malware capable of capturing credentials and enabling backdoor access, implemented as a userland rootkit.
SymmyWare ransomware
SymmyWare is a type of ransomware that encrypts files and demands a ransom for decryption.
SynAck ransomwaretrojan
Also known as Syn Ack. SynAck is variant of Trojan ransomware targeting mainly English-speaking users since at least fall 2017.
SynFlooder ddos
SynFlooder is a type of malware designed to launch SYN flood attacks, a kind of denial-of-service (DoS) attack that exploits the TCP…
Sync-Scheduler spywaretrojan
According to Cyfirma, Sync-Scheduler is a dedicated document stealer that targets Word documents, Excel Spreadsheets, PowerPoint…
SyncCrypt ransomware
A new ransomware called SyncCrypt was discovered by Emsisoft security researcher xXToffeeXx that is being distributed by spam attachments…
Syndrome RAT rat
Syndrome RAT is a remote access tool used for cyber espionage, targeting sectors like financial services, government, and technology.
SynoLocker ransomware
Ransomware Exploited Synology NAS firmware directly over WAN
Synth Loader loader
Synth Loader is a malware family known for enabling the distribution of various payloads.
Syrk ransomware
Syrk is a ransomware that disguises itself as a cheat tool for the game Fortnite.
Sys10 backdoor
Sys10 is a backdoor that was used throughout 2013 by Naikon.
SysGet rat
SysGet is a remote access trojan (RAT) used for cyber espionage activities.
SysJoker (ELF) backdoorratspyware
SysJoker is a cross-platform malware initially discovered in Linux environments.
SysJoker (OS X) backdoorrat
SysJoker is a multi-platform malware first discovered in early 2022, designed to provide backdoor access to compromised systems.
SysJoker (Windows) backdoor
Sysjoker is a backdoor malware that was first discovered in December 2021 by Intezer.
SysKit backdoorspyware
Also known as IvizTech, MANGOPUNCH. SysKit is an advanced spyware and backdoor malware used primarily for cyber-espionage.
SysScan
SysScan is a malware entity with currently limited public information available.
SysUpdate backdoorrat
Also known as HyperSSL, Soldier, FOCUSFJORD. SysUpdate is a backdoor written in C++ that has been used by Threat Group-3390 since at least 2020.
Sysraw Stealer credential-stealer
Also known as Clipsa. Sysraw stealer got its name because at some point, it was started as "ZSysRaw\sysraw.exe".
Sysrv-hello (ELF) botnetcryptominerworm
Also known as Sysrv. Sysrv-hello is a cryptojacking botnet that primarily targets Linux-based systems.
Sysrv-hello (Windows) cryptominer
Sysrv is a Golang written Cryptojacking malware.
SystemBC backdoordownloaderloader
Also known as Coroxy. SystemBC is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate…
SystemBC (ELF) backdoor
SystemBC is a proxy malware primarily used to facilitate other cyberattacks by establishing secure, encrypted communications with command…
SystemBC (Windows) downloadertrojan
Also known as Coroxy, DroxiDat. SystemBC is a multiplatform proxy malware active since August 2019.
SystemCrypter ransomware
SystemCrypter is a ransomware family known for encrypting files on victim machines and demanding payment.
Systeminfo
Systeminfo is a Windows utility that can be used to gather detailed information about a computer.
Szribi botnet
Also known as Srizbi. Srizbi, also known as Szribi, is a botnet malware family known for sending large volumes of spam emails.
T-Cmd rat
Also known as t_cmd. T-Cmd is a remote access tool that has been employed in cyber-espionage campaigns.
T-RAT 2.0 rat
T-RAT 2.0 is a remote access trojan known for its stealthy operations and capabilities to exfiltrate sensitive data from compromised…
T1Happy ransomware
T1Happy is a ransomware known for encrypting files on victim systems and demanding payment in cryptocurrency for decryption.
T34loader loader
T34loader is a loader malware that is used to deliver other malicious payloads onto compromised systems.
T9000 backdoor
T9000 is a backdoor that is a newer variant of the T5000 malware family, also known as Plat1.
TAINTEDSCRIBE rat
TAINTEDSCRIBE is a fully-featured beaconing implant integrated with command modules used by Lazarus Group.
TAMECAT rat
TAMECAT is a malware that is used by APT42 to execute PowerShell or C# content.
TBHRanso ransomware
TBHRanso is a ransomware strain designed to encrypt files on infected systems and demand ransom payments for decryption keys.
TClient rat
Also known as FIRESHADOW. Steve Miller pointed out that it is proxy-aware (Tencent) for C&C communication and uses wolfSSL, which makes it stick out.
TDTESS backdoor
TDTESS is a 64-bit .NET binary backdoor used by CopyKittens.
TEARDROP dropper
TEARDROP is a memory-only dropper that was discovered on some victim machines during investigations related to the SolarWinds Compromise.
TEMPLEDOOR rat
TEMPLEDOOR is a remote access tool primarily used for cyber-espionage, targeting governmental and financial sectors.
TERRACOTTA botnet
TERRACOTTA is an ad fraud botnet that has been capable of generating over 2 billion fraudulent requests per week.
TEXTMATE backdoor
Also known as DNSMessenger. TEXTMATE is a second-stage PowerShell backdoor that is memory-resident.
TFlower ransomware
TFlower is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
THINCRUST backdoor
THINCRUST is a Python-based backdoor tool that has been used by UNC3886 since at least 2023.
THT ransomware
THT is a ransomware family known for encrypting files and demanding ransom payments.
TINY rat
TINY is a set of programs that lets you control a DOS computer from any Java-capable machine over a TCP/IP connection.
TINYTYPHON backdoorworm
TINYTYPHON is a backdoor that has been used by the actors responsible for the MONSOON campaign.
TNTbotinger botnetloader
TNTbotinger is a botnet malware family known for its modular architecture and ability to perform DDoS attacks.
TOLLBOOTH webshell
Also known as HijackServer IIS. TOLLBOOTH, also known as HijackServer IIS, is a webshell deployed on IIS servers to enable unauthorized remote access and control.
TONEDEAF backdoor
TONEDEAF is a backdoor that communicates with Command and Control servers using HTTP or DNS.
TONERJAM backdoor
According to Symantec, Grager was deployed against three organizations in Taiwan, Hong Kong, and Vietnam in April 2024.
TONESHELL backdoor
TONESHELL is a custom backdoor that has been used since at least Q1 2021.
TOUCHMOVE backdoorrat
TOUCHMOVE is a sophisticated remote access tool used in cyber espionage campaigns.
TOUCHSHIFT trojanspywarerat
TOUCHSHIFT is a sophisticated trojan with capabilities to conduct cyber espionage.
TOUGHPROGRESS backdoorrat
Also known as Calendarwalk. According to Google Threat Intelligence Group, this malware uses Google Calendar events for command and control (C2).
TPS1.0 ransomware
TPS1.0 is a ransomware strain known for encrypting files on infected systems and demanding a ransom for decryption.
TRAILBLAZE dropper
TRAILBLAZE is an in-memory dropper used to deploy the passive backdoor BRUSHFIRE.
TRANSLATEXT spywaretrojan
TRANSLATEXT is malware that is believed to be used by Kimsuky.
TRITON
Also known as HatMan, TRISIS. This entry was deprecated as it was inadvertently added to Enterprise; a similar Software entry was created for ATT&CK for ICS.
TSCookie rat
TSCookie is a remote access tool (RAT) that has been used by BlackTech in campaigns against Japanese targets..
TSCookieRAT rat
TSCookie provides parameters such as C&C server information when loading TSCookieRAT.
TUNNELFISH ratbackdoor
TUNNELFISH is a remote access Trojan primarily used in targeted cyber espionage campaigns.
TURNEDUP backdoor
Also known as Notestuk. TURNEDUP is a non-public backdoor. It has been dropped by APT33's StoneDrill malware.
TYPEFRAME ratdownloader
TYPEFRAME is a remote access tool that has been used by Lazarus Group.
TYRANT ransomware
Also known as Crypto Tyrant. DUMB variant discovered on November 16, 2017.
TabMsgSQL trojan
TabMsgSQL is a trojan malware known for targeting financial services, retail, and technology sectors in multiple countries for data theft…
Taidoor rat
Also known as simbot. Taidoor is a remote access trojan (RAT) that has been used by Chinese government cyber actors to maintain access on victim networks.
TajMahal spyware
TajMahal is a multifunctional spying framework that has been in use since at least 2014.
Takahiro Locker ransomware
Takahiro Locker is a type of ransomware that encrypts files on an infected system and demands a ransom payment for the decryption key.
TalentRAT rat
Also known as Assassin RAT. TalentRAT, also known as Assassin RAT, is a remote access trojan often associated with cyber-espionage activities targeting government and…
Taleret rat
Taleret is a remote access tool (RAT) used for cyber espionage.
TamperedChef trojanbackdoor
TamperedChef is a sophisticated piece of malware that acts as both a trojan and a backdoor.
Tandfuy backdoorrat
Tandfuy is a backdoor and Remote Access Trojan (RAT) typically used in cyber-espionage campaigns against governmental and defense sectors.
Tangelo spyware
Tangelo is iOS malware that is believed to be from the same developers as the Stealth Mango Android malware.
TangleBot trojanspyware
TangleBot is SMS malware that was initially observed in September 2021, primarily targeting mobile users in the United States and Canada.
Tapaoux backdoor
Tapaoux is a backdoor malware linked to cyber espionage activities, primarily targeting government organizations.