Malware Families page 52 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Unidentified PS 001 spywaredropper
- Recon and exfiltration script, dropped from a LNK file.
- Unidentified PS 002 (RAT) ratdownloader
- A Powershell-based RAT capable of pulling further payloads, delivered through Russia-themed phishing mails.
- Unidentified PS 003 (RAT) rat
- This malware is a RAT written in PowerShell.
- Unidentified PS 004 (RAT) rat
- Unidentified PS 004 is a remote access tool (RAT) with capabilities for stealthy surveillance and remote control of compromised systems.
- Unidentified PS 005 (Telegram Bot) botnet
- Unidentified PS 005 is a malware sample that operates as a bot using Telegram as a communication channel.
- Unidentified VBS 001
- Unidentified VBS 001 is a malware with unspecified characteristics.
- Unidentified VBS 004 (RAT) rat
- Lab52 describes this as a light first-stage RAT used by MuddyWater and observed samples between at least November 2020 and January 2022.
- Unidentified VBS 005 (Telegram Loader) loader
- Unidentified VBS 005 is a VBS-based loader that uses Telegram as a communication channel.
- Unidentified VBS 006 (Telegram Loader) loader
- Unidentified VBS 006 is an unnamed loader that leverages the Telegram platform to potentially facilitate the distribution of malware.
- Unidentified macOS 001 (UnionCryptoTrader) trojan
- Unidentified macOS 001, also referred to as UnionCryptoTrader, is a macOS targeting Trojan with limited public information available.
- Unikey ransomware
- Unikey is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption.
- Unknown
- This malware entry currently lacks specific details and is classified as unknown.
- Unknown Crypted ransomware
- Unknown Crypted is a type of ransomware. Further details about its activity and targets are not well-documented at this time.
- Unknown Lock ransomware
- Unknown Lock is a ransomware strain. Its specific targets and geographical spread are not well-documented.
- Unknown Logger backdoor
- Unknown Logger is a publicly released, free backdoor.
- Unknown XTBL ransomware
- Unknown XTBL is a type of ransomware that encrypts files on the victim's machine, demanding payment for decryption.
- Unlckr ransomware
- Unlckr is a ransomware strain that encrypts files on infected devices, demanding a ransom for the decryption key.
- Unlock26 Ransomware ransomware
- About: This is most likely to affect English speaking users, since the note is written in English.
- Unlock92 ransomware
- Unlock92 is a ransomware known for infecting systems and encrypting files, demanding a ransom for decryption.
- UnluckyWare ransomware
- UnluckyWare is a ransomware that encrypts files on infected systems, demanding a ransom for decryption.
- Unnamed Android Ransomware ransomware
- Uses APK Editor Pro. Picks and activates DEX>Smali from APK Editor. Utilizes LockService application and edits the “const-string v4…
- Unnamed Bin ransomware
- Unnamed Bin is a ransomware that encrypts files on a victim's computer, demanding a ransom for decryption.
- Unnamed ramsomware 1 ransomware
- A new in-development ransomware was discovered that has an interesting characteristic.
- Unnamed ramsomware 2 ransomware
- Unnamed ransomware 2 is a ransomware type malware that encrypts files on the victim's computer, demanding a ransom for decryption.
- Unrans ransomware
- Unrans is a type of ransomware designed to encrypt files on infected systems, demanding a ransom for file decryption.
- Unsafe
- No description available.
- Upatre downloadertrojan
- Upatre is primarly a downloader. It has been discovered in 2013 and since that time it has been widely updated. Upatre is responsible for…
- UpdateAgent downloader
- UpdateAgent is a malware family primarily targeting macOS systems.
- UpdateHost Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Urausy ransomware
- Urausy is a ransomware family known for locking victim's screens and displaying fake law enforcement messages demanding payment.
- UrlZone trojancredential-stealer
- Also known as Bebloh, Shiotob. UrlZone, also known as Bebloh and Shiotob, is a banking Trojan primarily targeting the financial sector.
- Uroburos ratrootkit
- Also known as Snake. Uroburos is a sophisticated cyber espionage tool written in C that has been used by units within Russia's Federal Security Service (FSB)…
- Uroburos (OS X) rootkitspyware
- Uroburos (OS X) is a sophisticated rootkit and spyware primarily used in cyber-espionage campaigns targeting government and energy sectors.
- Uroburos (Windows) rootkit
- Also known as Snake. Uroburos is a driver for Windows, including a bypass of PatchGuard.
- Ursnif credential-stealertrojanspyware
- Also known as Gozi-ISFB, PE_URSNIF, Dreambot. Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing…
- UselessDisk ransomware
- UselessDisk is a type of ransomware that encrypts files on an infected system, demanding a ransom for decryption keys.
- UselessFiles ransomware
- UselessFiles is a ransomware variant known for encrypting files and demanding a ransom for decryption.
- UserFilesLocker Ransomware ransomware
- Also known as CzechoSlovak Ransomware. This is most likely to affect English speaking users, since the note is written in English.
- V Is Vendetta ransomware
- V Is Vendetta is a ransomware family known for targeting critical infrastructure sectors such as government and energy utilities.
- V8Locker Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- VALIDVICTOR spywareexploit-kit
- According to Google, this reconnaissance payload uses a profiling framework drawing canvas to identify the target’s exact iPhone model, a…
- VALUEVAULT credential-stealer
- VALUEVAULT is a credential-stealing malware known for targeting the financial sector to exfiltrate sensitive information.
- VBRANSOM 7 ransomware
- VBRANSOM 7 is a ransomware family that encrypts victim's files and demands a ransom for decryption.
- VBREVSHELL webshell
- According to Mandiant, VBREVSHELL is a VBA macro that spawns a reverse shell relying exclusively on Windows API calls.
- VBShower backdoordownloader
- VBShower is a backdoor that has been used by Inception since at least 2019.
- VCrypt ransomware
- VCrypt is a type of ransomware that encrypts victims' files and demands a ransom for their decryption.
- VEILEDSIGNAL backdoorrat
- VEILEDSIGNAL is a sophisticated remote access tool (RAT) primarily targeting government and defense sectors in the US and UK.
- VELETRIX loader
- According to Seqrite, VELETRIX as been observed as a loader for VShell.
- VENON trojan
- VENON is a Trojan-type malware with limited publicly available information.
- VERMIN rat
- VERMIN is a remote access tool written in the Microsoft .NET framework.
- VHD ransomware
- VHD is a ransomware family known for targeting systems with the intent of encrypting data and demanding ransom for decryption keys.
- VHD Ransomware ransomware
- VHD Ransomware is a malware family that encrypts files and demands a ransom for their release.
- VIGILANT CLEANER wiper
- Also known as VIGILANT CHECKER. Wiper malware discovered by Japanese security firm Mitsui Bussan Secure Directions (MBSD), which is assumed to target Japan, the host…
- VINETHORN backdoorspyware
- According to Mandiant, VINETHORN is an Android malware family capable of a wide range of backdoor functionality.
- VIP Keylogger keylogger
- VIP Keylogger is a malicious software tool designed to capture and log keystrokes inputted by a user on a compromised system.
- VIRTUALGATE rat
- VIRTUALGATE is a remote access Trojan (RAT) known for targeting government and telecommunications sectors.
- VIRTUALPIE backdoorrat
- VIRTUALPIE is a lightweight backdoor written in Python that spawns an IPv6 listener on a VMware ESXi server and features command line…
- VIRTUALPITA backdoor
- VIRTUALPITA is a passive backdoor with ESXi and Linux vCenter variants capable of command execution, file transfer, and starting and…
- VM Zeus credential-stealertrojanbotnet
- Also known as VMzeus, Zberp, ZeusVM. VM Zeus, also known as VMzeus and Zberp, is a variant of the Zeus malware family.
- VMola ransomware
- VMola is a sophisticated ransomware family that encrypts files on infected systems, primarily targeting financial services, healthcare…
- VPNFilter botnetcredential-stealerwiper
- VPNFilter is a multi-stage, modular platform with versatile capabilities to support both intelligence-collection and destructive cyber…
- VShell ratbackdoor
- VShell is an OST framework written in Go, enabling availability of implants for multiple platforms (Windows, Linux, macOS).
- VSingle backdoor
- VSingle is a backdoor malware used by threat actors for espionage purposes, primarily targeting government entities.
- Vaca ransomware
- Vaca is a ransomware that targets various industries by encrypting files and demanding ransom for decryption keys.
- Vadokrist trojan
- ESET reports that Vadokrist is a Latin American banking trojan that they have been tracking since 2018 and that is active almost…
- Vaggen ransomware
- Vaggen is a type of ransomware known for targeting various industries.
- VajraSpy spywaretrojan
- VajraSpy is Android malware distributed via trojanized messaging and news applications.
- Valak downloadercredential-stealer
- Also known as Valek. Valak is a multi-stage modular malware that can function as a standalone information stealer or downloader, first observed in 2019…
- Valkyrie Stealer credential-stealertrojan
- Valkyrie Stealer is a credential-stealing malware known for targeting sensitive data from compromised systems.
- ValleyRAT rat
- Also known as Winos. ValleyRAT, also known as Winos, is a remote access trojan primarily used for cyber-espionage.
- Vampire Bot botnetcredential-stealer
- Vampire Bot is a malicious software known for its botnet and credential-stealing capabilities.
- Vanguard trojanspyware
- Vanguard is a sophisticated malware family used in cyber-espionage campaigns targeting government and technology sectors.
- Vanguard Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Vantom rat
- Vantom is a free RAT with good option and very stable.
- VapeLauncher ransomware
- VapeLauncher is a variant of the CryptoWire ransomware known for encrypting files and demanding ransom payments from its victims.
- Vapor Ransomware ransomware
- MalwareHunterTeam discovered the Vapor Ransomware that appends the .Vapor extension to encrypted files.
- VaporRage downloader
- Also known as BOOMMIC. VaporRage is a shellcode downloader that has been used by APT29 since at least 2021.
- Varenyky
- In May 2019, ESET researchers observed a spike in ESET telemetry data regarding malware targeting France.
- Vasport backdoortrojan
- Vasport is a trojan used by Elderwood to open a backdoor on compromised hosts.
- VaultCrypt ransomware
- Also known as CrypVault, Zlader, Russian. VaultCrypt is a type of ransomware that encrypts user files and demands a ransom payment for decryption.
- Vawtrak botnetcredential-stealertrojan
- Also known as Catch, NeverQuest, grabnew. Vawtrak, also known as Catch, NeverQuest, and grabnew, is a banking trojan used in cybercrime operations.
- Veaty trojanbackdoor
- Also known as Whisper. Veaty, also known by its alias Whisper, is a sophisticated malware family primarily used for espionage.
- Veeam Dumper credential-stealer
- Also known as Eamfo. Veeam Dumper, also known as Eamfo, is a credential stealer written in .NET.
- VegaLocker ransomware
- Also known as Buran, Vega. VegaLocker, also known as Buran, is a ransomware family that encrypts files on infected systems and demands a ransom for decryption.
- Velso ransomware
- Velso is a ransomware family known for targeting critical sectors including finance, healthcare, and technology.
- Vendetta ransomware
- Vendetta is a type of ransomware that encrypts files on infected systems, demanding payment for decryption keys.
- Venis Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Venom Proxy trojan
- According to Cisco Talos, this is a reverse proxy socks5 server-client tool originally developed for penetration testers.
- Venom RAT rat
- Venom RAT is a remote access trojan used to gain unauthorized access to victim systems.
- VenomLNK loader
- VenomLNK is the initial phase of the more_eggs malware-as-a-service.
- VenomLoader loader
- VenomLoader is a malware loader designed to deliver various payloads to infected systems.
- VenomRAT ransomwarerat
- VenomRAT is a dual-purpose malware that functions as both a remote access trojan (RAT) and ransomware.
- Venomous ransomware
- Ransomware written in Python and delivered as compiled executable created using PyInstaller.
- Venomous Ivy ratkeylogger
- Venomous Ivy is a remote access trojan (RAT) known for its use in cyber espionage campaigns, targeting sectors such as technology and…
- Venus Locker ransomware
- Venus Locker is a ransomware family that encrypts the victim's files and demands a ransom in exchange for a decryption key.
- Venus Stealer credential-stealer
- Venus Stealer is a python based Infostealer observed early 2023.
- VenusLocker ransomware
- VenusLocker is a form of ransomware based on the EDA2 framework, which encrypts files on the victim's machine and demands a ransom for the…
- Verblecon cryptominercredential-stealerloader
- This malware seems to be used for attacks installing cryptocurrency miners on infected machines.
- Vermilion Strike (ELF) rat
- Vermilion Strike is a Remote Access Trojan (RAT) that targets Linux systems.
- Vermilion Strike (Windows) rat
- Vermilion Strike is a Windows-based Remote Access Trojan (RAT) used primarily for cyber espionage activities.