Malware Families page 51 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Umbral trojancredential-stealer
Umbral is a data-stealing Trojan that targets Windows systems.
UmbreCrypt ransomware
UmbreCrypt is a ransomware from the CrypBoss family, known for encrypting files and demanding a ransom for decryption keys.
Umbreon backdoorrootkit
Also known as Espeon. A Linux rootkit that provides backdoor access and hides from defenders.
UnblockUPC ransomware
UnblockUPC is a ransomware that encrypts a user's files and demands payment for decryption.
UnderminerEK exploit-kit
UnderminerEK is an exploit kit which has been used to deliver malware through drive-by download attacks.
Ungluk ransomware
Ransomware Ransom note instructs to use Bitmessage to get in contact with attacker - Secretishere.key - SECRETISHIDINGHEREINSIDE.KEY -…
Unidentified 001
Unidentified 001 is a malware with no detailed description available, suggesting it may be either newly discovered or not widely analyzed.
Unidentified 002 (Operation Kremlin) dropperspyware
Unnamed malware. Delivered as remote template that drops a VBS file, which uses LOLBINs to crawl the disk and exfiltrate data zipped up…
Unidentified 003
Unidentified 003 is a malware sample which currently lacks detailed public information about its characteristics, targeted techniques, or…
Unidentified 003 (Gamaredon Downloader) downloader
Gamaredon Downloader is a component of the Gamaredon Group's toolkit used to deliver additional malicious payloads.
Unidentified 005 (Sidecopy) rat
Unidentified 005, also known as Sidecopy, is a Remote Access Trojan (RAT) that has been linked to cyber espionage activities primarily…
Unidentified 006
Unidentified 007 (ARMAAN RAT) rattrojan
According to Cyble, this is an Android application that pretends to be the legitimate application for the Army Mobile Aadhaar App Network…
Unidentified 013 (Korean)
Unidentified 020 (Vault7) spywarerat
Unidentified 020, part of the Vault7 leaks, is associated with cyber espionage activities linked to intelligence gathering.
Unidentified 022 (Ransom) ransomware
Unidentified 022 is a ransomware with scant information available.
Unidentified 023
Unidentified 024 (Ransomware) ransomware
Unidentified 024 is a ransomware variant with limited available information.
Unidentified 025 (Clickfraud) botnet
Unidentified 025 is a click fraud malware that operates botnets to generate illegitimate ad clicks, thereby defrauding advertisers.
Unidentified 028
Unidentified 028 is a malware for which detailed information is currently unavailable.
Unidentified 029
This malware, named Unidentified 029, lacks sufficient information and is not classified under any specific type or family.
Unidentified 030 (Ransomware) ransomware
Unnamed ransomware that camouflages as a program performing system cleanup called "System Analyzer Pro".
Unidentified 031
Unidentified 031 is a malware entity with insufficient publicly available data for classification or attribution.
Unidentified 037
Unidentified 037 is a piece of malware with unclassified characteristics.
Unidentified 038
Unidentified 039
Unidentified 039 is a malware threat with undetermined characteristics and targets.
Unidentified 041
This malware, named Unidentified 041, currently lacks detailed information about its behavior, targeted industries, or regions.
Unidentified 042
Unidentified 044
Unidentified 045
Unidentified 045 is a malware sample with limited publicly available information.
Unidentified 047 rat
Unidentified 047 is a Remote Access Trojan (RAT) written in Delphi, known to be used by the Patchwork APT group, primarily targeting the…
Unidentified 052
Unidentified 052 is a malware with no specific identity or characterization currently available.
Unidentified 053 (Wonknu?) trojanrat
Unidentified 053, also known as Wonknu, is a remote access trojan potentially used for cyber espionage activities.
Unidentified 057
Unnamed portscanner as used in the Australian Parliament Hack (Feb 2019).
Unidentified 058
Unidentified 061 (Windows)
Was previously wrongly tagged as PoweliksDropper, now looking for additional context.
Unidentified 066 ratdownloaderdropper
This .net executable can receive commands from c2 sever, upload and download files according to the returned content, perform an…
Unidentified 067
A malware sample with insufficient information available to determine its characteristics or targets.
Unidentified 068
Unidentified 068 is currently an unknown malware with no available description or known attributes.
Unidentified 069 (Zeus Unnamed2) trojancredential-stealerbotnet
Unidentified 069, also known as Zeus Unnamed2, is a derivative of the Zeus malware family.
Unidentified 070 (Downloader) downloader
Unidentified downloader, possibly related to KONNI.
Unidentified 071 (Zeus Unnamed1) trojancredential-stealerbotnet
Unidentified 071 (Zeus Unnamed1) is a variant of the notorious Zeus banking trojan.
Unidentified 072 (Metamorfo Loader) loader
MSI-based loader that has been observed as a stager for win.metamorfo.
Unidentified 074 (Downloader) downloader
Unidentified 074 is a downloader malware with limited available information.
Unidentified 075
Unidentified 075 is an unpacked sample referred to as http_dll.dat in a blog post.
Unidentified 076 (Higaisa LNK to Shellcode) downloaderloader
Unidentified 076, also known as Higaisa LNK to Shellcode, is a malware variant that uses LNK files to execute shellcode.
Unidentified 077 (Lazarus Downloader) downloader
Unidentified 077 is a downloader attributed to the Lazarus Group, commonly associated with cyber espionage operations.
Unidentified 078 (Zebrocy Nim Loader?) loader
Suspected Zebrocy loader written in Nim, associated with the APT group often targeting Eastern European governmental entities.
Unidentified 080 trojanrat
This Trojan is a full-featured RAT capable of executing common tasks such as command execution and downloading/uploading files.
Unidentified 083 (AutoIT Stealer) credential-stealer
Unidentified 083 (AutoIT Stealer) is a credential-stealing malware that leverages AutoIT scripts to target various industries.
Unidentified 085 rat
A RAT written in .NET, potentially used by Transparent Tribe.
Unidentified 087 trojan
Symantec describes this family as an unidentified tool set used to target a range of organizations in South East Asia.
Unidentified 088 (Nim Ransomware) ransomware
Unidentified 088 is a ransomware threat written in the Nim programming language.
Unidentified 091 rat
Avast found this unidentified RAT, which abuses a code-signing certificate by the Philippine Navy.
Unidentified 092 (Confucius Backdoor) backdoorrat
According to Antiy CERT, this is a C++ backdoor that was first discovered in an attack by Confucius in September 2020.
Unidentified 093 (Sidewinder) trojan
Check Point Research observed this malware being used by Sidewinder.
Unidentified 095 (Iranian Wiper) wiper
Wiper, using EldoS RawDisk for low level access to disks.
Unidentified 096 (Keylogger) keylogger
Unidentified 096 is a keylogger malware designed to record and steal keystrokes from infected systems.
Unidentified 097 (Polonium Keylogger) keyloggercredential-stealerspyware
Unidentified 097, also known as Polonium Keylogger, is a malware used in targeted attacks to capture and exfiltrate credentials and…
Unidentified 098 (APT29 Slack Downloader) downloadertrojan
Unidentified 098, also known as APT29 Slack Downloader, is a piece of malware associated with cyber espionage activities, primarily…
Unidentified 099 (APT29 Dropbox Loader) loader
This malware uses DropBox for C2 and was spread via spear-phishing attack at government organizations.
Unidentified 100 (APT-Q-12)
Unidentified 100 (APT-Q-12) is a malware sample with limited publicly available information, making it challenging to determine its…
Unidentified 103 (FIN8) loader
Also known as Ragnar Loader, Sardonic. A malware that uses .NET to load unmanaged (shell)code which has some resemblance to BADHATCH, the IP found in the sample was referred to…
Unidentified 104
Unidentified 104 is an unknown malware entity with little available information.
Unidentified 105
Unidentified 106 ratbackdoor
This is possibly related to the MATA framework / Dacls.
Unidentified 107 (APT29) downloader
Also known as ICEBEAT. Unidentified 107, also known as ICEBEAT, is a small shellcode downloader likely used by APT29 for initial access in cyber espionage…
Unidentified 108
Unidentified 108 is a malware sample for which detailed information is currently unavailable.
Unidentified 109 (Lazarus?) trojanrat
Also known as IMEEX. Unidentified 109, also known as IMEEX, is a piece of malware associated with the Lazarus Group, suspected of North Korean origin…
Unidentified 110 (RustyFlag) credential-stealer
According to Deep Instinct, this information stealer is written in Rust and was observed in Operation Rusty Flag.
Unidentified 112 (Rust-based Stealer) credential-stealer
A Rust-based stealer, observed by Seqrite, along TTPs overlapping with Pakistan-linked APT groups.
Unidentified 113 (RAT) ratkeyloggerscreen-capture
According to Phylum, this is a RAT with these characteristics: * Registers as a scheduled task.
Unidentified 114 (APT28 InfoStealer) credential-stealerspyware
According to Trend Micro, this is a small information stealer written in .NET, that pushes its loot to a benign file sharing service and…
Unidentified 115 (Nim Loader) loader
According to Walmart, this is a loader written in Nim that contains an AmsiScanBuffer patch followed by a EtwEventWrite patch and that…
Unidentified 116 (Miner) cryptominerdownloaderdropper
This malware family delivers its artifacts packed with free and generic packers.
Unidentified 117 (Donot Loader) loader
Unidentified 117, also known as Donot Loader, is a malware associated with an advanced persistent threat group targeting South Asia.
Unidentified 118
Unidentified 118 is currently lacking detailed information and requires further investigation to determine its functionality, targeted…
Unidentified 120 loader
According to Deutsche Telekom CERT, this malware unpacks an obfuscated, multi-stage shellcode payload.
Unidentified 121 downloaderloader
unidentified_121 acts as a downloader and reflective PE loader, employing a dual-mode execution strategy based on its privilege level.
Unidentified 122 (Stealer) credential-stealerspyware
According to Datadog, this malware functions primarily as a credential and infostealer.
Unidentified 123 (Go Infostealer) credential-stealer
Also known as Go Infostealer. Unidentified 123, also known as Go Infostealer, is an information-stealing malware developed using the Go programming language.
Unidentified 124 (Azure Functions) trojan
Unidentified 124 is a malware leveraging Azure Functions for command and control communication, targeting the technology and government…
Unidentified APK 001
Unidentified APK 001 is a mobile application malware with currently unknown characteristics, distribution methods, and targets.
Unidentified APK 002
Unidentified APK 002 is a nondescript piece of malware with no detailed information regarding its behavior or targets.
Unidentified APK 004 rat
According to Check Point Research, this is a RAT that is disguised as a set of dating apps like "GrixyApp", "ZatuApp", "Catch&See"…
Unidentified APK 005
Unidentified APK 005 is a malware sample with insufficient public information regarding its behavior, industry targets, or geographical…
Unidentified APK 006 credential-stealertrojan
Information stealer posing as a fake banking app, targeting Korean users.
Unidentified APK 008 trojancredential-stealer
Android malware distributed through fake shopping websites targeting Malaysian users, targeting banking information.
Unidentified APK 009 (Chrome Recon) spyware
According to Google, a Chrome reconnaissance payload
Unidentified ASP 001 (Webshell) webshell
Unidentified ASP 001 is a webshell often used by attackers for remote access and control of a compromised server.
Unidentified ELF 004 trojanbackdoor
Implant used by APT31 on compromised SOHO infrastructure, tries to camouflage as a tool ("unifi-video") related to Ubiquiti UniFi…
Unidentified ELF 006 (Tox Backdoor) backdoorrat
Enables remote execution of scripts on a host, communicates via Tox.
Unidentified JS 001 (APT32 Profiler) spyware
Unidentified JS 001 is believed to be a profiling tool used by APT32 to gather preliminary information about potential victims.
Unidentified JS 002 downloadertrojan
Unidentified JS 002 is a JavaScript-based malware with functionalities consistent with downloaders and trojans.
Unidentified JS 003 (Emotet Downloader) downloaderdropper
According to Max Kersten, Emotet is dropped by a procedure spanned over multiple stages.
Unidentified JS 004 loader
A simple loader written in JavaScript found by Marco Ramilli.
Unidentified JS 005 (Stealer) credential-stealer
Unidentified JS 005 is a JavaScript-based malware primarily used to steal user credentials.
Unidentified JS 006 (Winter Wyvern) spyware
A script able to list folders and emails in the current Roundcube account, and to exfiltrate email messages to the C&C server by making…
Unidentified JS 007 (Zimbra Stealer) credential-stealer
According to Seqrite, this collector is delivered via a phishing mail and triggers via XSS in an active Zimbra session.
Unidentified Linux 001 exploit-kitcryptominerworm
According to Cybereason, these scripts have been used in an ongoing campaign exploiting a widespread vulnerability in the Exim MTA…