Malware Families page 53 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

VersaMem webshell
VersaMem is a web shell designed for deployment to Versa Director servers following exploitation.
Vetta Loader loaderdownloader
Also known as BrokerLoader, EMPTYSPACE. Vetta Loader is a persistent Loader spreading with infected USB drives.
VevoLocker ransomware
VevoLocker is a ransomware known for encrypting users' files and demanding a ransom for their release.
Vflooder worm
Vflooder floods VirusTotal by infinitely submitting a copy of itself.
Vfokx trojan
Vfokx is a Trojan malware with limited detailed information available.
ViACrypt ransomware
ViACrypt is a type of ransomware that encrypts files on infected systems, demanding cryptocurrency payments in exchange for decryption keys.
Viagra ransomware
Viagra is a ransomware strain known for encrypting files on victim machines and demanding a ransom payment for file decryption.
ViceLeaker spyware
Also known as Triout. ViceLeaker is a spyware framework, capable of extensive surveillance and data exfiltration operations, primarily targeting devices…
Vicesociety ransomware
Vice Society is a ransomware group known for targeting sectors such as education and healthcare, often deploying double-extortion tactics…
VictoryGate cryptominerbotnet
VictoryGate was the name of a cryptomining botnet, which was disrupted by ESET researchers in April 2020.
Vidar credential-stealerspyware
Vidar is a forked malware based on Arkei.
VideoBelle ransomware
ransomware
Vigram downloader
Also known as WizardUpdate. Vigram, also known as WizardUpdate, is a malware family primarily targeting macOS systems.
ViiperWare ransomware
ViiperWare is a ransomware strain that encrypts files on the infected system and demands a ransom for decryption.
VileRAT rat
VileRAT is a sophisticated Remote Access Trojan primarily targeting financial institutions.
Vilsa Stealer credential-stealerspyware
Vilsa Stealer is a credential-stealing malware that targets sensitive information from compromised systems.
VindowsLocker Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Viper RAT rat
Viper RAT is a sophisticated remote access trojan primarily targeting Android devices.
ViperRAT spywarerat
ViperRAT is sophisticated surveillanceware that has been in operation since at least 2015 and was used to target the Israeli Defense Force.
ViperSoftX cryptominertrojan
ViperSoftX is a cryptojacking and data-stealing malware primarily used to deploy cryptocurrency miners.
Virlock ransomwarevirusworm
Also known as NSMF. Virlock is a polymorphic ransomware known for its self-replication capabilities.
Viro ransomware
Viro is a ransomware that encrypts files on infected systems, demanding a ransom payment for decryption.
ViroBotnet ransomwarebotnet
ViroBotnet is a type of ransomware that also operates as a botnet.
Virus RAT rat
Virus RAT is a remote access tool that facilitates unauthorized access and control of infected systems.
Virus-Encoder ransomware
Also known as CrySiS. Virus-Encoder, also known as CrySiS, is a family of ransomware targeting various industries globally by encrypting files and demanding…
Virut botnetvirus
Virut is a polmorphic malware known for its ability to infect executable files and spread through removable drives and network shares.
VisionCrypt ransomware
VisionCrypt is a ransomware that encrypts files on infected systems and demands a ransom for decryption.
Vizom trojancredential-stealer
Vizom is a malware family primarily targeting financial institutions in Brazil.
Vjw0rm ratworm
VJW0rm (aka Vengeance Justice Worm) is a publicly available, modular JavaScript RAT.
Vobfus wormdownloader
Also known as Beebone. Malware of this family searches for computers on a network and creates copies of itself in folders with open access.
Vohuk ransomware
Vohuk is a ransomware family that encrypts files on target systems, demanding a ransom for decryption.
Void ransomware
Also known as VoidCrypt. Void, also known as VoidCrypt, is a ransomware family known for encrypting files and demanding a ransom in cryptocurrency.
VoidCrypt ransomware
VoidCrypt is a ransomware that encrypts files on a victim's system, demanding a ransom for decryption.
VoidLink rootkitcredential-stealertrojan
VoidLink is a cloud-native Linux malware family designed as a modular post-exploitation framework for modern cloud and containerized…
VoidRAT rat
VoidRAT is a sophisticated remote access trojan used primarily for cyber espionage.
Voidoor backdoor
Voidoor is an advanced malware designed to provide unauthorized access to infected systems.
Voldemort backdoorrat
Voldemort is a backdoor discovered by Proofpoint in August 2024.
Volgmer backdoortrojan
Also known as FALLCHILL, Manuscrypt. Volgmer is a backdoor Trojan designed to provide covert access to a compromised system.
VorteX rattrojan
VorteX is a sophisticated Remote Access Trojan (RAT) used for stealing sensitive information from targeted systems.
Vortex Ransomware ransomware
Also known as Ŧl๏tєгค гคภร๏๓ฬคгє. This is most likely to affect English speaking users, since the note is written in English.
Vovalex ransomware
Vovalex is a type of ransomware that encrypts files on victims' systems and demands a ransom payment for decryption keys.
Vreikstadi trojan
Vreikstadi is a trojan malware family with limited publicly available information.
Vsop ransomware
Vsop, also known as Onix/Onyx, is a ransomware family targeting financial services and other sectors in multiple countries.
Vulston ransomware
Vulston is a ransomware family known for encrypting files and demanding ransom payments.
Vultur trojanscreen-capturecredential-stealer
Also known as Vulture. Vultur is an Android banking trojan that primarily targets financial services.
Vulturi credential-stealerspyware
Vulturi is an information-stealing malware designed to exfiltrate sensitive data, particularly credentials, from infected systems.
Vurten ransomware
Vurten is a ransomware family that targets various industries, notably financial services and technology.
VxLock Ransomware ransomware
Developed in Visual Studios in 2010. Original name is VxCrypt. This ransomware encrypts your files, including photos, music, MS office…
Vyveva RAT rat
Vyveva is a remote access trojan that uses the Tor library for communication with C&C.
W4SP Stealer credential-stealertrojan
A basic info stealer w/ some capability to inject code into legit applications.
WARPWIRE credential-stealer
WARPWIRE is a Javascript credential stealer that targets plaintext passwords and usernames for exfiltration that was used during Cutting…
WAVESHAPER backdoor
According to Mandiant, WAVESHAPER is a backdoor written in C++ and packed by an unknown packer that targets macOS.
WEBC2 backdoor
WEBC2 is a family of backdoor malware used by APT1 as early as July 2006.
WEEVILPROXY credential-stealerspywaretrojan
Also known as JSCEAL. WEEVILPROXY is a sophisticated and featureful stealer which has a payload primarily written in NodeJS.
WHIRLPOOL ransomware
WHIRLPOOL is a ransomware family primarily targeting financial services and government sectors.
WINDSHIELD backdoor
WINDSHIELD is a signature backdoor attributed to the APT32 group, known for targeting Southeast Asian countries, impacting sectors such as…
WINELOADER loader
WINELOADER is a malware loader used to deliver various types of malicious payloads.
WINERACK backdoor
WINERACK is a backdoor used by APT37, known for targeting the government and technology sectors, primarily in South Korea.
WIREFIRE webshelltrojan
Also known as GIFTEDVISITOR. WIREFIRE is a web shell written in Python that exists as trojanized logic to the visits.py component of Ivanti Connect Secure VPN…
WMI Ghost backdoorrat
Also known as Syndicasec, Wimmie. WMI Ghost, also known as Syndicasec or Wimmie, is a stealthy remote access tool (RAT) that leverages Windows Management Instrumentation…
WMImplant rat
WMImplant is a remote access tool (RAT) primarily associated with cyber espionage activities targeting government and defense sectors.
WORMHOLE backdoorworm
WORMHOLE is a TCP tunneler that is dynamically configurable from a C&C server and can communicate with an additional remote machine…
WRECKSTEEL credential-stealerscreen-capture
According to CERT-UA, this is a stealer targeting a range of file extensions and creating screenshots of the compromised machine to be…
WSCSPL backdoorrat
WSCSPL is a remote access tool (RAT) used for cyber espionage activities.
WSO webshell
Also known as Webshell by Orb. WSO, also known as Webshell by Orb, is a web-based shell used by attackers to gain and maintain access to compromised servers.
WTDI ransomware
WTDI is a ransomware family known for encrypting files on infected systems and demanding ransom payments, predominantly targeting critical…
Wadhrama ransomware
Wadhrama is a ransomware family that encrypts victims' files and demands a ransom payment in cryptocurrency.
Waffle ransomware
Waffle is a ransomware strain known for encrypting victim's files and demanding a ransom payment for decryption.
Wainscot
No description available.
Waiting ransomware
The 'Waiting' ransomware encrypts files on infected systems and demands a ransom for decryption.
Waldo ransomware
Waldo is a ransomware variant known for encrypting files and demanding a ransom for their decryption.
WalkLoader loaderdropper
WalkLoader is a malware loader that facilitates the delivery of various malicious payloads.
WallyShack backdoorransomware
WallyShack is a sophisticated malware family primarily used for cyber espionage and ransomware attacks targeting technology…
Wanna Decryptor Portuguese ransomwareworm
Wanna Decryptor Portuguese, also known as WannaCry, is a ransomware and worm variant that encrypts files and demands ransom.
WannaCash ransomware
WannaCash is a ransomware malware primarily targeting financial services and retail sectors.
WannaCry ransomwareworm
Also known as WanaCry, WanaCrypt, WanaCrypt0r. WannaCry is ransomware that was first seen in a global attack during May 2017, which affected more than 150 countries.
WannaDie ransomwareworm
WannaDie is a type of ransomware similar to WannaCry, encrypting files on the infected devices and demanding ransom payments from victims…
WannaHusky ransomware
According to Mars, WannaHusky is a Nim-compiled ransomware malware sample, created for demonstration purposes and provided as part of the…
WannaMine cryptominer
WannaMine is a cryptocurrency mining malware that spreads laterally through infected networks using exploits and credential-stealing…
WannaPeace ransomware
WannaPeace is a ransomware family that primarily encrypts user files and demands a ransom payment in cryptocurrency for the decryption key.
WannaRen ransomware
WannaRen is ransomware that encrypts files on infected systems, demanding a ransom for decryption.
WannaRen Downloader downloader
WannaRen Downloader is a type of malware that facilitates the downloading of other malicious payloads onto infected systems.
WannaSmile ransomware
zCrypt variant discovered on November 17, 2017, one day after the discovery of TYRANT.
WannaSpam ransomwaretrojan
WannaSpam is a type of ransomware known for encrypting files on the affected systems, demanding ransom payments for decryption keys.
WannabeHappy ransomware
WannabeHappy is a ransomware program that encrypts files on the infected system and demands a cryptocurrency ransom for decryption keys.
Want Money ransomware
Want Money is a ransomware malware that encrypts files on infected systems and demands a ransom payment for decryption.
WarHawk rat
WarHawk is a remote access trojan often associated with cyber-espionage campaigns targeting governmental and defense entities in Western…
Warezov wormbotnet
Also known as Opnis, Stration. Warezov, also known as Opnis or Stration, is a worm primarily spreading through email.
WarmCookie backdoorscreen-capturetrojan
Also known as Badspace, Carrotstick, QUICKBIND. WarmCookie is backdoor that is capable of executing commands reading/writing files and capturing screenshots.
Warp Stealer credential-stealer
According to Seqrite, this is a fork of Stealerium that has high overlap with its originating codebase.
Warzone ratkeyloggercredential-stealer
Warzone is a remote access trojan (RAT) that has been active since 2018, often used to steal credentials and monitor keystrokes.
WarzoneRAT ratcredential-stealer
Also known as Warzone, Ave Maria, AVE_MARIA. WarzoneRAT is a malware-as-a-service remote access tool (RAT) written in C++ that has been publicly available for purchase since at least…
WasabiSeed backdoor
WasabiSeed is a backdoor malware associated with cyber-espionage campaigns.
WastedLoader loader
This malware looks similar to WastedLocker, but the ransomware component is missing.
WastedLocker ransomware
WastedLocker is a ransomware family attributed to Indrik Spider that has been used since at least May 2020.
WatchBog wormcryptominer
According to Intezer, this is a spreader module used by WatchBog.
WatchCat ddostrojan
WatchCat is a Linux-based malware primarily targeting IoT devices.
WaterMiner cryptominer
WaterMiner is a malware family known for illicit cryptocurrency mining activities.
WaterSpout ratspyware
WaterSpout is a sophisticated remote access trojan (RAT) often used in cyber-espionage campaigns targeting government and defense sectors.
Waterbear loaderbackdoor
Also known as DbgPrint, EYEWELL. Waterbear is modular malware attributed to BlackTech that has been used primarily for lateral movement, decrypting, and triggering…