Malware Families page 5 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

BRICKSTORM backdoor
BRICKSTORM is a cross-platform backdoor with variants written in Go and Rust that facilitates command and control, the ingress transfer of…
BROKEYOLK downloader
According to Mandiant, BROKEYOLK is a .NET downloader that downloads and executes a file from a hard-coded command and control (C2) server.
BROLER rat
Also known as down_new. BROLER, also known as down_new, is a remote access trojan primarily associated with targeting government and public sector entities.
BRUSHFIRE backdoor
BRUSHFIRE is a passive backdoor written in C that executes in-memory within an existing process.
BRansomware ransomware
BRansomware is a type of ransomware that encrypts data and demands payment for decryption.
BS2005 backdoorrat
BS2005 is malware that was used by Ke3chang in spearphishing campaigns since at least 2011.
BTCLocker Ransomware ransomware
Also known as BTC Ransomware. This is most likely to affect English speaking users, since the note is written in English.
BTCWare ransomware
According to PCRisk, BTCWare is an updated version of a ransomware-type virus called Crptxxx.
BTCWare Related to / new version of CryptXXX ransomware
BTCWare is a type of ransomware, a new iteration of CryptXXX, known for encrypting victim files and demanding a ransom payment in Bitcoin…
BTCWare-Aleta ransomware
BTCWare-Aleta is a ransomware threat known for encrypting users' files and demanding a cryptocurrency ransom for decryption keys.
BTCWare-Gryphon ransomware
BTCWare-Gryphon is a variant of the BTCWare ransomware family that encrypts files and demands a cryptocurrency ransom for decryption.
BTCWare-Master ransomware
BTCWare-Master is a variant of BTCWare ransomware that encrypts files on a victim's system and demands payment in cryptocurrency.
BTCWare-Nuclear ransomware
BTCWare-Nuclear is a type of ransomware that encrypts victims' files and demands a ransom for decryption.
BTCWare-Onyon ransomware
BTCWare-Onyon is a variant of the BTCWare ransomware family.
BTCWare-PayDay ransomware
BTCWare-PayDay is a ransomware variant known for encrypting files and demanding a Bitcoin payment.
BTCWare-Wyvern ransomware
BTCWare-Wyvern is a variant of the BTCWare ransomware family, known for encrypting files and demanding a cryptocurrency ransom for…
BTCamant Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
BTMOB RAT ratcredential-stealerkeylogger
According to Cyble, this is an advanced Android malware evolved from SpySolr that features remote control, credential theft, and data…
BUBBLEWRAP backdoor
Also known as Backdoor.APT.FakeWinHTTPHelper. BUBBLEWRAP is a full-featured, second-stage backdoor used by the admin@338 group.
BUFFETLINE rat
BUFFETLINE is a remote access tool (RAT) used primarily in cyber espionage campaigns targeting government and financial sectors…
BUGHATCH loader
According to Elastic, BUGHATCH is an in-memory implant loaded by an obfuscated PowerShell script that decodes and executes an embedded…
BURNBOOK dropper
According to Mandiant, BURNBOOK is a dropper for TEARPAGE.
BUSHWALK webshell
BUSHWALK is a web shell written in Perl that was inserted into the legitimate querymanifest.cgi file on compromised Ivanti Connect Secure…
BWall ransomware
BWall is a type of ransomware aimed at encrypting victim's data and demanding payment for decryption.
BX trojan
BX is a known malware trojan with limited information available on its specific characteristics or targeting behavior.
BYEBY ransomware
BYEBY is a ransomware family that encrypts victims' files, demanding a ransom for decryption.
Babadeda loader
According to PCrisk, Babadeda is a new sample in the crypters family, allowing threat actors to encrypt and obfuscate the malicious samples.
Babar spywarerat
Also known as SNOWBALL. Babar, also known as SNOWBALL, is a sophisticated piece of malware associated with cyber-espionage activities.
Babax ransomware
Babax is a ransomware that encrypts files on infected systems, demanding a ransom payment for decryption.
Babuk ransomware
Also known as Babyk, Vasa Locker. Babuk is a Ransomware-as-a-service (RaaS) malware that has been used since at least 2021.
Babuk (ELF) ransomware
Babuk is a ransomware variant known for targeting enterprise systems, specifically ESX and NAS environments.
Babuk Ransomsware ransomware
Since this is the first detection of this malware in the wild, it’s not surprising that Babuk is not obsfuscated at all.
Babuk-Locker ransomware
Babuk‑Locker emerged in early 2021 as a Ransomware‑as‑a‑Service (RaaS) gang targeting high‑value “big game” enterprises across sectors…
BabyLon RAT rat
BabyLon RAT is a remote access trojan used primarily for cyber espionage.
BabyShark spyware
Also known as LATEOP. BabyShark is a Microsoft Visual Basic (VB) script-based malware family that is believed to be associated with several North Korean…
Babyduck rat
Babyduck is a remote access tool (RAT) used primarily for surveillance and data exfiltration activities.
Babylon rat
Babylon is a highly advanced remote administration tool with no dependencies.
Bachosens spyware
Bachosens is a sophisticated spyware that has been used in cyber-espionage campaigns.
Back Orifice backdoorrat
Also known as BO. Back Orifice (often shortened to BO) is a computer program designed for remote system administration.
Back Orifice 2000 backdoorrattrojan
Also known as BO2k. Back Orifice 2000 (often shortened to BO2k) is a computer program designed for remote system administration.
BackConfig trojan
BackConfig is a custom Trojan with a flexible plugin architecture that has been used by Patchwork.
BackNet botnetbackdoor
BackNet is a sophisticated malware family known for creating botnets and establishing backdoors within targeted systems.
BackSwap trojancredential-stealer
BackSwap is a banking trojan known for its unique technique of injecting malicious scripts into web pages by replacing a code snippet…
Backdoor.Oldrea backdoor
Also known as Havex. Backdoor.Oldrea is a modular backdoor that used by Dragonfly against energy companies since at least 2013.
Backdoorit rat
Also known as backd00rit. According to Avast Decoded, Backdoorit is a multiplatform RAT written in Go programming language and supporting both Windows and…
Backoff POS credential-stealer
Backoff POS is a point-of-sale malware family used to steal payment card data from retail and hospitality businesses.
Bad Rabbit ransomwareworm
Also known as Win32/Diskcoder.D, BadRabbit, Bad-Rabbit. Bad Rabbit is a self-propagating ransomware that affected the Ukrainian transportation sector in 2017.
Bad Rabbit
Also known as Diskcoder.D. Bad Rabbit is a self-propagating (“wormable”) ransomware that affected the transportation sector in Ukraine.
BadBlock ransomware
BadBlock is a type of ransomware that encrypts files on an infected system and demands a ransom for decryption.
BadEncript ransomware
BadEncript is a ransomware family known for encrypting files and demanding a ransom for decryption.
BadEncript Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
BadPatch trojan
Also known as WelcomeChat. BadPatch is a Windows Trojan that was used in a Gaza Hackers-linked campaign.
BadPaw ransomware
BadPaw is a ransomware family known for targeting financial services and healthcare organizations.
Badbeeteam ransomware
Badbeeteam is a ransomware family that encrypts files on the victim's system and demands a ransom for decryption.
Bagle worm
Bagle is a mass-mailing email worm that spreads via email attachments.
Bahamut (Android) spyware
According to PCrisk, Bahamut is the name of Android malware with spyware functionality.
Bahamut (Windows) spyware
Bahamut is a highly sophisticated spyware believed to be used by an advanced persistent threat group.
BaksoCrypt ransomware
BaksoCrypt is a ransomware variant based on the my-Little-Ransomware template.
Balbaz ransomware
Balbaz is a type of ransomware that encrypts files on infected systems and demands a ransom payment for decryption.
Baldr credential-stealerloader
Also known as Baldir. Baldr is a credential-stealing malware known for its ability to exfiltrate information from web browsers and cryptocurrency wallets.
Baliluware ransomware
Baliluware is a ransomware family known for encrypting files and demanding a ransom payment in cryptocurrency.
BalkanDoor backdoorscreen-capture
According to ESET, BalkanDoor is a simple backdoor with a small number of commands (download and execute a file, create a remote shell…
BalkanRAT ratloader
The goal of BalkanRAT which is a more complex part of the malicious Balkan-toolset (cf.
Ballista botnetddos
Ballista is an IoT botnet, infecting unpatched TP-Link Archer AX21 (AX1800) routers.
Bam! ransomware
Bam! is a form of ransomware that encrypts victim's files and demands cryptocurrency payments for decryption keys.
Bamital botnetdownloader
Bamital is a malware family primarily associated with click-fraud and distribution through botnet networks.
BanPolMex RAT rat
BanPolMex is a remote access trojan that uses TCP for communication.
BananaCrypt ransomware
BananaCrypt is a ransomware family that encrypts files on infected machines and demands a ransom for the decryption key.
Banatrix trojan
Banatrix is a banking trojan primarily targeting the Polish financial services sector.
BancoCrypt HT ransomware
BancoCrypt HT is a type of ransomware that targets financial services, encrypting data and demanding ransom for decryption.
Bandarchor ransomware
Also known as Rakhni, Agent.iih, Aura. Bandarchor, also known as Rakhni, is a ransomware family that partially encrypts files, demanding a ransom from victims to restore access.
Bandit Stealer credential-stealerspyware
Bandit Stealer is a malicious software designed to extract sensitive information such as credentials from infected systems.
Bandook rat
Also known as Bandok. Bandook is a commercially available RAT, written in Delphi and C++, that has been available since at least 2007.
Bandook RAT rat
Bandook is a FWB#++ reverse connection rat (Remote Administration Tool), with a small size server when packed 30 KB, and a long list of…
Banjori trojan
Also known as BackPatcher, BankPatch, MultiBanker 2. Banjori is a banking trojan that targets financial institutions.
Banks1 ransomware
Banks1 is a ransomware known for targeting financial services and healthcare sectors.
Bankshot rat
Also known as Trojan Manuscript, COPPERHEDGE, FoggyBrass. Bankshot is a remote access tool (RAT) that was first reported by the Department of Homeland Security in December of 2017.
Banload downloadertrojan
F-Secure observed Banload variants silently downloading malicious files from a remote server, then installing and executing the files.
BansomQare Manna Ransomware ransomware
BansomQare Manna is a ransomware family known for encrypting files on victim systems and demanding a ransom for decryption.
BaoLoader loader
According to Expel, the developers behind the recent AppSuite-PDF and PDF Editor campaigns have used at least 26 code-signing certificates…
BarRax Ransomware ransomware
Also known as BarRaxCrypt Ransomware. This is most likely to affect English speaking users, since the note is written in English.
Barack Obama's EBBV ransomware
Ransomware known as Barack Obama's EBBV is primarily deployed to extort money from victims by encrypting their files and demanding a…
Barack Obama's Everlasting Blue Blackmail Virus Ransomware ransomware
Also known as Barack Obama's Blackmail Virus Ransomware. A new ransomware that only encrypts .EXE files on a computer.
Barb(ie) Downloader downloader
Barb(ie) Downloader is a type of malware used primarily to download and execute other malicious payloads.
BarbWire rat
BarbWire is a Remote Access Trojan (RAT) that focuses on espionage activities, particularly targeting government and media organizations.
Bart ransomwareloader
Also known as BaCrypt. Ransomware Possible affiliations with RockLoader, Locky and Dridex
Bart ransomware ransomwareloader
Also known as Locky Bart. Bart ransomware is distributed by the same Russian Cyber Mafia behind Dridex 220 and Locky.
Basbanke trojan
Basbanke is a banking trojan targeting Android devices, primarily used in Brazil to steal banking credentials.
Bashlite ddosbotnet
Also known as Gafgyt, gayfgt, lizkebab. Bashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS).
Basilisque Locker ransomware
Basilisque Locker is a type of ransomware that encrypts victims' files and demands a ransom for decryption.
Batch NET trojandownloader
Batch NET is a trojan that targets government and technology sectors, primarily in the US, UK, and Canada.
BatchWiper wiper
BatchWiper is a destructive malware known for targeting the Middle East, particularly Iran.
Batel ransomwaretrojan
Batel is a ransomware family that specifically targets financial services and government sectors.
Bateleur rat
Bateleur is a remote access trojan (RAT) primarily used in phishing campaigns targeting financial services and technology sectors.
Bazar backdoorloaderdownloader
Also known as KEGTAP, Team9, Bazaloader. Bazar is a downloader and backdoor that has been used since at least April 2020, with infections primarily against professional services…
BazarNimrod loader
Also known as NimzaLoader. A rewrite of Bazarloader in the Nim programming language.
BeamYourScreen ratscreen-capture
Another free and portable remote access program is BeamYourScreen.
Beapy cryptominerworm
According to Symantec, Beapy is a cryptojacking campaign impacting enterprises that uses the EternalBlue exploit and stolen and hardcoded…
Beast Trojan rattrojanbackdoor
Beast is a Windows-based backdoor trojan horse, more commonly known in the hacking community as a Remote Administration Tool or a "RAT".
BeaverTail credential-stealerdownloader
BeaverTail is a malware that has both a JavaScript and C++ variant.