Malware Families page 5 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- BRICKSTORM backdoor
- BRICKSTORM is a cross-platform backdoor with variants written in Go and Rust that facilitates command and control, the ingress transfer of…
- BROKEYOLK downloader
- According to Mandiant, BROKEYOLK is a .NET downloader that downloads and executes a file from a hard-coded command and control (C2) server.
- BROLER rat
- Also known as down_new. BROLER, also known as down_new, is a remote access trojan primarily associated with targeting government and public sector entities.
- BRUSHFIRE backdoor
- BRUSHFIRE is a passive backdoor written in C that executes in-memory within an existing process.
- BRansomware ransomware
- BRansomware is a type of ransomware that encrypts data and demands payment for decryption.
- BS2005 backdoorrat
- BS2005 is malware that was used by Ke3chang in spearphishing campaigns since at least 2011.
- BTCLocker Ransomware ransomware
- Also known as BTC Ransomware. This is most likely to affect English speaking users, since the note is written in English.
- BTCWare ransomware
- According to PCRisk, BTCWare is an updated version of a ransomware-type virus called Crptxxx.
- BTCWare Related to / new version of CryptXXX ransomware
- BTCWare is a type of ransomware, a new iteration of CryptXXX, known for encrypting victim files and demanding a ransom payment in Bitcoin…
- BTCWare-Aleta ransomware
- BTCWare-Aleta is a ransomware threat known for encrypting users' files and demanding a cryptocurrency ransom for decryption keys.
- BTCWare-Gryphon ransomware
- BTCWare-Gryphon is a variant of the BTCWare ransomware family that encrypts files and demands a cryptocurrency ransom for decryption.
- BTCWare-Master ransomware
- BTCWare-Master is a variant of BTCWare ransomware that encrypts files on a victim's system and demands payment in cryptocurrency.
- BTCWare-Nuclear ransomware
- BTCWare-Nuclear is a type of ransomware that encrypts victims' files and demands a ransom for decryption.
- BTCWare-Onyon ransomware
- BTCWare-Onyon is a variant of the BTCWare ransomware family.
- BTCWare-PayDay ransomware
- BTCWare-PayDay is a ransomware variant known for encrypting files and demanding a Bitcoin payment.
- BTCWare-Wyvern ransomware
- BTCWare-Wyvern is a variant of the BTCWare ransomware family, known for encrypting files and demanding a cryptocurrency ransom for…
- BTCamant Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- BTMOB RAT ratcredential-stealerkeylogger
- According to Cyble, this is an advanced Android malware evolved from SpySolr that features remote control, credential theft, and data…
- BUBBLEWRAP backdoor
- Also known as Backdoor.APT.FakeWinHTTPHelper. BUBBLEWRAP is a full-featured, second-stage backdoor used by the admin@338 group.
- BUFFETLINE rat
- BUFFETLINE is a remote access tool (RAT) used primarily in cyber espionage campaigns targeting government and financial sectors…
- BUGHATCH loader
- According to Elastic, BUGHATCH is an in-memory implant loaded by an obfuscated PowerShell script that decodes and executes an embedded…
- BURNBOOK dropper
- According to Mandiant, BURNBOOK is a dropper for TEARPAGE.
- BUSHWALK webshell
- BUSHWALK is a web shell written in Perl that was inserted into the legitimate querymanifest.cgi file on compromised Ivanti Connect Secure…
- BWall ransomware
- BWall is a type of ransomware aimed at encrypting victim's data and demanding payment for decryption.
- BX trojan
- BX is a known malware trojan with limited information available on its specific characteristics or targeting behavior.
- BYEBY ransomware
- BYEBY is a ransomware family that encrypts victims' files, demanding a ransom for decryption.
- Babadeda loader
- According to PCrisk, Babadeda is a new sample in the crypters family, allowing threat actors to encrypt and obfuscate the malicious samples.
- Babar spywarerat
- Also known as SNOWBALL. Babar, also known as SNOWBALL, is a sophisticated piece of malware associated with cyber-espionage activities.
- Babax ransomware
- Babax is a ransomware that encrypts files on infected systems, demanding a ransom payment for decryption.
- Babuk ransomware
- Also known as Babyk, Vasa Locker. Babuk is a Ransomware-as-a-service (RaaS) malware that has been used since at least 2021.
- Babuk (ELF) ransomware
- Babuk is a ransomware variant known for targeting enterprise systems, specifically ESX and NAS environments.
- Babuk Ransomsware ransomware
- Since this is the first detection of this malware in the wild, it’s not surprising that Babuk is not obsfuscated at all.
- Babuk-Locker ransomware
- Babuk‑Locker emerged in early 2021 as a Ransomware‑as‑a‑Service (RaaS) gang targeting high‑value “big game” enterprises across sectors…
- BabyLon RAT rat
- BabyLon RAT is a remote access trojan used primarily for cyber espionage.
- BabyShark spyware
- Also known as LATEOP. BabyShark is a Microsoft Visual Basic (VB) script-based malware family that is believed to be associated with several North Korean…
- Babyduck rat
- Babyduck is a remote access tool (RAT) used primarily for surveillance and data exfiltration activities.
- Babylon rat
- Babylon is a highly advanced remote administration tool with no dependencies.
- Bachosens spyware
- Bachosens is a sophisticated spyware that has been used in cyber-espionage campaigns.
- Back Orifice backdoorrat
- Also known as BO. Back Orifice (often shortened to BO) is a computer program designed for remote system administration.
- Back Orifice 2000 backdoorrattrojan
- Also known as BO2k. Back Orifice 2000 (often shortened to BO2k) is a computer program designed for remote system administration.
- BackConfig trojan
- BackConfig is a custom Trojan with a flexible plugin architecture that has been used by Patchwork.
- BackNet botnetbackdoor
- BackNet is a sophisticated malware family known for creating botnets and establishing backdoors within targeted systems.
- BackSwap trojancredential-stealer
- BackSwap is a banking trojan known for its unique technique of injecting malicious scripts into web pages by replacing a code snippet…
- Backdoor.Oldrea backdoor
- Also known as Havex. Backdoor.Oldrea is a modular backdoor that used by Dragonfly against energy companies since at least 2013.
- Backdoorit rat
- Also known as backd00rit. According to Avast Decoded, Backdoorit is a multiplatform RAT written in Go programming language and supporting both Windows and…
- Backoff POS credential-stealer
- Backoff POS is a point-of-sale malware family used to steal payment card data from retail and hospitality businesses.
- Bad Rabbit ransomwareworm
- Also known as Win32/Diskcoder.D, BadRabbit, Bad-Rabbit. Bad Rabbit is a self-propagating ransomware that affected the Ukrainian transportation sector in 2017.
- Bad Rabbit
- Also known as Diskcoder.D. Bad Rabbit is a self-propagating (“wormable”) ransomware that affected the transportation sector in Ukraine.
- BadBlock ransomware
- BadBlock is a type of ransomware that encrypts files on an infected system and demands a ransom for decryption.
- BadEncript ransomware
- BadEncript is a ransomware family known for encrypting files and demanding a ransom for decryption.
- BadEncript Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- BadPatch trojan
- Also known as WelcomeChat. BadPatch is a Windows Trojan that was used in a Gaza Hackers-linked campaign.
- BadPaw ransomware
- BadPaw is a ransomware family known for targeting financial services and healthcare organizations.
- Badbeeteam ransomware
- Badbeeteam is a ransomware family that encrypts files on the victim's system and demands a ransom for decryption.
- Bagle worm
- Bagle is a mass-mailing email worm that spreads via email attachments.
- Bahamut (Android) spyware
- According to PCrisk, Bahamut is the name of Android malware with spyware functionality.
- Bahamut (Windows) spyware
- Bahamut is a highly sophisticated spyware believed to be used by an advanced persistent threat group.
- BaksoCrypt ransomware
- BaksoCrypt is a ransomware variant based on the my-Little-Ransomware template.
- Balbaz ransomware
- Balbaz is a type of ransomware that encrypts files on infected systems and demands a ransom payment for decryption.
- Baldr credential-stealerloader
- Also known as Baldir. Baldr is a credential-stealing malware known for its ability to exfiltrate information from web browsers and cryptocurrency wallets.
- Baliluware ransomware
- Baliluware is a ransomware family known for encrypting files and demanding a ransom payment in cryptocurrency.
- BalkanDoor backdoorscreen-capture
- According to ESET, BalkanDoor is a simple backdoor with a small number of commands (download and execute a file, create a remote shell…
- BalkanRAT ratloader
- The goal of BalkanRAT which is a more complex part of the malicious Balkan-toolset (cf.
- Ballista botnetddos
- Ballista is an IoT botnet, infecting unpatched TP-Link Archer AX21 (AX1800) routers.
- Bam! ransomware
- Bam! is a form of ransomware that encrypts victim's files and demands cryptocurrency payments for decryption keys.
- Bamital botnetdownloader
- Bamital is a malware family primarily associated with click-fraud and distribution through botnet networks.
- BanPolMex RAT rat
- BanPolMex is a remote access trojan that uses TCP for communication.
- BananaCrypt ransomware
- BananaCrypt is a ransomware family that encrypts files on infected machines and demands a ransom for the decryption key.
- Banatrix trojan
- Banatrix is a banking trojan primarily targeting the Polish financial services sector.
- BancoCrypt HT ransomware
- BancoCrypt HT is a type of ransomware that targets financial services, encrypting data and demanding ransom for decryption.
- Bandarchor ransomware
- Also known as Rakhni, Agent.iih, Aura. Bandarchor, also known as Rakhni, is a ransomware family that partially encrypts files, demanding a ransom from victims to restore access.
- Bandit Stealer credential-stealerspyware
- Bandit Stealer is a malicious software designed to extract sensitive information such as credentials from infected systems.
- Bandook rat
- Also known as Bandok. Bandook is a commercially available RAT, written in Delphi and C++, that has been available since at least 2007.
- Bandook RAT rat
- Bandook is a FWB#++ reverse connection rat (Remote Administration Tool), with a small size server when packed 30 KB, and a long list of…
- Banjori trojan
- Also known as BackPatcher, BankPatch, MultiBanker 2. Banjori is a banking trojan that targets financial institutions.
- Banks1 ransomware
- Banks1 is a ransomware known for targeting financial services and healthcare sectors.
- Bankshot rat
- Also known as Trojan Manuscript, COPPERHEDGE, FoggyBrass. Bankshot is a remote access tool (RAT) that was first reported by the Department of Homeland Security in December of 2017.
- Banload downloadertrojan
- F-Secure observed Banload variants silently downloading malicious files from a remote server, then installing and executing the files.
- BansomQare Manna Ransomware ransomware
- BansomQare Manna is a ransomware family known for encrypting files on victim systems and demanding a ransom for decryption.
- BaoLoader loader
- According to Expel, the developers behind the recent AppSuite-PDF and PDF Editor campaigns have used at least 26 code-signing certificates…
- BarRax Ransomware ransomware
- Also known as BarRaxCrypt Ransomware. This is most likely to affect English speaking users, since the note is written in English.
- Barack Obama's EBBV ransomware
- Ransomware known as Barack Obama's EBBV is primarily deployed to extort money from victims by encrypting their files and demanding a…
- Barack Obama's Everlasting Blue Blackmail Virus Ransomware ransomware
- Also known as Barack Obama's Blackmail Virus Ransomware. A new ransomware that only encrypts .EXE files on a computer.
- Barb(ie) Downloader downloader
- Barb(ie) Downloader is a type of malware used primarily to download and execute other malicious payloads.
- BarbWire rat
- BarbWire is a Remote Access Trojan (RAT) that focuses on espionage activities, particularly targeting government and media organizations.
- Bart ransomwareloader
- Also known as BaCrypt. Ransomware Possible affiliations with RockLoader, Locky and Dridex
- Bart ransomware ransomwareloader
- Also known as Locky Bart. Bart ransomware is distributed by the same Russian Cyber Mafia behind Dridex 220 and Locky.
- Basbanke trojan
- Basbanke is a banking trojan targeting Android devices, primarily used in Brazil to steal banking credentials.
- Bashlite ddosbotnet
- Also known as Gafgyt, gayfgt, lizkebab. Bashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS).
- Basilisque Locker ransomware
- Basilisque Locker is a type of ransomware that encrypts victims' files and demands a ransom for decryption.
- Batch NET trojandownloader
- Batch NET is a trojan that targets government and technology sectors, primarily in the US, UK, and Canada.
- BatchWiper wiper
- BatchWiper is a destructive malware known for targeting the Middle East, particularly Iran.
- Batel ransomwaretrojan
- Batel is a ransomware family that specifically targets financial services and government sectors.
- Bateleur rat
- Bateleur is a remote access trojan (RAT) primarily used in phishing campaigns targeting financial services and technology sectors.
- Bazar backdoorloaderdownloader
- Also known as KEGTAP, Team9, Bazaloader. Bazar is a downloader and backdoor that has been used since at least April 2020, with infections primarily against professional services…
- BazarNimrod loader
- Also known as NimzaLoader. A rewrite of Bazarloader in the Nim programming language.
- BeamYourScreen ratscreen-capture
- Another free and portable remote access program is BeamYourScreen.
- Beapy cryptominerworm
- According to Symantec, Beapy is a cryptojacking campaign impacting enterprises that uses the EternalBlue exploit and stolen and hardcoded…
- Beast Trojan rattrojanbackdoor
- Beast is a Windows-based backdoor trojan horse, more commonly known in the hacking community as a Remote Administration Tool or a "RAT".
- BeaverTail credential-stealerdownloader
- BeaverTail is a malware that has both a JavaScript and C++ variant.