Malware Families page 53 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- VersaMem webshell
- VersaMem is a web shell designed for deployment to Versa Director servers following exploitation.
- Vetta Loader loaderdownloader
- Also known as BrokerLoader, EMPTYSPACE. Vetta Loader is a persistent Loader spreading with infected USB drives.
- VevoLocker ransomware
- VevoLocker is a ransomware known for encrypting users' files and demanding a ransom for their release.
- Vflooder worm
- Vflooder floods VirusTotal by infinitely submitting a copy of itself.
- Vfokx trojan
- Vfokx is a Trojan malware with limited detailed information available.
- ViACrypt ransomware
- ViACrypt is a type of ransomware that encrypts files on infected systems, demanding cryptocurrency payments in exchange for decryption keys.
- Viagra ransomware
- Viagra is a ransomware strain known for encrypting files on victim machines and demanding a ransom payment for file decryption.
- ViceLeaker spyware
- Also known as Triout. ViceLeaker is a spyware framework, capable of extensive surveillance and data exfiltration operations, primarily targeting devices…
- Vicesociety ransomware
- Vice Society is a ransomware group known for targeting sectors such as education and healthcare, often deploying double-extortion tactics…
- VictoryGate cryptominerbotnet
- VictoryGate was the name of a cryptomining botnet, which was disrupted by ESET researchers in April 2020.
- Vidar credential-stealerspyware
- Vidar is a forked malware based on Arkei.
- VideoBelle ransomware
- ransomware
- Vigram downloader
- Also known as WizardUpdate. Vigram, also known as WizardUpdate, is a malware family primarily targeting macOS systems.
- ViiperWare ransomware
- ViiperWare is a ransomware strain that encrypts files on the infected system and demands a ransom for decryption.
- VileRAT rat
- VileRAT is a sophisticated Remote Access Trojan primarily targeting financial institutions.
- Vilsa Stealer credential-stealerspyware
- Vilsa Stealer is a credential-stealing malware that targets sensitive information from compromised systems.
- VindowsLocker Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Viper RAT rat
- Viper RAT is a sophisticated remote access trojan primarily targeting Android devices.
- ViperRAT spywarerat
- ViperRAT is sophisticated surveillanceware that has been in operation since at least 2015 and was used to target the Israeli Defense Force.
- ViperSoftX cryptominertrojan
- ViperSoftX is a cryptojacking and data-stealing malware primarily used to deploy cryptocurrency miners.
- Virlock ransomwarevirusworm
- Also known as NSMF. Virlock is a polymorphic ransomware known for its self-replication capabilities.
- Viro ransomware
- Viro is a ransomware that encrypts files on infected systems, demanding a ransom payment for decryption.
- ViroBotnet ransomwarebotnet
- ViroBotnet is a type of ransomware that also operates as a botnet.
- Virus RAT rat
- Virus RAT is a remote access tool that facilitates unauthorized access and control of infected systems.
- Virus-Encoder ransomware
- Also known as CrySiS. Virus-Encoder, also known as CrySiS, is a family of ransomware targeting various industries globally by encrypting files and demanding…
- Virut botnetvirus
- Virut is a polmorphic malware known for its ability to infect executable files and spread through removable drives and network shares.
- VisionCrypt ransomware
- VisionCrypt is a ransomware that encrypts files on infected systems and demands a ransom for decryption.
- Vizom trojancredential-stealer
- Vizom is a malware family primarily targeting financial institutions in Brazil.
- Vjw0rm ratworm
- VJW0rm (aka Vengeance Justice Worm) is a publicly available, modular JavaScript RAT.
- Vobfus wormdownloader
- Also known as Beebone. Malware of this family searches for computers on a network and creates copies of itself in folders with open access.
- Vohuk ransomware
- Vohuk is a ransomware family that encrypts files on target systems, demanding a ransom for decryption.
- Void ransomware
- Also known as VoidCrypt. Void, also known as VoidCrypt, is a ransomware family known for encrypting files and demanding a ransom in cryptocurrency.
- VoidCrypt ransomware
- VoidCrypt is a ransomware that encrypts files on a victim's system, demanding a ransom for decryption.
- VoidLink rootkitcredential-stealertrojan
- VoidLink is a cloud-native Linux malware family designed as a modular post-exploitation framework for modern cloud and containerized…
- VoidRAT rat
- VoidRAT is a sophisticated remote access trojan used primarily for cyber espionage.
- Voidoor backdoor
- Voidoor is an advanced malware designed to provide unauthorized access to infected systems.
- Voldemort backdoorrat
- Voldemort is a backdoor discovered by Proofpoint in August 2024.
- Volgmer backdoortrojan
- Also known as FALLCHILL, Manuscrypt. Volgmer is a backdoor Trojan designed to provide covert access to a compromised system.
- VorteX rattrojan
- VorteX is a sophisticated Remote Access Trojan (RAT) used for stealing sensitive information from targeted systems.
- Vortex Ransomware ransomware
- Also known as Ŧl๏tєгค гคภร๏๓ฬคгє. This is most likely to affect English speaking users, since the note is written in English.
- Vovalex ransomware
- Vovalex is a type of ransomware that encrypts files on victims' systems and demands a ransom payment for decryption keys.
- Vreikstadi trojan
- Vreikstadi is a trojan malware family with limited publicly available information.
- Vsop ransomware
- Vsop, also known as Onix/Onyx, is a ransomware family targeting financial services and other sectors in multiple countries.
- Vulston ransomware
- Vulston is a ransomware family known for encrypting files and demanding ransom payments.
- Vultur trojanscreen-capturecredential-stealer
- Also known as Vulture. Vultur is an Android banking trojan that primarily targets financial services.
- Vulturi credential-stealerspyware
- Vulturi is an information-stealing malware designed to exfiltrate sensitive data, particularly credentials, from infected systems.
- Vurten ransomware
- Vurten is a ransomware family that targets various industries, notably financial services and technology.
- VxLock Ransomware ransomware
- Developed in Visual Studios in 2010. Original name is VxCrypt. This ransomware encrypts your files, including photos, music, MS office…
- Vyveva RAT rat
- Vyveva is a remote access trojan that uses the Tor library for communication with C&C.
- W4SP Stealer credential-stealertrojan
- A basic info stealer w/ some capability to inject code into legit applications.
- WARPWIRE credential-stealer
- WARPWIRE is a Javascript credential stealer that targets plaintext passwords and usernames for exfiltration that was used during Cutting…
- WAVESHAPER backdoor
- According to Mandiant, WAVESHAPER is a backdoor written in C++ and packed by an unknown packer that targets macOS.
- WEBC2 backdoor
- WEBC2 is a family of backdoor malware used by APT1 as early as July 2006.
- WEEVILPROXY credential-stealerspywaretrojan
- Also known as JSCEAL. WEEVILPROXY is a sophisticated and featureful stealer which has a payload primarily written in NodeJS.
- WHIRLPOOL ransomware
- WHIRLPOOL is a ransomware family primarily targeting financial services and government sectors.
- WINDSHIELD backdoor
- WINDSHIELD is a signature backdoor attributed to the APT32 group, known for targeting Southeast Asian countries, impacting sectors such as…
- WINELOADER loader
- WINELOADER is a malware loader used to deliver various types of malicious payloads.
- WINERACK backdoor
- WINERACK is a backdoor used by APT37, known for targeting the government and technology sectors, primarily in South Korea.
- WIREFIRE webshelltrojan
- Also known as GIFTEDVISITOR. WIREFIRE is a web shell written in Python that exists as trojanized logic to the visits.py component of Ivanti Connect Secure VPN…
- WMI Ghost backdoorrat
- Also known as Syndicasec, Wimmie. WMI Ghost, also known as Syndicasec or Wimmie, is a stealthy remote access tool (RAT) that leverages Windows Management Instrumentation…
- WMImplant rat
- WMImplant is a remote access tool (RAT) primarily associated with cyber espionage activities targeting government and defense sectors.
- WORMHOLE backdoorworm
- WORMHOLE is a TCP tunneler that is dynamically configurable from a C&C server and can communicate with an additional remote machine…
- WRECKSTEEL credential-stealerscreen-capture
- According to CERT-UA, this is a stealer targeting a range of file extensions and creating screenshots of the compromised machine to be…
- WSCSPL backdoorrat
- WSCSPL is a remote access tool (RAT) used for cyber espionage activities.
- WSO webshell
- Also known as Webshell by Orb. WSO, also known as Webshell by Orb, is a web-based shell used by attackers to gain and maintain access to compromised servers.
- WTDI ransomware
- WTDI is a ransomware family known for encrypting files on infected systems and demanding ransom payments, predominantly targeting critical…
- Wadhrama ransomware
- Wadhrama is a ransomware family that encrypts victims' files and demands a ransom payment in cryptocurrency.
- Waffle ransomware
- Waffle is a ransomware strain known for encrypting victim's files and demanding a ransom payment for decryption.
- Wainscot
- No description available.
- Waiting ransomware
- The 'Waiting' ransomware encrypts files on infected systems and demands a ransom for decryption.
- Waldo ransomware
- Waldo is a ransomware variant known for encrypting files and demanding a ransom for their decryption.
- WalkLoader loaderdropper
- WalkLoader is a malware loader that facilitates the delivery of various malicious payloads.
- WallyShack backdoorransomware
- WallyShack is a sophisticated malware family primarily used for cyber espionage and ransomware attacks targeting technology…
- Wanna Decryptor Portuguese ransomwareworm
- Wanna Decryptor Portuguese, also known as WannaCry, is a ransomware and worm variant that encrypts files and demands ransom.
- WannaCash ransomware
- WannaCash is a ransomware malware primarily targeting financial services and retail sectors.
- WannaCry ransomwareworm
- Also known as WanaCry, WanaCrypt, WanaCrypt0r. WannaCry is ransomware that was first seen in a global attack during May 2017, which affected more than 150 countries.
- WannaDie ransomwareworm
- WannaDie is a type of ransomware similar to WannaCry, encrypting files on the infected devices and demanding ransom payments from victims…
- WannaHusky ransomware
- According to Mars, WannaHusky is a Nim-compiled ransomware malware sample, created for demonstration purposes and provided as part of the…
- WannaMine cryptominer
- WannaMine is a cryptocurrency mining malware that spreads laterally through infected networks using exploits and credential-stealing…
- WannaPeace ransomware
- WannaPeace is a ransomware family that primarily encrypts user files and demands a ransom payment in cryptocurrency for the decryption key.
- WannaRen ransomware
- WannaRen is ransomware that encrypts files on infected systems, demanding a ransom for decryption.
- WannaRen Downloader downloader
- WannaRen Downloader is a type of malware that facilitates the downloading of other malicious payloads onto infected systems.
- WannaSmile ransomware
- zCrypt variant discovered on November 17, 2017, one day after the discovery of TYRANT.
- WannaSpam ransomwaretrojan
- WannaSpam is a type of ransomware known for encrypting files on the affected systems, demanding ransom payments for decryption keys.
- WannabeHappy ransomware
- WannabeHappy is a ransomware program that encrypts files on the infected system and demands a cryptocurrency ransom for decryption keys.
- Want Money ransomware
- Want Money is a ransomware malware that encrypts files on infected systems and demands a ransom payment for decryption.
- WarHawk rat
- WarHawk is a remote access trojan often associated with cyber-espionage campaigns targeting governmental and defense entities in Western…
- Warezov wormbotnet
- Also known as Opnis, Stration. Warezov, also known as Opnis or Stration, is a worm primarily spreading through email.
- WarmCookie backdoorscreen-capturetrojan
- Also known as Badspace, Carrotstick, QUICKBIND. WarmCookie is backdoor that is capable of executing commands reading/writing files and capturing screenshots.
- Warp Stealer credential-stealer
- According to Seqrite, this is a fork of Stealerium that has high overlap with its originating codebase.
- Warzone ratkeyloggercredential-stealer
- Warzone is a remote access trojan (RAT) that has been active since 2018, often used to steal credentials and monitor keystrokes.
- WarzoneRAT ratcredential-stealer
- Also known as Warzone, Ave Maria, AVE_MARIA. WarzoneRAT is a malware-as-a-service remote access tool (RAT) written in C++ that has been publicly available for purchase since at least…
- WasabiSeed backdoor
- WasabiSeed is a backdoor malware associated with cyber-espionage campaigns.
- WastedLoader loader
- This malware looks similar to WastedLocker, but the ransomware component is missing.
- WastedLocker ransomware
- WastedLocker is a ransomware family attributed to Indrik Spider that has been used since at least May 2020.
- WatchBog wormcryptominer
- According to Intezer, this is a spreader module used by WatchBog.
- WatchCat ddostrojan
- WatchCat is a Linux-based malware primarily targeting IoT devices.
- WaterMiner cryptominer
- WaterMiner is a malware family known for illicit cryptocurrency mining activities.
- WaterSpout ratspyware
- WaterSpout is a sophisticated remote access trojan (RAT) often used in cyber-espionage campaigns targeting government and defense sectors.
- Waterbear loaderbackdoor
- Also known as DbgPrint, EYEWELL. Waterbear is modular malware attributed to BlackTech that has been used primarily for lateral movement, decrypting, and triggering…