Malware Families page 52 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Unidentified PS 001 spywaredropper
Recon and exfiltration script, dropped from a LNK file.
Unidentified PS 002 (RAT) ratdownloader
A Powershell-based RAT capable of pulling further payloads, delivered through Russia-themed phishing mails.
Unidentified PS 003 (RAT) rat
This malware is a RAT written in PowerShell.
Unidentified PS 004 (RAT) rat
Unidentified PS 004 is a remote access tool (RAT) with capabilities for stealthy surveillance and remote control of compromised systems.
Unidentified PS 005 (Telegram Bot) botnet
Unidentified PS 005 is a malware sample that operates as a bot using Telegram as a communication channel.
Unidentified VBS 001
Unidentified VBS 001 is a malware with unspecified characteristics.
Unidentified VBS 004 (RAT) rat
Lab52 describes this as a light first-stage RAT used by MuddyWater and observed samples between at least November 2020 and January 2022.
Unidentified VBS 005 (Telegram Loader) loader
Unidentified VBS 005 is a VBS-based loader that uses Telegram as a communication channel.
Unidentified VBS 006 (Telegram Loader) loader
Unidentified VBS 006 is an unnamed loader that leverages the Telegram platform to potentially facilitate the distribution of malware.
Unidentified macOS 001 (UnionCryptoTrader) trojan
Unidentified macOS 001, also referred to as UnionCryptoTrader, is a macOS targeting Trojan with limited public information available.
Unikey ransomware
Unikey is a type of ransomware that encrypts files on infected systems and demands a ransom for decryption.
Unknown
This malware entry currently lacks specific details and is classified as unknown.
Unknown Crypted ransomware
Unknown Crypted is a type of ransomware. Further details about its activity and targets are not well-documented at this time.
Unknown Lock ransomware
Unknown Lock is a ransomware strain. Its specific targets and geographical spread are not well-documented.
Unknown Logger backdoor
Unknown Logger is a publicly released, free backdoor.
Unknown XTBL ransomware
Unknown XTBL is a type of ransomware that encrypts files on the victim's machine, demanding payment for decryption.
Unlckr ransomware
Unlckr is a ransomware strain that encrypts files on infected devices, demanding a ransom for the decryption key.
Unlock26 Ransomware ransomware
About: This is most likely to affect English speaking users, since the note is written in English.
Unlock92 ransomware
Unlock92 is a ransomware known for infecting systems and encrypting files, demanding a ransom for decryption.
UnluckyWare ransomware
UnluckyWare is a ransomware that encrypts files on infected systems, demanding a ransom for decryption.
Unnamed Android Ransomware ransomware
Uses APK Editor Pro. Picks and activates DEX>Smali from APK Editor. Utilizes LockService application and edits the “const-string v4…
Unnamed Bin ransomware
Unnamed Bin is a ransomware that encrypts files on a victim's computer, demanding a ransom for decryption.
Unnamed ramsomware 1 ransomware
A new in-development ransomware was discovered that has an interesting characteristic.
Unnamed ramsomware 2 ransomware
Unnamed ransomware 2 is a ransomware type malware that encrypts files on the victim's computer, demanding a ransom for decryption.
Unrans ransomware
Unrans is a type of ransomware designed to encrypt files on infected systems, demanding a ransom for file decryption.
Unsafe
No description available.
Upatre downloadertrojan
Upatre is primarly a downloader. It has been discovered in 2013 and since that time it has been widely updated. Upatre is responsible for…
UpdateAgent downloader
UpdateAgent is a malware family primarily targeting macOS systems.
UpdateHost Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Urausy ransomware
Urausy is a ransomware family known for locking victim's screens and displaying fake law enforcement messages demanding payment.
UrlZone trojancredential-stealer
Also known as Bebloh, Shiotob. UrlZone, also known as Bebloh and Shiotob, is a banking Trojan primarily targeting the financial sector.
Uroburos ratrootkit
Also known as Snake. Uroburos is a sophisticated cyber espionage tool written in C that has been used by units within Russia's Federal Security Service (FSB)…
Uroburos (OS X) rootkitspyware
Uroburos (OS X) is a sophisticated rootkit and spyware primarily used in cyber-espionage campaigns targeting government and energy sectors.
Uroburos (Windows) rootkit
Also known as Snake. Uroburos is a driver for Windows, including a bypass of PatchGuard.
Ursnif credential-stealertrojanspyware
Also known as Gozi-ISFB, PE_URSNIF, Dreambot. Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing…
UselessDisk ransomware
UselessDisk is a type of ransomware that encrypts files on an infected system, demanding a ransom for decryption keys.
UselessFiles ransomware
UselessFiles is a ransomware variant known for encrypting files and demanding a ransom for decryption.
UserFilesLocker Ransomware ransomware
Also known as CzechoSlovak Ransomware. This is most likely to affect English speaking users, since the note is written in English.
V Is Vendetta ransomware
V Is Vendetta is a ransomware family known for targeting critical infrastructure sectors such as government and energy utilities.
V8Locker Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
VALIDVICTOR spywareexploit-kit
According to Google, this reconnaissance payload uses a profiling framework drawing canvas to identify the target’s exact iPhone model, a…
VALUEVAULT credential-stealer
VALUEVAULT is a credential-stealing malware known for targeting the financial sector to exfiltrate sensitive information.
VBRANSOM 7 ransomware
VBRANSOM 7 is a ransomware family that encrypts victim's files and demands a ransom for decryption.
VBREVSHELL webshell
According to Mandiant, VBREVSHELL is a VBA macro that spawns a reverse shell relying exclusively on Windows API calls.
VBShower backdoordownloader
VBShower is a backdoor that has been used by Inception since at least 2019.
VCrypt ransomware
VCrypt is a type of ransomware that encrypts victims' files and demands a ransom for their decryption.
VEILEDSIGNAL backdoorrat
VEILEDSIGNAL is a sophisticated remote access tool (RAT) primarily targeting government and defense sectors in the US and UK.
VELETRIX loader
According to Seqrite, VELETRIX as been observed as a loader for VShell.
VENON trojan
VENON is a Trojan-type malware with limited publicly available information.
VERMIN rat
VERMIN is a remote access tool written in the Microsoft .NET framework.
VHD ransomware
VHD is a ransomware family known for targeting systems with the intent of encrypting data and demanding ransom for decryption keys.
VHD Ransomware ransomware
VHD Ransomware is a malware family that encrypts files and demands a ransom for their release.
VIGILANT CLEANER wiper
Also known as VIGILANT CHECKER. Wiper malware discovered by Japanese security firm Mitsui Bussan Secure Directions (MBSD), which is assumed to target Japan, the host…
VINETHORN backdoorspyware
According to Mandiant, VINETHORN is an Android malware family capable of a wide range of backdoor functionality.
VIP Keylogger keylogger
VIP Keylogger is a malicious software tool designed to capture and log keystrokes inputted by a user on a compromised system.
VIRTUALGATE rat
VIRTUALGATE is a remote access Trojan (RAT) known for targeting government and telecommunications sectors.
VIRTUALPIE backdoorrat
VIRTUALPIE is a lightweight backdoor written in Python that spawns an IPv6 listener on a VMware ESXi server and features command line…
VIRTUALPITA backdoor
VIRTUALPITA is a passive backdoor with ESXi and Linux vCenter variants capable of command execution, file transfer, and starting and…
VM Zeus credential-stealertrojanbotnet
Also known as VMzeus, Zberp, ZeusVM. VM Zeus, also known as VMzeus and Zberp, is a variant of the Zeus malware family.
VMola ransomware
VMola is a sophisticated ransomware family that encrypts files on infected systems, primarily targeting financial services, healthcare…
VPNFilter botnetcredential-stealerwiper
VPNFilter is a multi-stage, modular platform with versatile capabilities to support both intelligence-collection and destructive cyber…
VShell ratbackdoor
VShell is an OST framework written in Go, enabling availability of implants for multiple platforms (Windows, Linux, macOS).
VSingle backdoor
VSingle is a backdoor malware used by threat actors for espionage purposes, primarily targeting government entities.
Vaca ransomware
Vaca is a ransomware that targets various industries by encrypting files and demanding ransom for decryption keys.
Vadokrist trojan
ESET reports that Vadokrist is a Latin American banking trojan that they have been tracking since 2018 and that is active almost…
Vaggen ransomware
Vaggen is a type of ransomware known for targeting various industries.
VajraSpy spywaretrojan
VajraSpy is Android malware distributed via trojanized messaging and news applications.
Valak downloadercredential-stealer
Also known as Valek. Valak is a multi-stage modular malware that can function as a standalone information stealer or downloader, first observed in 2019…
Valkyrie Stealer credential-stealertrojan
Valkyrie Stealer is a credential-stealing malware known for targeting sensitive data from compromised systems.
ValleyRAT rat
Also known as Winos. ValleyRAT, also known as Winos, is a remote access trojan primarily used for cyber-espionage.
Vampire Bot botnetcredential-stealer
Vampire Bot is a malicious software known for its botnet and credential-stealing capabilities.
Vanguard trojanspyware
Vanguard is a sophisticated malware family used in cyber-espionage campaigns targeting government and technology sectors.
Vanguard Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Vantom rat
Vantom is a free RAT with good option and very stable.
VapeLauncher ransomware
VapeLauncher is a variant of the CryptoWire ransomware known for encrypting files and demanding ransom payments from its victims.
Vapor Ransomware ransomware
MalwareHunterTeam discovered the Vapor Ransomware that appends the .Vapor extension to encrypted files.
VaporRage downloader
Also known as BOOMMIC. VaporRage is a shellcode downloader that has been used by APT29 since at least 2021.
Varenyky
In May 2019, ESET researchers observed a spike in ESET telemetry data regarding malware targeting France.
Vasport backdoortrojan
Vasport is a trojan used by Elderwood to open a backdoor on compromised hosts.
VaultCrypt ransomware
Also known as CrypVault, Zlader, Russian. VaultCrypt is a type of ransomware that encrypts user files and demands a ransom payment for decryption.
Vawtrak botnetcredential-stealertrojan
Also known as Catch, NeverQuest, grabnew. Vawtrak, also known as Catch, NeverQuest, and grabnew, is a banking trojan used in cybercrime operations.
Veaty trojanbackdoor
Also known as Whisper. Veaty, also known by its alias Whisper, is a sophisticated malware family primarily used for espionage.
Veeam Dumper credential-stealer
Also known as Eamfo. Veeam Dumper, also known as Eamfo, is a credential stealer written in .NET.
VegaLocker ransomware
Also known as Buran, Vega. VegaLocker, also known as Buran, is a ransomware family that encrypts files on infected systems and demands a ransom for decryption.
Velso ransomware
Velso is a ransomware family known for targeting critical sectors including finance, healthcare, and technology.
Vendetta ransomware
Vendetta is a type of ransomware that encrypts files on infected systems, demanding payment for decryption keys.
Venis Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Venom Proxy trojan
According to Cisco Talos, this is a reverse proxy socks5 server-client tool originally developed for penetration testers.
Venom RAT rat
Venom RAT is a remote access trojan used to gain unauthorized access to victim systems.
VenomLNK loader
VenomLNK is the initial phase of the more_eggs malware-as-a-service.
VenomLoader loader
VenomLoader is a malware loader designed to deliver various payloads to infected systems.
VenomRAT ransomwarerat
VenomRAT is a dual-purpose malware that functions as both a remote access trojan (RAT) and ransomware.
Venomous ransomware
Ransomware written in Python and delivered as compiled executable created using PyInstaller.
Venomous Ivy ratkeylogger
Venomous Ivy is a remote access trojan (RAT) known for its use in cyber espionage campaigns, targeting sectors such as technology and…
Venus Locker ransomware
Venus Locker is a ransomware family that encrypts the victim's files and demands a ransom in exchange for a decryption key.
Venus Stealer credential-stealer
Venus Stealer is a python based Infostealer observed early 2023.
VenusLocker ransomware
VenusLocker is a form of ransomware based on the EDA2 framework, which encrypts files on the victim's machine and demands a ransom for the…
Verblecon cryptominercredential-stealerloader
This malware seems to be used for attacks installing cryptocurrency miners on infected machines.
Vermilion Strike (ELF) rat
Vermilion Strike is a Remote Access Trojan (RAT) that targets Linux systems.
Vermilion Strike (Windows) rat
Vermilion Strike is a Windows-based Remote Access Trojan (RAT) used primarily for cyber espionage activities.