Malware Families page 49 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Tarrask backdoor
Tarrask is malware that has been used by HAFNIUM since at least August 2021.
Tarsip backdoor
Tarsip is a backdoor malware known to be used in cyber espionage campaigns primarily targeting government and technology sectors.
Tasklist
The Tasklist utility displays a list of applications and services with their Process IDs (PID) for all tasks running on either a local or…
Tater PrivEsc exploit-kit
Tater PrivEsc is an exploit kit used for privilege escalation on Windows systems.
Taurus Stealer credential-stealer
According to Zscaler, Taurus is a stealer that surfaced in June 2020.
TeamPCP Cloud Stealer
Also known as SANDCLOCK. The TeamPCP Cloud Stealer is a comprehensive filesystem credential stealer that can harvest, encrypt, and exfiltrate credentials from over…
TeamSpy ratspyware
Also known as TVRAT, TVSPY, TeamViewerENT. TeamSpy, also known as TVRAT or TeamViewerENT, is a remote access tool (RAT) that leverages TeamViewer to gain unauthorized access and…
TeamTNT cryptominer
Since Fall 2019, Team TNT is a well known threat actor which targets *nix based systems and misconfigured Docker container environments.
TeamViewer
TeamViewer is a proprietary computer software package for remote control, desktop sharing, online meetings, web conferencing and file…
TeamXrat ransomware
TeamXrat is a ransomware strain known for targeting critical sectors, demanding ransom from victims through encryption of files.
Teamo ransomware
Teamo is a type of ransomware that encrypts files on infected machines, demanding a ransom payment for file decryption.
Tear Dr0p ransomware
Tear Dr0p is a form of ransomware that targets various industries by encrypting files and demanding ransom for decryption.
TechandStrat ransomware
TechandStrat is a type of ransomware that encrypts a victim's files and demands payment for the decryption key.
Technicy ransomware
Technicy is a ransomware threat that encrypts victim files, demanding payment for the decryption key.
TefoSteal credential-stealer
TefoSteal is a credential-stealing malware designed to exfiltrate sensitive data, including login credentials and personal information.
TelAndExt credential-stealerspyware
According to Check Point, this is a Telegram-focused infostealer (FTP / Delphi) used to target Iranian expats and dissidents.
TelB credential-stealerspywaretrojan
According to Check Point, this is a Telegram-focused infostealer (SOAP / Delphi) used to target Iranian expats and dissidents.
TeleBot trojan
TeleBot is an Android trojan that uses Telegram's bot API for command and control operations.
TeleDoor backdoorrat
TeleDoor is a remote access trojan (RAT) known for providing attackers with a backdoor into compromised systems.
TeleGrab credential-stealer
The first version stole browser credentials and cookies, along with all text files it can find on the system.
TelePowerBot botnet
TelePowerBot is known to facilitate cyberespionage activities, primarily targeting government and critical infrastructure sectors.
TeleRAT rat
TeleRAT is a remote access Trojan (RAT) primarily targeting Android devices, allowing attackers to control infected devices and access…
Telecrypt Ransomware ransomware
This is most likely to affect Russian speaking users, since the note is written in Russian.
TelegramGrabber credential-stealer
TelegramGrabber is a credential-stealing malware that focuses on exfiltrating account credentials from Telegram.
Telemiris backdoor
Telemiris is a sophisticated backdoor malware associated with state-sponsored cyber-espionage activities.
Teleport
Cisco Talos reports that this is a data exfiltration tool used by TA505.
Tellyouthepass ransomware
Tellyouthepass is a ransomware that alters system files, registry entries and encodes personal photos, documents, and servers or archives.
TempStealer credential-stealertrojan
According to Cyble, this is a stealer targeting several crypto currency wallets along browser data.
Tempedreve rat
Tempedreve is a remote access trojan predominantly used for espionage purposes.
TemptingCedar Spyware spyware
Tempting cedar spyware is an Android spyware campaign, active since at least 2015, that used social engineering via fake, attractive…
Tendyron trojan
Tendyron is a trojan commonly associated with targeting financial services.
Tenzor credential-stealer
According to Gen, this is a potential internal test build that marks the transition of Lumma Stealer to a 64 bit version.
Tequila Bandita trojan
Tequila Bandita is a trojan malware known for its malicious activities, including data exfiltration and system compromise.
Terminator RAT rat
Also known as Fakem RAT. Terminator RAT, also known as Fakem RAT, is a remote access tool used primarily for cyber espionage.
Termite Ransomware ransomware
Ben Hunter discovered a new ransomware called Termite Ransomware.
TerraLoader loader
TerraLoader is a malware loader that focuses on deploying additional payloads to compromised systems.
TerraPreter backdoorrat
TerraPreter is a sophisticated remote access tool used by threat actors to gain unauthorized access to targeted networks.
TerraRecon loader
Also known as Taurus Loader Reconnaissance Module. According to QuoINT TerraRecon is a reconnaissance tool, looking for a specific piece of hardware and software targeting retail and…
TerraStealer credential-stealerloader
Also known as SONE, StealerOne, Taurus Loader Stealer Module. According to QuoINT, TerraStealer (also known as SONE or StealerOne) is a generic reconnaissance tool, targeting for example email…
TerraTV loader
Also known as Taurus Loader TeamViewer Module. TerraTV is a custom DLL designed to hijack legit TeamViewer applications.
Terralogger keylogger
TerraLogger is a standalone keylogger malware developed by Golden Chickens, a financially motivated threat actor.
TeslaCrypt ransomware
Also known as cryptesla. According to Kaspersky, detected in February 2015, the new ransomware Trojan gained immediate notoriety as a menace to computer gamers.
TeslaCrypt 0.x - 2.2.0 ransomware
Also known as AlphaCrypt. TeslaCrypt is a ransomware family that emerged in early 2015, known for encrypting files of various types including game saves and other…
TeslaCrypt 3.0+ ransomware
TeslaCrypt 3.0+ is a ransomware variant that encrypts files on the victim's system and demands payment in cryptocurrency for decryption.
TeslaCrypt 4.1A ransomware
TeslaCrypt 4.1A is a variant of the TeslaCrypt ransomware family, known for encrypting files on the infected system and demanding ransom…
TeslaCrypt 4.2 ransomware
TeslaCrypt 4.2 is a variant of the TeslaCrypt ransomware family known for encrypting files and demanding a ransom in cryptocurrency for…
TeslaWare ransomware
TeslaWare is a ransomware that encrypts user files and demands a ransom for decryption.
Tetra Loader loader
According to Cisco Talos, this is loader is written in Rust and was observed to stage Cobalt Strike Beacons and VShell.
TgToxic trojancredential-stealer
According to Trend Micro, TgToxic has been used in an ongoing campaign that has been targeting Android users in Southeast Asia since July…
Thanatos ransomware
Also known as Alphabot. first ransomware seen to ask for payment to be made in Bitcoin Cash (BCH)
Thanatos Ransomware ransomware
Thanatos Ransomware is a malware strain that encrypts files on the infected system and demands a ransom payment in cryptocurrency.
Thanksgiving Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
The Brotherhood ransomware
The Brotherhood is a ransomware family known for targeting a variety of industries, including healthcare, financial services, and the…
The Magic ransomware
The Magic is a ransomware family known for encrypting victims' files and demanding ransom payments.
TheCursedMurderer ransomware
TheCursedMurderer is a ransomware known for encrypting files and demanding ransom from victims across various industries.
TheDarkEncryptor ransomware
TheDarkEncryptor is a ransomware that encrypts files on infected systems and demands a ransom payment for decryption.
TheFat RAT ratbackdoor
Thefatrat a massive exploiting tool revealed >> An easy tool to generate backdoor and easy tool to post exploitation attack like browser…
TheMoon wormbotnet
TheMoon is a self-replicating malware primarily targeting Internet of Things (IoT) devices, such as routers.
TheOneSpy spyware
Remotely monitor and control any wrong activity of kids on all smartphones & computers
Theef trojancredential-stealer
Theef is a credential-stealing trojan known for targeting financial services and other industries.
ThemeForestRAT rat
Also known as TALLSHIP. ThemeForestRAT, also known as TALLSHIP, is a Remote Access Trojan (RAT) primarily used for cyber espionage activities against technology…
ThiefBot credential-stealer
ThiefBot is a sophisticated credential-stealing malware primarily targeting financial industries.
ThiefQuest viruswipertrojan
Also known as MacRansom.K, EvilQuest. ThiefQuest is a virus, data stealer, and wiper that presents itself as ransomware targeting macOS systems.
ThinMon rat
ThinMon is a remote access trojan (RAT) known for targeting government and financial sectors.
Thor ransomware
Thor ransomware encrypts files on the infected system and demands a ransom for decryption keys.
Threat Finder ransomware
Threat Finder is a ransomware with a graphical user interface.
ThreatNeedle backdoor
ThreatNeedle is a backdoor that has been used by Lazarus Group since at least 2019 to target cryptocurrency, defense, and mobile gaming…
ThreeByte backdoorrat
ThreeByte is a backdoor remote access trojan (RAT) primarily used for espionage activities.
ThumbThief credential-stealertrojan
ThumbThief is a credential-stealing trojan designed to target government and financial sectors.
ThunderCrypt ransomware
ThunderCrypt is a type of ransomware that encrypts files on a victim's computer and demands a ransom for decryption.
ThunderShell ratbackdoor
ThunderShell is a remote access tool (RAT) primarily used for cyber espionage.
ThunderX ransomware
Also known as Ranzy Locker. ThunderX, also known as Ranzy Locker, is a strain of ransomware that targets organizations in various sectors.
Thunker rattrojan
Thunker is a remote access trojan (RAT) often used to target financial services and government sectors.
TianySpy credential-stealerspyware
TianySpy is a mobile malware primarily spread by SMS phishing between September 30 and October 12, 2021.
Tidepool backdoorrat
Tidepool is a sophisticated remote access trojan (RAT) commonly used for cyber espionage activities.
Tiger RAT backdoorrat
This is third stage backdoor mentioned in the Kaspersky blog, "Andariel evolves to target South Korea with ransomware".
TigerLite downloaderrat
TigerLite is a TCP downloader. It creates mutexes like "qtrgads32" or "Microsoft32". It uses RC4 with the key…
Tiktok Pro spyware
Tiktok Pro is spyware that has been masquerading as the TikTok application.
TimbreStealer credential-stealer
TimbreStealer is a credential-stealing malware that targets various industries, primarily aiming to extract sensitive information such as…
Tinba trojancredential-stealer
Also known as Illi, TinyBanker, Zusy. F-Secure notes that TinyBanker or short Tinba is usually distributed through malvertising (advertising content that leads the user to…
TinyFluff dropperrat
TinyFluff is a dropper developed by the OldGremlin group.
TinyLoader loader
TinyLoader is a malware loader used to deliver various types of malicious payloads.
TinyMet rat
Also known as TiniMet. TinyMet is a lightweight meterpreter stager, often used for establishing remote access on compromised systems.
TinyNuke trojancredential-stealer
Also known as MicroBankingTrojan, Nuclear Bot, NukeBot. TinyNuke (aka Nuclear Bot) is a fully-fledged banking trojan including HiddenDesktop/VNC server and a reverse socks4 server.
TinyTurla backdoor
TinyTurla is a backdoor that has been used by Turla against targets in the US, Germany, and Afghanistan since at least 2020.
TinyTurlaNG backdoor
Also known as TTNG. Cisco Talos states that TinyTurla-NG is a small “last chance” backdoor that is left behind to be used when all other unauthorized…
TinyZ botnettrojan
Also known as Catelites Android Bot, MarsElite Android Bot. TinyZ, also known as Catelites and MarsElite Android Bot, is a mobile malware family that primarily targets Android devices.
TinyZBot botnet
TinyZBot is a bot written in C# that was developed by Cleaver.
Tiop backdoortrojan
Tiop is a sophisticated malware backdoor known for its stealth and targeted attacks primarily against government and healthcare sectors.
Titan rat
Titan is an advanced remote access tool (RAT) used primarily for cyber espionage.
TitanStealer credential-stealerscreen-capturespyware
The stealer is written in Go and capable of stealing a variety of information from infected Windows machines, including credential data…
Tk ransomware
Tk is a notorious ransomware known for encrypting data on infected systems and demanding a ransom payment for decryption.
Tmanger backdoorrat
Also known as LuckyBack. Tmanger, also known as LuckyBack, is a remote access trojan that provides backdoor access to compromised systems.
Tofsee trojanbotnetcredential-stealer
Also known as Gheg. According to PCrisk, Tofsee (also known as Gheg) is a malicious Trojan-type program that is capable of performing DDoS attacks, mining…
TokyoX rat
TokyoX is a remote access trojan primarily focused on targeting governmental and technology sectors in Japan.
TomNom ransomware
TomNom is a ransomware that encrypts files on infected systems and demands a ransom for their decryption.
Tomiris backdoor
Tomiris is a backdoor written in Go that continuously queries its C2 server for executables to download and execute on a victim system.
Tonnerre rat
Tonnerre is a remote access trojan (RAT) primarily targeting entities in France and Belgium.
Topinambour downloaderspyware
Topinambour is a malware family predominantly used by APT28 for cyber espionage activities.
Toquito Bandito trojancredential-stealer
Toquito Bandito is a malicious software primarily known for targeting credentials within financial institutions and retail environments.