Malware Families page 50 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Tor
- Tor is a software suite and network that provides increased anonymity on the Internet.
- TorCT PHP RAT rat
- TorCT PHP RAT is a remote access trojan written in PHP.
- TorLoader downloader
- Downloader, delivered via a lure with fake exploits published on Github.
- TorLocker ransomware
- TorLocker is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
- Torchwood ransomware
- Torchwood is a ransomware known for targeting various industries such as healthcare and financial services, primarily in the US and Europe.
- Torii botnet
- Torii is an advanced botnet malware that affects IoT devices.
- Torisma spyware
- Torisma is a second stage implant designed for specialized monitoring that has been used by Lazarus Group.
- TorrentLocker ransomware
- Also known as Crypt0L0cker, CryptoFortress, Teerac. Ransomware Newer variants not decryptable.
- Tortoise ransomware
- Tortoise is a ransomware that encrypts files on the targeted systems and demands a ransom for decryption keys.
- TotalWipeOut ransomware
- TotalWipeOut is a ransomware family known for encrypting files and demanding a ransom for decryption.
- TowerWeb ransomware
- TowerWeb is a ransomware family known for encrypting files on infected systems and demanding payment for decryption keys.
- Toxcrypt ransomware
- Toxcrypt is a type of ransomware that encrypts files on the victim's system and demands a ransom for decryption.
- ToxicEye ransomware
- ToxicEye is a ransomware that spreads through phishing emails.
- ToxicPanda rat
- ToxicPanda is an Android banking RAT first identified by Cleafy in October 2024.
- TrailBlazer ratbackdoor
- TrailBlazer is a modular malware that has been used by APT29 since at least 2019.
- TransBox backdoor
- According to Trend Micro, this is a backdoor abusing the Dropbox API, used by threat actor Earth Yako.
- TransferLoader loader
- TransferLoader is a malware loader used to deliver various payloads to compromised systems.
- TreasureHunter backdoor
- Also known as huntpos. TreasureHunter is a point-of-sale (POS) malware designed to collect payment card information from infected systems.
- Triada trojandownloader
- Triada was first reported in 2016 as a second stage malware.
- TriangleDB spywarebackdoor
- TriangleDB is an Objective-C written implant deployed after Binary Validator and after root privileges are obtained during Operation…
- Trick-Or-Treat ransomware
- Trick-Or-Treat is a ransomware strain known for encrypting files and demanding payment for decryption keys.
- TrickBot credential-stealerspywaretrojan
- Also known as Totbrick, TSPY_TRICKLOAD, TheTrick. TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre.
- TrickMo trojan
- TrickMo a 2FA bypass mobile banking trojan, most likely being distributed by TrickBot.
- Triout spyware
- Bitdefender described Triout as a Android spyware, which appears to act as a framework for building extensive surveillance capabilities…
- TripleCross rootkit
- According to its author, TripleCross is a Linux eBPF rootkit that demonstrates the offensive capabilities of the eBPF technology.
- Tripoli ransomware
- Tripoli is a ransomware malware designed to encrypt files on a victim's system and demand a ransom in exchange for decryption keys.
- Triton exploit-kit
- Also known as TRISIS, HatMan, Trisis. Triton is an attack framework built to interact with Triconex Safety Instrumented System (SIS) controllers.
- Trochilus rat
- Trochilus is a remote access trojan (RAT) first identified in October 2015 when attackers used it to infect visitors of a Myanmar website.
- Trochilus RAT rat
- Trochilus is a C++ written RAT, which is available on GitHub.
- Trojan ransomware
- Also known as BrainCrypt. BrainCrypt is a ransomware trojan known for encrypting files on targeted systems and demanding a ransom.
- Trojan Dz trojan
- Trojan Dz is a variant of the CyberSplitter malware family, known for targeting financial services and government sectors.
- Trojan-SMS.AndroidOS.Agent.ao trojan
- Trojan-SMS.AndroidOS.Agent.ao is Android malware that poses as a Trojan capable of sending SMS messages without the user's consent, often…
- Trojan-SMS.AndroidOS.FakeInst.a trojan
- Trojan-SMS.AndroidOS.FakeInst.a is Android malware.
- Trojan-SMS.AndroidOS.OpFake.a trojan
- Trojan-SMS.AndroidOS.OpFake.a is Android malware known for sending unauthorized SMS messages, often as part of billing fraud schemes on…
- Trojan-Syria ransomware
- Trojan-Syria is a ransomware malware primarily associated with targeting entities within Syria.
- Trojan.Karagany rattrojan
- Also known as xFrost, Karagany. Trojan.Karagany is a modular remote access tool used for recon and linked to Dragonfly.
- Trojan.Mebromi trojanrootkit
- Trojan.Mebromi is BIOS-level malware that takes control of the victim before MBR.
- Troldesh orShade, XTBL ransomwaredownloader
- Also known as Shade, Troldesh. Ransomware May download additional malware after encryption
- Troll Stealer credential-stealerdropper
- Troll Stealer is an information stealer written in Go associated with Kimsuky operations.
- Tron ransomware ransomware
- Tron ransomware is known for encrypting files on infected systems and demanding a ransom payment for file decryption.
- Tropidoor rat
- Tropidoor is an advanced HTTP/S Remote Access Trojan (RAT) written as a C project, which exhibits significant code overlap with the…
- TroubleGrabber credential-stealer
- TroubleGrabber is a credential-stealing malware that primarily targets Discord users.
- TrueCrypter ransomware
- TrueCrypter is a type of ransomware that encrypts files on the infected systems and demands a ransom in cryptocurrency in exchange for the…
- TruffleHog credential-stealer
- TruffleHog is an open-source secrets-discovery tool that is used to search for credentials, API keys, and encryption keys across a variety…
- Trump Bot botnetransomwaretrojan
- Trump Bot is a malware family known for its involvement in cybercriminal activity, particularly targeting government and financial sectors.
- Trump Ransom ransomware
- Trump Ransom is a ransomware family with limited targeting and unclear distribution.
- TrumpHead ransomware
- TrumpHead is a ransomware strain known for encrypting files on the infected system and demanding a ransom for decryption.
- TrumpLocker Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- TrustConnect RAT ratscreen-capture
- TrustConnect RAT is a malware-as-a-service remote access trojan disguised as a legitimate remote monitoring tool.
- Truvasys trojandownloader
- Truvasys is first-stage malware that has been used by PROMETHIUM.
- Try2Cry ransomwareworm
- Try2Cry is ransomware that propagates like a worm, utilizing USB drives among other methods to spread.
- TsarBot trojancredential-stealerdropper
- According to Cyble, this is a banking trojan that targets over 750 applications globally, including banking, finance, cryptocurrency, and…
- Tsifiri rat
- Tsifiri is a remote access trojan (RAT) primarily deployed for espionage purposes targeting government and financial sectors.
- Tsunami (ELF) botnetddos
- Also known as Amnesia, Muhstik, Radiation. Tsunami is a Linux-based malware that primarily operates as a botnet and is used for launching distributed denial-of-service (DDoS) attacks.
- Tsunami (OS X) ddosbackdoor
- Tsunami is a trojan malware known for its DDoS capabilities, primarily targeting Mac OS X systems.
- TsunamiKit cryptominerloadercredential-stealer
- TsunamiKit is a multi-stage malware toolkit written in Python and .NET.
- Tsundere backdoor
- Also known as DinDoor. Tsundere, also known as DinDoor, is a backdoor malware primarily used for cyber espionage.
- Tsundere Botnet botnet
- Also known as DinDoor. Tsundere Botnet is a botnet first reported in mid-2025 that is delivered via MSI installer or a PowerShell script.
- Tunna webshell
- Tunna is a webshell used to facilitate remote administration by creating a bridge between an attacker and a compromised web server.
- TunnelSpecter ratspyware
- TunnelSpecter is a Remote Access Trojan (RAT) used primarily in cyber-espionage campaigns targeting critical infrastructure and…
- Tuoni
- According to its Github repo, Tuoni is a sophisticated, cross-platform red teaming framework designed to enhance cybersecurity education…
- Turian backdoor
- Turian is a backdoor that has been used by BackdoorDiplomacy to target Ministries of Foreign Affairs, telecommunication companies, and…
- TurkStatik ransomware
- TurkStatik is a ransomware strain that primarily targets users in Turkey.
- Turkish ransomware
- Turkish is a ransomware type malware known for encrypting files on victim systems and demanding a ransom for decryption.
- Turkish FileEncryptor Ransomware ransomware
- Also known as Fake CTB-Locker. his is most likely to affect English speaking users, since the note is written in English.
- Turkish Ransom ransomware
- Turkish Ransom is a type of ransomware that encrypts files and demands a ransom payment for decryption.
- Turkojan rat
- Turkojan is a Remote Access Trojan (RAT) known for enabling attackers to gain unauthorized control of infected machines.
- Turla RAT rat
- Turla RAT is a highly sophisticated Remote Access Trojan used by the Turla Group, primarily for cyber-espionage purposes.
- Turla SilentMoon rat
- Also known as BigBoss, Cacao, GoldenSky. Turla SilentMoon, also known as BigBoss, is a sophisticated remote access trojan linked to the cyber-espionage group Turla.
- TurlaRPC rat
- TurlaRPC is a remote access tool linked to the Turla APT group, known for cyber espionage targeting governmental and military…
- Twitoor dropper
- Twitoor is a dropper application capable of receiving commands from social media.
- TwoDash ransomware
- TwoDash is a ransomware family primarily targeting financial services and government entities in the United States and United Kingdom.
- TwoFace webshellloader
- Also known as HighShell, HyperShell, Minion. According to Unit42, TwoFace is a two-staged (loader+payload) webshell, written in C# and meant to run on webservers with ASP.NET.
- Tycoon ransomware
- This malware is written in Java and is named after references in the code.
- TypeHash credential-stealerrat
- Also known as SkinnyD. TypeHash, also known as SkinnyD, is a sophisticated remote access trojan primarily used for cyber espionage.
- Typhon Stealer credential-stealerspyware
- Also known as Typhon Reborn V2. According to PCrisk, Typhon is a stealer-type malware written in the C# programming language.
- Tyupkin trojan
- Tyupkin is a type of ATM malware that allows attackers to dispense cash from targeted ATMs by exploiting vulnerabilities in the machine's…
- UACMe exploit-kit
- Also known as Akagi. UACMe is an open source assessment tool that contains many methods for bypassing Windows User Account Control on multiple versions of the…
- UBoatRAT rat
- UBoatRAT is a remote access tool that was identified in May 2017.
- UCCU ransomware
- UCCU is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
- UDPoS ddos
- UDPoS is a malware that targets point-of-sale systems using UDP for communication and potentially conducting denial-of-service attacks.
- UFR Stealer credential-stealer
- Also known as Usteal. UFR Stealer, also known as Usteal, is a type of information stealer malware.
- UNITEDRAKE rat
- The existence of the UNITEDRAKE RAT first came to light in 2014 as part of a series of classified documents leaked by former NSA…
- UNNAM3D ransomware
- UNNAM3D is a type of ransomware designed to encrypt files on a victim's computer, demanding a ransom payment for decryption.
- UPAS credential-stealerkeylogger
- Also known as Rombrast. UPAS, also known as Rombrast, is a credential-stealing malware known for its keylogging capabilities.
- UPPERCUT backdoor
- Also known as ANEL, lena. UPPERCUT is a 32-bit HTTP-based backdoor that has been used by menuPass since at least 2017.
- UPSTYLE backdoor
- UPSTYLE is a Python-based backdoor associated with exploitation of Palo Alto firewalls using CVE-2024-3400 in early 2024.
- USBCulprit wormspyware
- According to Kaspersky, USBCulprit is a malware that is capable of scanning various paths in victim machines, collecting documents with…
- USBStealer spyware
- Also known as USB Stealer, Win32/USBStealer. USBStealer is malware that has been used by APT28 since at least 2005 to extract information from air-gapped networks.
- USBferry
- USBferry is an information stealing malware and has been used by Tropic Trooper in targeted attacks against Taiwanese and Philippine…
- USR0 ransomware
- USR0 is a type of ransomware malware. It is used by threat actors to encrypt victims' data and demand a ransom for the decryption key.
- Uh-Oh ransomware
- Uh-Oh is a ransomware variant that encrypts files on the infected systems, demanding a ransom for decryption.
- Uiwix ransomware
- Uiwix is a ransomware strain that encrypts files on infected systems and demands a ransom in cryptocurrency.
- Uiwix Ransomware ransomwareworm
- Also known as UIWIX. Uiwix is a ransomware strain that exploits the EternalBlue SMB vulnerability to infect victim systems.
- Ukash ransomware
- Ukash is a type of ransomware that locks victims' computers and demands a payment often using Ukash or other prepaid cash services.
- UltimaSMS trojan
- UltimaSMS is an Android-based premium SMS trojan that subscribes users to premium services without their consent, resulting in significant…
- Ultimo HT ransomware
- Ultimo HT is a type of ransomware that encrypts files on an infected system and demands a ransom payment for decryption keys.
- Ultra VNC rat
- UltraVNC works a bit like Remote Utilities, where a server and viewer is installed on two PCs, and the viewer is used to control the server.
- UltraCrypter ransomware
- UltraCrypter is a ransomware family that encrypts files on infected systems and demands a ransom for decryption keys.
- UltraLocker Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.