Malware Families page 51 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Umbral trojancredential-stealer
- Umbral is a data-stealing Trojan that targets Windows systems.
- UmbreCrypt ransomware
- UmbreCrypt is a ransomware from the CrypBoss family, known for encrypting files and demanding a ransom for decryption keys.
- Umbreon backdoorrootkit
- Also known as Espeon. A Linux rootkit that provides backdoor access and hides from defenders.
- UnblockUPC ransomware
- UnblockUPC is a ransomware that encrypts a user's files and demands payment for decryption.
- UnderminerEK exploit-kit
- UnderminerEK is an exploit kit which has been used to deliver malware through drive-by download attacks.
- Ungluk ransomware
- Ransomware Ransom note instructs to use Bitmessage to get in contact with attacker - Secretishere.key - SECRETISHIDINGHEREINSIDE.KEY -…
- Unidentified 001
- Unidentified 001 is a malware with no detailed description available, suggesting it may be either newly discovered or not widely analyzed.
- Unidentified 002 (Operation Kremlin) dropperspyware
- Unnamed malware. Delivered as remote template that drops a VBS file, which uses LOLBINs to crawl the disk and exfiltrate data zipped up…
- Unidentified 003
- Unidentified 003 is a malware sample which currently lacks detailed public information about its characteristics, targeted techniques, or…
- Unidentified 003 (Gamaredon Downloader) downloader
- Gamaredon Downloader is a component of the Gamaredon Group's toolkit used to deliver additional malicious payloads.
- Unidentified 005 (Sidecopy) rat
- Unidentified 005, also known as Sidecopy, is a Remote Access Trojan (RAT) that has been linked to cyber espionage activities primarily…
- Unidentified 006
- Unidentified 007 (ARMAAN RAT) rattrojan
- According to Cyble, this is an Android application that pretends to be the legitimate application for the Army Mobile Aadhaar App Network…
- Unidentified 013 (Korean)
- Unidentified 020 (Vault7) spywarerat
- Unidentified 020, part of the Vault7 leaks, is associated with cyber espionage activities linked to intelligence gathering.
- Unidentified 022 (Ransom) ransomware
- Unidentified 022 is a ransomware with scant information available.
- Unidentified 023
- Unidentified 024 (Ransomware) ransomware
- Unidentified 024 is a ransomware variant with limited available information.
- Unidentified 025 (Clickfraud) botnet
- Unidentified 025 is a click fraud malware that operates botnets to generate illegitimate ad clicks, thereby defrauding advertisers.
- Unidentified 028
- Unidentified 028 is a malware for which detailed information is currently unavailable.
- Unidentified 029
- This malware, named Unidentified 029, lacks sufficient information and is not classified under any specific type or family.
- Unidentified 030 (Ransomware) ransomware
- Unnamed ransomware that camouflages as a program performing system cleanup called "System Analyzer Pro".
- Unidentified 031
- Unidentified 031 is a malware entity with insufficient publicly available data for classification or attribution.
- Unidentified 037
- Unidentified 037 is a piece of malware with unclassified characteristics.
- Unidentified 038
- Unidentified 039
- Unidentified 039 is a malware threat with undetermined characteristics and targets.
- Unidentified 041
- This malware, named Unidentified 041, currently lacks detailed information about its behavior, targeted industries, or regions.
- Unidentified 042
- Unidentified 044
- Unidentified 045
- Unidentified 045 is a malware sample with limited publicly available information.
- Unidentified 047 rat
- Unidentified 047 is a Remote Access Trojan (RAT) written in Delphi, known to be used by the Patchwork APT group, primarily targeting the…
- Unidentified 052
- Unidentified 052 is a malware with no specific identity or characterization currently available.
- Unidentified 053 (Wonknu?) trojanrat
- Unidentified 053, also known as Wonknu, is a remote access trojan potentially used for cyber espionage activities.
- Unidentified 057
- Unnamed portscanner as used in the Australian Parliament Hack (Feb 2019).
- Unidentified 058
- Unidentified 061 (Windows)
- Was previously wrongly tagged as PoweliksDropper, now looking for additional context.
- Unidentified 066 ratdownloaderdropper
- This .net executable can receive commands from c2 sever, upload and download files according to the returned content, perform an…
- Unidentified 067
- A malware sample with insufficient information available to determine its characteristics or targets.
- Unidentified 068
- Unidentified 068 is currently an unknown malware with no available description or known attributes.
- Unidentified 069 (Zeus Unnamed2) trojancredential-stealerbotnet
- Unidentified 069, also known as Zeus Unnamed2, is a derivative of the Zeus malware family.
- Unidentified 070 (Downloader) downloader
- Unidentified downloader, possibly related to KONNI.
- Unidentified 071 (Zeus Unnamed1) trojancredential-stealerbotnet
- Unidentified 071 (Zeus Unnamed1) is a variant of the notorious Zeus banking trojan.
- Unidentified 072 (Metamorfo Loader) loader
- MSI-based loader that has been observed as a stager for win.metamorfo.
- Unidentified 074 (Downloader) downloader
- Unidentified 074 is a downloader malware with limited available information.
- Unidentified 075
- Unidentified 075 is an unpacked sample referred to as http_dll.dat in a blog post.
- Unidentified 076 (Higaisa LNK to Shellcode) downloaderloader
- Unidentified 076, also known as Higaisa LNK to Shellcode, is a malware variant that uses LNK files to execute shellcode.
- Unidentified 077 (Lazarus Downloader) downloader
- Unidentified 077 is a downloader attributed to the Lazarus Group, commonly associated with cyber espionage operations.
- Unidentified 078 (Zebrocy Nim Loader?) loader
- Suspected Zebrocy loader written in Nim, associated with the APT group often targeting Eastern European governmental entities.
- Unidentified 080 trojanrat
- This Trojan is a full-featured RAT capable of executing common tasks such as command execution and downloading/uploading files.
- Unidentified 083 (AutoIT Stealer) credential-stealer
- Unidentified 083 (AutoIT Stealer) is a credential-stealing malware that leverages AutoIT scripts to target various industries.
- Unidentified 085 rat
- A RAT written in .NET, potentially used by Transparent Tribe.
- Unidentified 087 trojan
- Symantec describes this family as an unidentified tool set used to target a range of organizations in South East Asia.
- Unidentified 088 (Nim Ransomware) ransomware
- Unidentified 088 is a ransomware threat written in the Nim programming language.
- Unidentified 091 rat
- Avast found this unidentified RAT, which abuses a code-signing certificate by the Philippine Navy.
- Unidentified 092 (Confucius Backdoor) backdoorrat
- According to Antiy CERT, this is a C++ backdoor that was first discovered in an attack by Confucius in September 2020.
- Unidentified 093 (Sidewinder) trojan
- Check Point Research observed this malware being used by Sidewinder.
- Unidentified 095 (Iranian Wiper) wiper
- Wiper, using EldoS RawDisk for low level access to disks.
- Unidentified 096 (Keylogger) keylogger
- Unidentified 096 is a keylogger malware designed to record and steal keystrokes from infected systems.
- Unidentified 097 (Polonium Keylogger) keyloggercredential-stealerspyware
- Unidentified 097, also known as Polonium Keylogger, is a malware used in targeted attacks to capture and exfiltrate credentials and…
- Unidentified 098 (APT29 Slack Downloader) downloadertrojan
- Unidentified 098, also known as APT29 Slack Downloader, is a piece of malware associated with cyber espionage activities, primarily…
- Unidentified 099 (APT29 Dropbox Loader) loader
- This malware uses DropBox for C2 and was spread via spear-phishing attack at government organizations.
- Unidentified 100 (APT-Q-12)
- Unidentified 100 (APT-Q-12) is a malware sample with limited publicly available information, making it challenging to determine its…
- Unidentified 103 (FIN8) loader
- Also known as Ragnar Loader, Sardonic. A malware that uses .NET to load unmanaged (shell)code which has some resemblance to BADHATCH, the IP found in the sample was referred to…
- Unidentified 104
- Unidentified 104 is an unknown malware entity with little available information.
- Unidentified 105
- Unidentified 106 ratbackdoor
- This is possibly related to the MATA framework / Dacls.
- Unidentified 107 (APT29) downloader
- Also known as ICEBEAT. Unidentified 107, also known as ICEBEAT, is a small shellcode downloader likely used by APT29 for initial access in cyber espionage…
- Unidentified 108
- Unidentified 108 is a malware sample for which detailed information is currently unavailable.
- Unidentified 109 (Lazarus?) trojanrat
- Also known as IMEEX. Unidentified 109, also known as IMEEX, is a piece of malware associated with the Lazarus Group, suspected of North Korean origin…
- Unidentified 110 (RustyFlag) credential-stealer
- According to Deep Instinct, this information stealer is written in Rust and was observed in Operation Rusty Flag.
- Unidentified 112 (Rust-based Stealer) credential-stealer
- A Rust-based stealer, observed by Seqrite, along TTPs overlapping with Pakistan-linked APT groups.
- Unidentified 113 (RAT) ratkeyloggerscreen-capture
- According to Phylum, this is a RAT with these characteristics: * Registers as a scheduled task.
- Unidentified 114 (APT28 InfoStealer) credential-stealerspyware
- According to Trend Micro, this is a small information stealer written in .NET, that pushes its loot to a benign file sharing service and…
- Unidentified 115 (Nim Loader) loader
- According to Walmart, this is a loader written in Nim that contains an AmsiScanBuffer patch followed by a EtwEventWrite patch and that…
- Unidentified 116 (Miner) cryptominerdownloaderdropper
- This malware family delivers its artifacts packed with free and generic packers.
- Unidentified 117 (Donot Loader) loader
- Unidentified 117, also known as Donot Loader, is a malware associated with an advanced persistent threat group targeting South Asia.
- Unidentified 118
- Unidentified 118 is currently lacking detailed information and requires further investigation to determine its functionality, targeted…
- Unidentified 120 loader
- According to Deutsche Telekom CERT, this malware unpacks an obfuscated, multi-stage shellcode payload.
- Unidentified 121 downloaderloader
- unidentified_121 acts as a downloader and reflective PE loader, employing a dual-mode execution strategy based on its privilege level.
- Unidentified 122 (Stealer) credential-stealerspyware
- According to Datadog, this malware functions primarily as a credential and infostealer.
- Unidentified 123 (Go Infostealer) credential-stealer
- Also known as Go Infostealer. Unidentified 123, also known as Go Infostealer, is an information-stealing malware developed using the Go programming language.
- Unidentified 124 (Azure Functions) trojan
- Unidentified 124 is a malware leveraging Azure Functions for command and control communication, targeting the technology and government…
- Unidentified APK 001
- Unidentified APK 001 is a mobile application malware with currently unknown characteristics, distribution methods, and targets.
- Unidentified APK 002
- Unidentified APK 002 is a nondescript piece of malware with no detailed information regarding its behavior or targets.
- Unidentified APK 004 rat
- According to Check Point Research, this is a RAT that is disguised as a set of dating apps like "GrixyApp", "ZatuApp", "Catch&See"…
- Unidentified APK 005
- Unidentified APK 005 is a malware sample with insufficient public information regarding its behavior, industry targets, or geographical…
- Unidentified APK 006 credential-stealertrojan
- Information stealer posing as a fake banking app, targeting Korean users.
- Unidentified APK 008 trojancredential-stealer
- Android malware distributed through fake shopping websites targeting Malaysian users, targeting banking information.
- Unidentified APK 009 (Chrome Recon) spyware
- According to Google, a Chrome reconnaissance payload
- Unidentified ASP 001 (Webshell) webshell
- Unidentified ASP 001 is a webshell often used by attackers for remote access and control of a compromised server.
- Unidentified ELF 004 trojanbackdoor
- Implant used by APT31 on compromised SOHO infrastructure, tries to camouflage as a tool ("unifi-video") related to Ubiquiti UniFi…
- Unidentified ELF 006 (Tox Backdoor) backdoorrat
- Enables remote execution of scripts on a host, communicates via Tox.
- Unidentified JS 001 (APT32 Profiler) spyware
- Unidentified JS 001 is believed to be a profiling tool used by APT32 to gather preliminary information about potential victims.
- Unidentified JS 002 downloadertrojan
- Unidentified JS 002 is a JavaScript-based malware with functionalities consistent with downloaders and trojans.
- Unidentified JS 003 (Emotet Downloader) downloaderdropper
- According to Max Kersten, Emotet is dropped by a procedure spanned over multiple stages.
- Unidentified JS 004 loader
- A simple loader written in JavaScript found by Marco Ramilli.
- Unidentified JS 005 (Stealer) credential-stealer
- Unidentified JS 005 is a JavaScript-based malware primarily used to steal user credentials.
- Unidentified JS 006 (Winter Wyvern) spyware
- A script able to list folders and emails in the current Roundcube account, and to exfiltrate email messages to the C&C server by making…
- Unidentified JS 007 (Zimbra Stealer) credential-stealer
- According to Seqrite, this collector is delivered via a phishing mail and triggers via XSS in an active Zimbra session.
- Unidentified Linux 001 exploit-kitcryptominerworm
- According to Cybereason, these scripts have been used in an ongoing campaign exploiting a widespread vulnerability in the Exim MTA…