Malware Families page 50 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Tor
Tor is a software suite and network that provides increased anonymity on the Internet.
TorCT PHP RAT rat
TorCT PHP RAT is a remote access trojan written in PHP.
TorLoader downloader
Downloader, delivered via a lure with fake exploits published on Github.
TorLocker ransomware
TorLocker is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
Torchwood ransomware
Torchwood is a ransomware known for targeting various industries such as healthcare and financial services, primarily in the US and Europe.
Torii botnet
Torii is an advanced botnet malware that affects IoT devices.
Torisma spyware
Torisma is a second stage implant designed for specialized monitoring that has been used by Lazarus Group.
TorrentLocker ransomware
Also known as Crypt0L0cker, CryptoFortress, Teerac. Ransomware Newer variants not decryptable.
Tortoise ransomware
Tortoise is a ransomware that encrypts files on the targeted systems and demands a ransom for decryption keys.
TotalWipeOut ransomware
TotalWipeOut is a ransomware family known for encrypting files and demanding a ransom for decryption.
TowerWeb ransomware
TowerWeb is a ransomware family known for encrypting files on infected systems and demanding payment for decryption keys.
Toxcrypt ransomware
Toxcrypt is a type of ransomware that encrypts files on the victim's system and demands a ransom for decryption.
ToxicEye ransomware
ToxicEye is a ransomware that spreads through phishing emails.
ToxicPanda rat
ToxicPanda is an Android banking RAT first identified by Cleafy in October 2024.
TrailBlazer ratbackdoor
TrailBlazer is a modular malware that has been used by APT29 since at least 2019.
TransBox backdoor
According to Trend Micro, this is a backdoor abusing the Dropbox API, used by threat actor Earth Yako.
TransferLoader loader
TransferLoader is a malware loader used to deliver various payloads to compromised systems.
TreasureHunter backdoor
Also known as huntpos. TreasureHunter is a point-of-sale (POS) malware designed to collect payment card information from infected systems.
Triada trojandownloader
Triada was first reported in 2016 as a second stage malware.
TriangleDB spywarebackdoor
TriangleDB is an Objective-C written implant deployed after Binary Validator and after root privileges are obtained during Operation…
Trick-Or-Treat ransomware
Trick-Or-Treat is a ransomware strain known for encrypting files and demanding payment for decryption keys.
TrickBot credential-stealerspywaretrojan
Also known as Totbrick, TSPY_TRICKLOAD, TheTrick. TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre.
TrickMo trojan
TrickMo a 2FA bypass mobile banking trojan, most likely being distributed by TrickBot.
Triout spyware
Bitdefender described Triout as a Android spyware, which appears to act as a framework for building extensive surveillance capabilities…
TripleCross rootkit
According to its author, TripleCross is a Linux eBPF rootkit that demonstrates the offensive capabilities of the eBPF technology.
Tripoli ransomware
Tripoli is a ransomware malware designed to encrypt files on a victim's system and demand a ransom in exchange for decryption keys.
Triton exploit-kit
Also known as TRISIS, HatMan, Trisis. Triton is an attack framework built to interact with Triconex Safety Instrumented System (SIS) controllers.
Trochilus rat
Trochilus is a remote access trojan (RAT) first identified in October 2015 when attackers used it to infect visitors of a Myanmar website.
Trochilus RAT rat
Trochilus is a C++ written RAT, which is available on GitHub.
Trojan ransomware
Also known as BrainCrypt. BrainCrypt is a ransomware trojan known for encrypting files on targeted systems and demanding a ransom.
Trojan Dz trojan
Trojan Dz is a variant of the CyberSplitter malware family, known for targeting financial services and government sectors.
Trojan-SMS.AndroidOS.Agent.ao trojan
Trojan-SMS.AndroidOS.Agent.ao is Android malware that poses as a Trojan capable of sending SMS messages without the user's consent, often…
Trojan-SMS.AndroidOS.FakeInst.a trojan
Trojan-SMS.AndroidOS.FakeInst.a is Android malware.
Trojan-SMS.AndroidOS.OpFake.a trojan
Trojan-SMS.AndroidOS.OpFake.a is Android malware known for sending unauthorized SMS messages, often as part of billing fraud schemes on…
Trojan-Syria ransomware
Trojan-Syria is a ransomware malware primarily associated with targeting entities within Syria.
Trojan.Karagany rattrojan
Also known as xFrost, Karagany. Trojan.Karagany is a modular remote access tool used for recon and linked to Dragonfly.
Trojan.Mebromi trojanrootkit
Trojan.Mebromi is BIOS-level malware that takes control of the victim before MBR.
Troldesh orShade, XTBL ransomwaredownloader
Also known as Shade, Troldesh. Ransomware May download additional malware after encryption
Troll Stealer credential-stealerdropper
Troll Stealer is an information stealer written in Go associated with Kimsuky operations.
Tron ransomware ransomware
Tron ransomware is known for encrypting files on infected systems and demanding a ransom payment for file decryption.
Tropidoor rat
Tropidoor is an advanced HTTP/S Remote Access Trojan (RAT) written as a C project, which exhibits significant code overlap with the…
TroubleGrabber credential-stealer
TroubleGrabber is a credential-stealing malware that primarily targets Discord users.
TrueCrypter ransomware
TrueCrypter is a type of ransomware that encrypts files on the infected systems and demands a ransom in cryptocurrency in exchange for the…
TruffleHog credential-stealer
TruffleHog is an open-source secrets-discovery tool that is used to search for credentials, API keys, and encryption keys across a variety…
Trump Bot botnetransomwaretrojan
Trump Bot is a malware family known for its involvement in cybercriminal activity, particularly targeting government and financial sectors.
Trump Ransom ransomware
Trump Ransom is a ransomware family with limited targeting and unclear distribution.
TrumpHead ransomware
TrumpHead is a ransomware strain known for encrypting files on the infected system and demanding a ransom for decryption.
TrumpLocker Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
TrustConnect RAT ratscreen-capture
TrustConnect RAT is a malware-as-a-service remote access trojan disguised as a legitimate remote monitoring tool.
Truvasys trojandownloader
Truvasys is first-stage malware that has been used by PROMETHIUM.
Try2Cry ransomwareworm
Try2Cry is ransomware that propagates like a worm, utilizing USB drives among other methods to spread.
TsarBot trojancredential-stealerdropper
According to Cyble, this is a banking trojan that targets over 750 applications globally, including banking, finance, cryptocurrency, and…
Tsifiri rat
Tsifiri is a remote access trojan (RAT) primarily deployed for espionage purposes targeting government and financial sectors.
Tsunami (ELF) botnetddos
Also known as Amnesia, Muhstik, Radiation. Tsunami is a Linux-based malware that primarily operates as a botnet and is used for launching distributed denial-of-service (DDoS) attacks.
Tsunami (OS X) ddosbackdoor
Tsunami is a trojan malware known for its DDoS capabilities, primarily targeting Mac OS X systems.
TsunamiKit cryptominerloadercredential-stealer
TsunamiKit is a multi-stage malware toolkit written in Python and .NET.
Tsundere backdoor
Also known as DinDoor. Tsundere, also known as DinDoor, is a backdoor malware primarily used for cyber espionage.
Tsundere Botnet botnet
Also known as DinDoor. Tsundere Botnet is a botnet first reported in mid-2025 that is delivered via MSI installer or a PowerShell script.
Tunna webshell
Tunna is a webshell used to facilitate remote administration by creating a bridge between an attacker and a compromised web server.
TunnelSpecter ratspyware
TunnelSpecter is a Remote Access Trojan (RAT) used primarily in cyber-espionage campaigns targeting critical infrastructure and…
Tuoni
According to its Github repo, Tuoni is a sophisticated, cross-platform red teaming framework designed to enhance cybersecurity education…
Turian backdoor
Turian is a backdoor that has been used by BackdoorDiplomacy to target Ministries of Foreign Affairs, telecommunication companies, and…
TurkStatik ransomware
TurkStatik is a ransomware strain that primarily targets users in Turkey.
Turkish ransomware
Turkish is a ransomware type malware known for encrypting files on victim systems and demanding a ransom for decryption.
Turkish FileEncryptor Ransomware ransomware
Also known as Fake CTB-Locker. his is most likely to affect English speaking users, since the note is written in English.
Turkish Ransom ransomware
Turkish Ransom is a type of ransomware that encrypts files and demands a ransom payment for decryption.
Turkojan rat
Turkojan is a Remote Access Trojan (RAT) known for enabling attackers to gain unauthorized control of infected machines.
Turla RAT rat
Turla RAT is a highly sophisticated Remote Access Trojan used by the Turla Group, primarily for cyber-espionage purposes.
Turla SilentMoon rat
Also known as BigBoss, Cacao, GoldenSky. Turla SilentMoon, also known as BigBoss, is a sophisticated remote access trojan linked to the cyber-espionage group Turla.
TurlaRPC rat
TurlaRPC is a remote access tool linked to the Turla APT group, known for cyber espionage targeting governmental and military…
Twitoor dropper
Twitoor is a dropper application capable of receiving commands from social media.
TwoDash ransomware
TwoDash is a ransomware family primarily targeting financial services and government entities in the United States and United Kingdom.
TwoFace webshellloader
Also known as HighShell, HyperShell, Minion. According to Unit42, TwoFace is a two-staged (loader+payload) webshell, written in C# and meant to run on webservers with ASP.NET.
Tycoon ransomware
This malware is written in Java and is named after references in the code.
TypeHash credential-stealerrat
Also known as SkinnyD. TypeHash, also known as SkinnyD, is a sophisticated remote access trojan primarily used for cyber espionage.
Typhon Stealer credential-stealerspyware
Also known as Typhon Reborn V2. According to PCrisk, Typhon is a stealer-type malware written in the C# programming language.
Tyupkin trojan
Tyupkin is a type of ATM malware that allows attackers to dispense cash from targeted ATMs by exploiting vulnerabilities in the machine's…
UACMe exploit-kit
Also known as Akagi. UACMe is an open source assessment tool that contains many methods for bypassing Windows User Account Control on multiple versions of the…
UBoatRAT rat
UBoatRAT is a remote access tool that was identified in May 2017.
UCCU ransomware
UCCU is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
UDPoS ddos
UDPoS is a malware that targets point-of-sale systems using UDP for communication and potentially conducting denial-of-service attacks.
UFR Stealer credential-stealer
Also known as Usteal. UFR Stealer, also known as Usteal, is a type of information stealer malware.
UNITEDRAKE rat
The existence of the UNITEDRAKE RAT first came to light in 2014 as part of a series of classified documents leaked by former NSA…
UNNAM3D ransomware
UNNAM3D is a type of ransomware designed to encrypt files on a victim's computer, demanding a ransom payment for decryption.
UPAS credential-stealerkeylogger
Also known as Rombrast. UPAS, also known as Rombrast, is a credential-stealing malware known for its keylogging capabilities.
UPPERCUT backdoor
Also known as ANEL, lena. UPPERCUT is a 32-bit HTTP-based backdoor that has been used by menuPass since at least 2017.
UPSTYLE backdoor
UPSTYLE is a Python-based backdoor associated with exploitation of Palo Alto firewalls using CVE-2024-3400 in early 2024.
USBCulprit wormspyware
According to Kaspersky, USBCulprit is a malware that is capable of scanning various paths in victim machines, collecting documents with…
USBStealer spyware
Also known as USB Stealer, Win32/USBStealer. USBStealer is malware that has been used by APT28 since at least 2005 to extract information from air-gapped networks.
USBferry
USBferry is an information stealing malware and has been used by Tropic Trooper in targeted attacks against Taiwanese and Philippine…
USR0 ransomware
USR0 is a type of ransomware malware. It is used by threat actors to encrypt victims' data and demand a ransom for the decryption key.
Uh-Oh ransomware
Uh-Oh is a ransomware variant that encrypts files on the infected systems, demanding a ransom for decryption.
Uiwix ransomware
Uiwix is a ransomware strain that encrypts files on infected systems and demands a ransom in cryptocurrency.
Uiwix Ransomware ransomwareworm
Also known as UIWIX. Uiwix is a ransomware strain that exploits the EternalBlue SMB vulnerability to infect victim systems.
Ukash ransomware
Ukash is a type of ransomware that locks victims' computers and demands a payment often using Ukash or other prepaid cash services.
UltimaSMS trojan
UltimaSMS is an Android-based premium SMS trojan that subscribes users to premium services without their consent, resulting in significant…
Ultimo HT ransomware
Ultimo HT is a type of ransomware that encrypts files on an infected system and demands a ransom payment for decryption keys.
Ultra VNC rat
UltraVNC works a bit like Remote Utilities, where a server and viewer is installed on two PCs, and the viewer is used to control the server.
UltraCrypter ransomware
UltraCrypter is a ransomware family that encrypts files on infected systems and demands a ransom for decryption keys.
UltraLocker Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.