Malware Families page 48 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Sunbird spyware
- Sunbird is one of two mobile malware families known to be used by the APT Confucius.
- Sunless ransomwaretrojan
- Sunless is a ransomware family known for targeting government and financial sectors with its dual capability of encryption and data…
- SuperB ransomware
- SuperB is a notable ransomware family that encrypts files on compromised systems, demanding payment for decryption keys.
- SuperBear RAT rat
- SuperBear RAT is a remote access tool used for cyber-espionage, primarily targeting government and technology sectors in the United…
- SuperCrypt ransomware
- SuperCrypt is a ransomware family known for encrypting victims' files and demanding ransom payments typically in cryptocurrency.
- Supper backdoorrattrojan
- Also known as SocksShell, ZAPCAT. Supper is a 64-bit Windows backdoor and tunnelling utility first observed in the wild in July 2024.
- SuppoBox botnettrojan
- Also known as Bayrob, Nivdort, pizd. SuppoBox, also known as Bayrob or Nivdort, is a malware family associated with cybercrime operations, often targeting financial…
- SupremeBot botnetddos
- Also known as BlazeBot. SupremeBot, also known as BlazeBot, is a malware family known for its botnet capabilities used in distributed denial-of-service (DDoS)…
- SureRansom Ransomeware (Fake) ransomware
- It’s directed to English speaking users, therefore is able to strike worldwide.
- Suri ransomware
- Suri is a type of ransomware designed to encrypt files and demand a ransom for their decryption.
- Surprise ransomware
- Surprise ransomware is based on the open-source EDA2 project.
- Survey ransomware
- Ransomware Still in development, shows FileIce survey
- Suterusu rootkit
- Also known as HCRootkit. Suterusu, also known as HCRootkit, is a Linux kernel rootkit known for its advanced stealth techniques, which can help attackers hide…
- Svpeng credential-stealertrojan
- Svpeng is a malicious banking trojan targeting Android devices, and it poses a significant threat to both mobile users and the developers…
- SwaetRAT rat
- SwaetRAT is a remote access tool used for cyber espionage.
- SweetSpecter spywaretrojan
- SweetSpecter is a sophisticated malware family primarily utilized for espionage purposes.
- Swid ransomware
- Swid is a type of ransomware that encrypts files on the infected system and demands a ransom payment from the victim.
- SwiftSlicer wiper
- Also known as JaguarBlade. According to ESET, this is a wiper written in Go, that was deployed against an Ukrainian organization on January 25th 2023 through Group…
- Switcher trojan
- Switcher is a form of Android malware that targets users in China by hijacking router DNS settings.
- Sword trojan
- Sword is a sophisticated malware family known for its use in espionage campaigns targeting the defense and government sectors.
- Sword2033 backdoortrojan
- Sword2033 is a sophisticated malware used in cyber-espionage campaigns, predominantly targeting government and defense sectors in specific…
- Swrort Stager loadertrojan
- Swrort Stager is a loader malware known for its role in delivering secondary payloads in targeted attacks.
- Sykipot trojan
- Also known as Wkysol, getkys. Sykipot is malware that has been used in spearphishing campaigns since approximately 2007 against victims primarily in the US.
- Syla trojanspyware
- Syla is a sophisticated malware family utilized primarily for cyber-espionage activities.
- Symbiom ransomware
- Symbiom is a ransomware strain known for encrypting sensitive data in targeted sectors, demanding a ransom for decryption keys.
- Symbiote backdoorcredential-stealerrootkit
- A malware capable of capturing credentials and enabling backdoor access, implemented as a userland rootkit.
- SymmyWare ransomware
- SymmyWare is a type of ransomware that encrypts files and demands a ransom for decryption.
- SynAck ransomwaretrojan
- Also known as Syn Ack. SynAck is variant of Trojan ransomware targeting mainly English-speaking users since at least fall 2017.
- SynFlooder ddos
- SynFlooder is a type of malware designed to launch SYN flood attacks, a kind of denial-of-service (DoS) attack that exploits the TCP…
- Sync-Scheduler spywaretrojan
- According to Cyfirma, Sync-Scheduler is a dedicated document stealer that targets Word documents, Excel Spreadsheets, PowerPoint…
- SyncCrypt ransomware
- A new ransomware called SyncCrypt was discovered by Emsisoft security researcher xXToffeeXx that is being distributed by spam attachments…
- Syndrome RAT rat
- Syndrome RAT is a remote access tool used for cyber espionage, targeting sectors like financial services, government, and technology.
- SynoLocker ransomware
- Ransomware Exploited Synology NAS firmware directly over WAN
- Synth Loader loader
- Synth Loader is a malware family known for enabling the distribution of various payloads.
- Syrk ransomware
- Syrk is a ransomware that disguises itself as a cheat tool for the game Fortnite.
- Sys10 backdoor
- Sys10 is a backdoor that was used throughout 2013 by Naikon.
- SysGet rat
- SysGet is a remote access trojan (RAT) used for cyber espionage activities.
- SysJoker (ELF) backdoorratspyware
- SysJoker is a cross-platform malware initially discovered in Linux environments.
- SysJoker (OS X) backdoorrat
- SysJoker is a multi-platform malware first discovered in early 2022, designed to provide backdoor access to compromised systems.
- SysJoker (Windows) backdoor
- Sysjoker is a backdoor malware that was first discovered in December 2021 by Intezer.
- SysKit backdoorspyware
- Also known as IvizTech, MANGOPUNCH. SysKit is an advanced spyware and backdoor malware used primarily for cyber-espionage.
- SysScan
- SysScan is a malware entity with currently limited public information available.
- SysUpdate backdoorrat
- Also known as HyperSSL, Soldier, FOCUSFJORD. SysUpdate is a backdoor written in C++ that has been used by Threat Group-3390 since at least 2020.
- Sysraw Stealer credential-stealer
- Also known as Clipsa. Sysraw stealer got its name because at some point, it was started as "ZSysRaw\sysraw.exe".
- Sysrv-hello (ELF) botnetcryptominerworm
- Also known as Sysrv. Sysrv-hello is a cryptojacking botnet that primarily targets Linux-based systems.
- Sysrv-hello (Windows) cryptominer
- Sysrv is a Golang written Cryptojacking malware.
- SystemBC backdoordownloaderloader
- Also known as Coroxy. SystemBC is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate…
- SystemBC (ELF) backdoor
- SystemBC is a proxy malware primarily used to facilitate other cyberattacks by establishing secure, encrypted communications with command…
- SystemBC (Windows) downloadertrojan
- Also known as Coroxy, DroxiDat. SystemBC is a multiplatform proxy malware active since August 2019.
- SystemCrypter ransomware
- SystemCrypter is a ransomware family known for encrypting files on victim machines and demanding payment.
- Systeminfo
- Systeminfo is a Windows utility that can be used to gather detailed information about a computer.
- Szribi botnet
- Also known as Srizbi. Srizbi, also known as Szribi, is a botnet malware family known for sending large volumes of spam emails.
- T-Cmd rat
- Also known as t_cmd. T-Cmd is a remote access tool that has been employed in cyber-espionage campaigns.
- T-RAT 2.0 rat
- T-RAT 2.0 is a remote access trojan known for its stealthy operations and capabilities to exfiltrate sensitive data from compromised…
- T1Happy ransomware
- T1Happy is a ransomware known for encrypting files on victim systems and demanding payment in cryptocurrency for decryption.
- T34loader loader
- T34loader is a loader malware that is used to deliver other malicious payloads onto compromised systems.
- T9000 backdoor
- T9000 is a backdoor that is a newer variant of the T5000 malware family, also known as Plat1.
- TAINTEDSCRIBE rat
- TAINTEDSCRIBE is a fully-featured beaconing implant integrated with command modules used by Lazarus Group.
- TAMECAT rat
- TAMECAT is a malware that is used by APT42 to execute PowerShell or C# content.
- TBHRanso ransomware
- TBHRanso is a ransomware strain designed to encrypt files on infected systems and demand ransom payments for decryption keys.
- TClient rat
- Also known as FIRESHADOW. Steve Miller pointed out that it is proxy-aware (Tencent) for C&C communication and uses wolfSSL, which makes it stick out.
- TDTESS backdoor
- TDTESS is a 64-bit .NET binary backdoor used by CopyKittens.
- TEARDROP dropper
- TEARDROP is a memory-only dropper that was discovered on some victim machines during investigations related to the SolarWinds Compromise.
- TEMPLEDOOR rat
- TEMPLEDOOR is a remote access tool primarily used for cyber-espionage, targeting governmental and financial sectors.
- TERRACOTTA botnet
- TERRACOTTA is an ad fraud botnet that has been capable of generating over 2 billion fraudulent requests per week.
- TEXTMATE backdoor
- Also known as DNSMessenger. TEXTMATE is a second-stage PowerShell backdoor that is memory-resident.
- TFlower ransomware
- TFlower is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
- THINCRUST backdoor
- THINCRUST is a Python-based backdoor tool that has been used by UNC3886 since at least 2023.
- THT ransomware
- THT is a ransomware family known for encrypting files and demanding ransom payments.
- TINY rat
- TINY is a set of programs that lets you control a DOS computer from any Java-capable machine over a TCP/IP connection.
- TINYTYPHON backdoorworm
- TINYTYPHON is a backdoor that has been used by the actors responsible for the MONSOON campaign.
- TNTbotinger botnetloader
- TNTbotinger is a botnet malware family known for its modular architecture and ability to perform DDoS attacks.
- TOLLBOOTH webshell
- Also known as HijackServer IIS. TOLLBOOTH, also known as HijackServer IIS, is a webshell deployed on IIS servers to enable unauthorized remote access and control.
- TONEDEAF backdoor
- TONEDEAF is a backdoor that communicates with Command and Control servers using HTTP or DNS.
- TONERJAM backdoor
- According to Symantec, Grager was deployed against three organizations in Taiwan, Hong Kong, and Vietnam in April 2024.
- TONESHELL backdoor
- TONESHELL is a custom backdoor that has been used since at least Q1 2021.
- TOUCHMOVE backdoorrat
- TOUCHMOVE is a sophisticated remote access tool used in cyber espionage campaigns.
- TOUCHSHIFT trojanspywarerat
- TOUCHSHIFT is a sophisticated trojan with capabilities to conduct cyber espionage.
- TOUGHPROGRESS backdoorrat
- Also known as Calendarwalk. According to Google Threat Intelligence Group, this malware uses Google Calendar events for command and control (C2).
- TPS1.0 ransomware
- TPS1.0 is a ransomware strain known for encrypting files on infected systems and demanding a ransom for decryption.
- TRAILBLAZE dropper
- TRAILBLAZE is an in-memory dropper used to deploy the passive backdoor BRUSHFIRE.
- TRANSLATEXT spywaretrojan
- TRANSLATEXT is malware that is believed to be used by Kimsuky.
- TRITON
- Also known as HatMan, TRISIS. This entry was deprecated as it was inadvertently added to Enterprise; a similar Software entry was created for ATT&CK for ICS.
- TSCookie rat
- TSCookie is a remote access tool (RAT) that has been used by BlackTech in campaigns against Japanese targets..
- TSCookieRAT rat
- TSCookie provides parameters such as C&C server information when loading TSCookieRAT.
- TUNNELFISH ratbackdoor
- TUNNELFISH is a remote access Trojan primarily used in targeted cyber espionage campaigns.
- TURNEDUP backdoor
- Also known as Notestuk. TURNEDUP is a non-public backdoor. It has been dropped by APT33's StoneDrill malware.
- TYPEFRAME ratdownloader
- TYPEFRAME is a remote access tool that has been used by Lazarus Group.
- TYRANT ransomware
- Also known as Crypto Tyrant. DUMB variant discovered on November 16, 2017.
- TabMsgSQL trojan
- TabMsgSQL is a trojan malware known for targeting financial services, retail, and technology sectors in multiple countries for data theft…
- Taidoor rat
- Also known as simbot. Taidoor is a remote access trojan (RAT) that has been used by Chinese government cyber actors to maintain access on victim networks.
- TajMahal spyware
- TajMahal is a multifunctional spying framework that has been in use since at least 2014.
- Takahiro Locker ransomware
- Takahiro Locker is a type of ransomware that encrypts files on an infected system and demands a ransom payment for the decryption key.
- TalentRAT rat
- Also known as Assassin RAT. TalentRAT, also known as Assassin RAT, is a remote access trojan often associated with cyber-espionage activities targeting government and…
- Taleret rat
- Taleret is a remote access tool (RAT) used for cyber espionage.
- TamperedChef trojanbackdoor
- TamperedChef is a sophisticated piece of malware that acts as both a trojan and a backdoor.
- Tandfuy backdoorrat
- Tandfuy is a backdoor and Remote Access Trojan (RAT) typically used in cyber-espionage campaigns against governmental and defense sectors.
- Tangelo spyware
- Tangelo is iOS malware that is believed to be from the same developers as the Stealth Mango Android malware.
- TangleBot trojanspyware
- TangleBot is SMS malware that was initially observed in September 2021, primarily targeting mobile users in the United States and Canada.
- Tapaoux backdoor
- Tapaoux is a backdoor malware linked to cyber espionage activities, primarily targeting government organizations.