Malware Families page 49 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Tarrask backdoor
- Tarrask is malware that has been used by HAFNIUM since at least August 2021.
- Tarsip backdoor
- Tarsip is a backdoor malware known to be used in cyber espionage campaigns primarily targeting government and technology sectors.
- Tasklist
- The Tasklist utility displays a list of applications and services with their Process IDs (PID) for all tasks running on either a local or…
- Tater PrivEsc exploit-kit
- Tater PrivEsc is an exploit kit used for privilege escalation on Windows systems.
- Taurus Stealer credential-stealer
- According to Zscaler, Taurus is a stealer that surfaced in June 2020.
- TeamPCP Cloud Stealer
- Also known as SANDCLOCK. The TeamPCP Cloud Stealer is a comprehensive filesystem credential stealer that can harvest, encrypt, and exfiltrate credentials from over…
- TeamSpy ratspyware
- Also known as TVRAT, TVSPY, TeamViewerENT. TeamSpy, also known as TVRAT or TeamViewerENT, is a remote access tool (RAT) that leverages TeamViewer to gain unauthorized access and…
- TeamTNT cryptominer
- Since Fall 2019, Team TNT is a well known threat actor which targets *nix based systems and misconfigured Docker container environments.
- TeamViewer
- TeamViewer is a proprietary computer software package for remote control, desktop sharing, online meetings, web conferencing and file…
- TeamXrat ransomware
- TeamXrat is a ransomware strain known for targeting critical sectors, demanding ransom from victims through encryption of files.
- Teamo ransomware
- Teamo is a type of ransomware that encrypts files on infected machines, demanding a ransom payment for file decryption.
- Tear Dr0p ransomware
- Tear Dr0p is a form of ransomware that targets various industries by encrypting files and demanding ransom for decryption.
- TechandStrat ransomware
- TechandStrat is a type of ransomware that encrypts a victim's files and demands payment for the decryption key.
- Technicy ransomware
- Technicy is a ransomware threat that encrypts victim files, demanding payment for the decryption key.
- TefoSteal credential-stealer
- TefoSteal is a credential-stealing malware designed to exfiltrate sensitive data, including login credentials and personal information.
- TelAndExt credential-stealerspyware
- According to Check Point, this is a Telegram-focused infostealer (FTP / Delphi) used to target Iranian expats and dissidents.
- TelB credential-stealerspywaretrojan
- According to Check Point, this is a Telegram-focused infostealer (SOAP / Delphi) used to target Iranian expats and dissidents.
- TeleBot trojan
- TeleBot is an Android trojan that uses Telegram's bot API for command and control operations.
- TeleDoor backdoorrat
- TeleDoor is a remote access trojan (RAT) known for providing attackers with a backdoor into compromised systems.
- TeleGrab credential-stealer
- The first version stole browser credentials and cookies, along with all text files it can find on the system.
- TelePowerBot botnet
- TelePowerBot is known to facilitate cyberespionage activities, primarily targeting government and critical infrastructure sectors.
- TeleRAT rat
- TeleRAT is a remote access Trojan (RAT) primarily targeting Android devices, allowing attackers to control infected devices and access…
- Telecrypt Ransomware ransomware
- This is most likely to affect Russian speaking users, since the note is written in Russian.
- TelegramGrabber credential-stealer
- TelegramGrabber is a credential-stealing malware that focuses on exfiltrating account credentials from Telegram.
- Telemiris backdoor
- Telemiris is a sophisticated backdoor malware associated with state-sponsored cyber-espionage activities.
- Teleport
- Cisco Talos reports that this is a data exfiltration tool used by TA505.
- Tellyouthepass ransomware
- Tellyouthepass is a ransomware that alters system files, registry entries and encodes personal photos, documents, and servers or archives.
- TempStealer credential-stealertrojan
- According to Cyble, this is a stealer targeting several crypto currency wallets along browser data.
- Tempedreve rat
- Tempedreve is a remote access trojan predominantly used for espionage purposes.
- TemptingCedar Spyware spyware
- Tempting cedar spyware is an Android spyware campaign, active since at least 2015, that used social engineering via fake, attractive…
- Tendyron trojan
- Tendyron is a trojan commonly associated with targeting financial services.
- Tenzor credential-stealer
- According to Gen, this is a potential internal test build that marks the transition of Lumma Stealer to a 64 bit version.
- Tequila Bandita trojan
- Tequila Bandita is a trojan malware known for its malicious activities, including data exfiltration and system compromise.
- Terminator RAT rat
- Also known as Fakem RAT. Terminator RAT, also known as Fakem RAT, is a remote access tool used primarily for cyber espionage.
- Termite Ransomware ransomware
- Ben Hunter discovered a new ransomware called Termite Ransomware.
- TerraLoader loader
- TerraLoader is a malware loader that focuses on deploying additional payloads to compromised systems.
- TerraPreter backdoorrat
- TerraPreter is a sophisticated remote access tool used by threat actors to gain unauthorized access to targeted networks.
- TerraRecon loader
- Also known as Taurus Loader Reconnaissance Module. According to QuoINT TerraRecon is a reconnaissance tool, looking for a specific piece of hardware and software targeting retail and…
- TerraStealer credential-stealerloader
- Also known as SONE, StealerOne, Taurus Loader Stealer Module. According to QuoINT, TerraStealer (also known as SONE or StealerOne) is a generic reconnaissance tool, targeting for example email…
- TerraTV loader
- Also known as Taurus Loader TeamViewer Module. TerraTV is a custom DLL designed to hijack legit TeamViewer applications.
- Terralogger keylogger
- TerraLogger is a standalone keylogger malware developed by Golden Chickens, a financially motivated threat actor.
- TeslaCrypt ransomware
- Also known as cryptesla. According to Kaspersky, detected in February 2015, the new ransomware Trojan gained immediate notoriety as a menace to computer gamers.
- TeslaCrypt 0.x - 2.2.0 ransomware
- Also known as AlphaCrypt. TeslaCrypt is a ransomware family that emerged in early 2015, known for encrypting files of various types including game saves and other…
- TeslaCrypt 3.0+ ransomware
- TeslaCrypt 3.0+ is a ransomware variant that encrypts files on the victim's system and demands payment in cryptocurrency for decryption.
- TeslaCrypt 4.1A ransomware
- TeslaCrypt 4.1A is a variant of the TeslaCrypt ransomware family, known for encrypting files on the infected system and demanding ransom…
- TeslaCrypt 4.2 ransomware
- TeslaCrypt 4.2 is a variant of the TeslaCrypt ransomware family known for encrypting files and demanding a ransom in cryptocurrency for…
- TeslaWare ransomware
- TeslaWare is a ransomware that encrypts user files and demands a ransom for decryption.
- Tetra Loader loader
- According to Cisco Talos, this is loader is written in Rust and was observed to stage Cobalt Strike Beacons and VShell.
- TgToxic trojancredential-stealer
- According to Trend Micro, TgToxic has been used in an ongoing campaign that has been targeting Android users in Southeast Asia since July…
- Thanatos ransomware
- Also known as Alphabot. first ransomware seen to ask for payment to be made in Bitcoin Cash (BCH)
- Thanatos Ransomware ransomware
- Thanatos Ransomware is a malware strain that encrypts files on the infected system and demands a ransom payment in cryptocurrency.
- Thanksgiving Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- The Brotherhood ransomware
- The Brotherhood is a ransomware family known for targeting a variety of industries, including healthcare, financial services, and the…
- The Magic ransomware
- The Magic is a ransomware family known for encrypting victims' files and demanding ransom payments.
- TheCursedMurderer ransomware
- TheCursedMurderer is a ransomware known for encrypting files and demanding ransom from victims across various industries.
- TheDarkEncryptor ransomware
- TheDarkEncryptor is a ransomware that encrypts files on infected systems and demands a ransom payment for decryption.
- TheFat RAT ratbackdoor
- Thefatrat a massive exploiting tool revealed >> An easy tool to generate backdoor and easy tool to post exploitation attack like browser…
- TheMoon wormbotnet
- TheMoon is a self-replicating malware primarily targeting Internet of Things (IoT) devices, such as routers.
- TheOneSpy spyware
- Remotely monitor and control any wrong activity of kids on all smartphones & computers
- Theef trojancredential-stealer
- Theef is a credential-stealing trojan known for targeting financial services and other industries.
- ThemeForestRAT rat
- Also known as TALLSHIP. ThemeForestRAT, also known as TALLSHIP, is a Remote Access Trojan (RAT) primarily used for cyber espionage activities against technology…
- ThiefBot credential-stealer
- ThiefBot is a sophisticated credential-stealing malware primarily targeting financial industries.
- ThiefQuest viruswipertrojan
- Also known as MacRansom.K, EvilQuest. ThiefQuest is a virus, data stealer, and wiper that presents itself as ransomware targeting macOS systems.
- ThinMon rat
- ThinMon is a remote access trojan (RAT) known for targeting government and financial sectors.
- Thor ransomware
- Thor ransomware encrypts files on the infected system and demands a ransom for decryption keys.
- Threat Finder ransomware
- Threat Finder is a ransomware with a graphical user interface.
- ThreatNeedle backdoor
- ThreatNeedle is a backdoor that has been used by Lazarus Group since at least 2019 to target cryptocurrency, defense, and mobile gaming…
- ThreeByte backdoorrat
- ThreeByte is a backdoor remote access trojan (RAT) primarily used for espionage activities.
- ThumbThief credential-stealertrojan
- ThumbThief is a credential-stealing trojan designed to target government and financial sectors.
- ThunderCrypt ransomware
- ThunderCrypt is a type of ransomware that encrypts files on a victim's computer and demands a ransom for decryption.
- ThunderShell ratbackdoor
- ThunderShell is a remote access tool (RAT) primarily used for cyber espionage.
- ThunderX ransomware
- Also known as Ranzy Locker. ThunderX, also known as Ranzy Locker, is a strain of ransomware that targets organizations in various sectors.
- Thunker rattrojan
- Thunker is a remote access trojan (RAT) often used to target financial services and government sectors.
- TianySpy credential-stealerspyware
- TianySpy is a mobile malware primarily spread by SMS phishing between September 30 and October 12, 2021.
- Tidepool backdoorrat
- Tidepool is a sophisticated remote access trojan (RAT) commonly used for cyber espionage activities.
- Tiger RAT backdoorrat
- This is third stage backdoor mentioned in the Kaspersky blog, "Andariel evolves to target South Korea with ransomware".
- TigerLite downloaderrat
- TigerLite is a TCP downloader. It creates mutexes like "qtrgads32" or "Microsoft32". It uses RC4 with the key…
- Tiktok Pro spyware
- Tiktok Pro is spyware that has been masquerading as the TikTok application.
- TimbreStealer credential-stealer
- TimbreStealer is a credential-stealing malware that targets various industries, primarily aiming to extract sensitive information such as…
- Tinba trojancredential-stealer
- Also known as Illi, TinyBanker, Zusy. F-Secure notes that TinyBanker or short Tinba is usually distributed through malvertising (advertising content that leads the user to…
- TinyFluff dropperrat
- TinyFluff is a dropper developed by the OldGremlin group.
- TinyLoader loader
- TinyLoader is a malware loader used to deliver various types of malicious payloads.
- TinyMet rat
- Also known as TiniMet. TinyMet is a lightweight meterpreter stager, often used for establishing remote access on compromised systems.
- TinyNuke trojancredential-stealer
- Also known as MicroBankingTrojan, Nuclear Bot, NukeBot. TinyNuke (aka Nuclear Bot) is a fully-fledged banking trojan including HiddenDesktop/VNC server and a reverse socks4 server.
- TinyTurla backdoor
- TinyTurla is a backdoor that has been used by Turla against targets in the US, Germany, and Afghanistan since at least 2020.
- TinyTurlaNG backdoor
- Also known as TTNG. Cisco Talos states that TinyTurla-NG is a small “last chance” backdoor that is left behind to be used when all other unauthorized…
- TinyZ botnettrojan
- Also known as Catelites Android Bot, MarsElite Android Bot. TinyZ, also known as Catelites and MarsElite Android Bot, is a mobile malware family that primarily targets Android devices.
- TinyZBot botnet
- TinyZBot is a bot written in C# that was developed by Cleaver.
- Tiop backdoortrojan
- Tiop is a sophisticated malware backdoor known for its stealth and targeted attacks primarily against government and healthcare sectors.
- Titan rat
- Titan is an advanced remote access tool (RAT) used primarily for cyber espionage.
- TitanStealer credential-stealerscreen-capturespyware
- The stealer is written in Go and capable of stealing a variety of information from infected Windows machines, including credential data…
- Tk ransomware
- Tk is a notorious ransomware known for encrypting data on infected systems and demanding a ransom payment for decryption.
- Tmanger backdoorrat
- Also known as LuckyBack. Tmanger, also known as LuckyBack, is a remote access trojan that provides backdoor access to compromised systems.
- Tofsee trojanbotnetcredential-stealer
- Also known as Gheg. According to PCrisk, Tofsee (also known as Gheg) is a malicious Trojan-type program that is capable of performing DDoS attacks, mining…
- TokyoX rat
- TokyoX is a remote access trojan primarily focused on targeting governmental and technology sectors in Japan.
- TomNom ransomware
- TomNom is a ransomware that encrypts files on infected systems and demands a ransom for their decryption.
- Tomiris backdoor
- Tomiris is a backdoor written in Go that continuously queries its C2 server for executables to download and execute on a victim system.
- Tonnerre rat
- Tonnerre is a remote access trojan (RAT) primarily targeting entities in France and Belgium.
- Topinambour downloaderspyware
- Topinambour is a malware family predominantly used by APT28 for cyber espionage activities.
- Toquito Bandito trojancredential-stealer
- Toquito Bandito is a malicious software primarily known for targeting credentials within financial institutions and retail environments.