Malware Families page 54 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Wave Stealer credential-stealer
Wave Stealer is an infostealer offered as Malware-as-a-Service by a French-speaking actor called "Wave".
WavyExfiller
WavyExfiller is a malware used to exfiltrate sensitive information from compromised systems.
Wcry Ransomware ransomwareworm
It’s directed to English speaking users, therefore is able to infect worldwide.
WeChat Ransom ransomwarecredential-stealer
Also known as UNNAMED1989. Over 100,000 thousand computers in China have been infected in just a few days with poorly-written ransomware that encrypts local files…
WeControl trojan
WeControl is a piece of malware identified as a Trojan, commonly used to gain unauthorized access to targeted systems.
WeSteal trojancredential-stealer
WeSteal is a piece of malware designed primarily to steal cryptocurrency from compromised systems.
WebC2-AdSpace botnetbackdoor
WebC2-AdSpace is a malware family known for using web-based command and control mechanisms.
WebC2-Ausov ratwebshell
WebC2-Ausov is a Remote Access Trojan (RAT) designed to establish command and control over infected systems, often used in targeted…
WebC2-Bolid rat
WebC2-Bolid is a Remote Access Trojan (RAT) used primarily against government and energy sectors in Eastern Europe, leveraging web-based…
WebC2-Cson webshellrat
WebC2-Cson is a web-based malware family used to establish Command and Control (C2) communication channels.
WebC2-DIV ratwebshell
WebC2-DIV is a remote access tool used to establish command and control channels for unauthorized access and persistence in target systems.
WebC2-GreenCat webshellbackdoor
WebC2-GreenCat is a malware variant known for utilizing web-based backdoors to enable remote command and control operations.
WebC2-Head webshell
WebC2-Head is a web-based command and control (C2) malware that allows attackers to execute commands and manage compromised systems via a…
WebC2-Kt3 webshell
WebC2-Kt3 is a sophisticated webshell used for persistent access to compromised networks.
WebC2-Qbp webshellrat
WebC2-Qbp is a malware family known to operate as a remote access tool and web shell, often used for command and control operations.
WebC2-Rave rat
WebC2-Rave is a form of remote access trojan (RAT) that facilitates unauthorized control over infected systems.
WebC2-Table webshellbackdoor
WebC2-Table is a web-based backdoor that facilitates remote access to compromised systems.
WebC2-UGX rat
WebC2-UGX is a remote access tool used for establishing command and control communications over the web.
WebC2-Yahoo webshell
WebC2-Yahoo is a piece of malware primarily used to set up command and control (C2) infrastructure through web-based methods.
WebMonitor RAT rat
Also known as RevCode. On its website, Webmonitor RAT is described as 'a very powerful, user-friendly, easy-to-setup and state-of-the-art monitoring tool.
WebbyTea downloader
WebbyTea is an HTTP(S) downloader that uses AES for C&C trafic encryption.
WellMail backdoorspyware
WellMail is a lightweight malware written in Golang used by APT29, similar in design and structure to WellMess.
WellMess backdoorrattrojan
WellMess is lightweight malware family with variants written in .NET and Golang that has been in use since at least 2018 by APT29.
Wesker ransomware
Wesker is a type of ransomware known for encrypting files and demanding a ransom for decryption.
Wevtutil
Wevtutil is a Windows command-line utility that enables administrators to retrieve information about event logs and publishers.
WhatAFuck ransomware
WhatAFuck is a ransomware strain designed to encrypt files and demand ransom payments for decryption.
WhiskerSpy spyware
WhiskerSpy is a cyber-espionage malware family primarily targeting entities in Hong Kong and China.
WhisperGate wiperransomware
Also known as PAYWIPE. WhisperGate is a multi-stage wiper designed to look like ransomware that has been used against multiple government, non-profit, and…
WhiteBird backdoor
According to Dr.Web, WhiteBird is a backdoor written in C++ and designed to operate in both 32-bit and 64-bit Microsoft Windows operating…
WhiteBlackCrypt ransomwaretrojan
Also known as WARYLOOK. WhiteBlackCrypt, also known as WARYLOOK, is a ransomware family that targets financial services and public sector entities, encrypting…
WhiteRabbit ransomware
WhiteRabbit is a ransomware variant known for targeting the financial and hospitality sectors.
WhiteRose ransomware
A new ransomware has been discovered by MalwareHunterTeam that is based off of the InfiniteTear ransomware family, of which BlackRuby and…
WhiteShadow spywareloader
WhiteShadow is a type of malware known for its capabilities as both spyware and a loader, which enables it to deploy additional malicious…
WhiteSnake Stealer credential-stealerkeyloggerspyware
WhiteSnake Stealer, discovered in February 2022, is a sophisticated .NET data-stealing malware that targets browsers, applications, and…
WhoLocker ransomware
WhoLocker is a form of ransomware that encrypts the victim's files and demands a ransom for decryption.
WhyCry ransomware
WhyCry is a type of ransomware that encrypts victims' files and demands a ransom for decryption.
WiRAT rat
WiRAT is a remote access tool designed to steal information and execute arbitrary commands on target systems.
Wiarp backdoortrojan
Wiarp is a trojan used by Elderwood to open a backdoor on compromised hosts.
WickedLocker HT Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
WikiLoader loader
Also known as WailingCrab. WikiLoader, also known as WailingCrab, is a malware loader known for its ability to execute follow-on payloads.
WildFire ransomware
WildFire is a ransomware family that encrypts files on infected systems and demands a ransom for decryption.
WildFire Locker ransomware
Also known as Hades Locker. Ransomware Zyklon variant
Win32.HsIdir rat
Win32.HsIdir is an advanced remote administrator tool systems was done by the original author HS32-Idir, it is the development of the…
WinDealer spywaretrojan
WinDealer is an information stealer malware used by the threat actor LuoYu.
WinInetLoader loaderdropper
Also known as LIDSHOT. WinInetLoader, also known as LIDSHOT, is a malware loader primarily used in cyber espionage campaigns.
WinMM backdoor
WinMM is a full-featured, simple backdoor used by Naikon.
WinPot trojan
Also known as ATMPot. WinPot is created to make ATMs by a popular ATM vendor to automatically dispense all cash from their most valuable cassettes.
WinRarer Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
WinScreeny backdoor
Backdoor used in the EvilPlayout campaign against Iran's State Broadcaster.
WinUpdatesDisabler ransomware
WinUpdatesDisabler is ransomware that targets Windows systems by disabling updates and encrypting user data.
WinWord64 ransomware
WinWord64 is a type of ransomware known for encrypting files on infected systems and demanding ransom payments in cryptocurrency for file…
WindTail spyware
WindTail is a macOS surveillance implant used by Windshift.
Windows Credential Editor credential-stealer
Also known as WCE. Windows Credential Editor is a password dumping tool.
Windows Remote Desktop
Windows Remote Desktop is the remote access software built into the Windows operating system.
Windows10 ransomware
Windows10 is a ransomware variant that encrypts files on infected systems, demanding payment for decryption keys.
Windows_Security Ransonware ransomwaretrojan
Also known as WS Go Ransonware, Trojan.Encoder.6491. This is most likely to affect English speaking users, since the note is written in English.
Winexe
Winexe is a lightweight, open source tool similar to PsExec designed to allow system administrators to execute commands on remote servers.
Wingbird backdoor
Wingbird is a backdoor that appears to be a version of commercial software FinFisher.
WininiCrypt ransomware
WininiCrypt is a type of ransomware designed to encrypt files on infected systems and demand a ransom for their decryption.
Winnix Cryptor Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Winnti (ELF) backdoor
Winnti (ELF) is a sophisticated malware family used by advanced threat actors for cyber espionage.
Winnti (OS X) backdoor
Winnti (OS X) is a variant of the Winnti malware family, primarily known for targeting government and technology sectors in multiple…
Winnti (Windows) backdoorrat
Also known as BleDoor, JUMPALL, Pasteboy. Winnti is a well-known malware family used by a Chinese state-sponsored threat group.
Winnti for Linux trojanbackdoor
Winnti for Linux is a trojan, seen since at least 2015, designed specifically for targeting Linux systems.
Winnti for Windows rat
Winnti for Windows is a modular remote access Trojan (RAT) that has been used likely by multiple groups to carry out intrusions in various…
WinorDLL64 downloaderbackdoor
According to ESET Research, this is a payload downloaded by win.wslink.
Winos rat
Winos is a Remote Access Trojan (RAT) characterized by its ability to execute arbitrary commands on compromised systems.
Winsecure ransomware
Winsecure is a ransomware family that encrypts files on compromised systems, demanding a cryptocurrency payment for decryption.
Winsloader loader
Winsloader is a malware loader used to deploy additional malicious payloads on targeted systems.
Wiper wiper
Wiper is a family of destructive malware used in March 2013 during breaches of South Korean banks and media companies.
WireLurker trojan
WireLurker is a family of macOS malware that targets iOS devices connected over USB.
WireLurker (OS X) trojan
WireLurker is a malware family targeting OS X and iOS devices, primarily distributed through trojanized applications from third-party app…
WireLurker (iOS) trojan
The iOS malware that is installed over USB by osx.wirelurker
WireX ddos
WireX is a botnet malware that primarily affects Android devices.
Wirenet (ELF) credential-stealerkeylogger
Wirenet (ELF) is a malware designed to target Linux systems, primarily focusing on stealing credentials.
Wirenet (OS X) keyloggercredential-stealer
Wirenet is a piece of malware targeting Linux and OS X systems.
WmRAT ratscreen-capture
According to Proofpoint, WmRAT is a remote access trojan (RAT) written in C++ that uses sockets for communications and has standard RAT…
WndTest
No description available.
WolfRAT rat
WolfRAT is malware based on a leaked version of Dendroid that has primarily targeted Thai users.
WolfsBane rat
WolfsBane is a remote access trojan designed for cyber espionage activities, primarily targeting government and technology sectors in the…
Wonknu rat
Wonknu is a sophisticated Remote Access Trojan (RAT) primarily targeting government and technology sectors.
WoodRat ransomwarerat
WoodRat is a malware that combines the functionalities of a ransomware and a remote access trojan (RAT), used by attackers to encrypt the…
Woody RAT rat
Woody RAT is a remote access trojan (RAT) that has been used since at least August 2021 against Russian organizations.
Woolger keyloggercredential-stealer
Also known as WoolenLogger. Woolger, also known as WoolenLogger, is a malware family primarily aimed at stealing credentials through keylogging techniques.
WorldWind credential-stealerkeyloggertrojan
WorldWind is an information-stealer malware designed to exfiltrate sensitive data such as credentials from targeted systems.
WormLocker ransomwareworm
Also known as WormLckr. WormLocker is a self-propagating ransomware that encrypts files on infected systems and demands a ransom for decryption.
WpBruteBot botnetcredential-stealer
WpBruteBot is a botnet malware that targets WordPress sites using brute-force attacks to compromise login credentials.
Wroba trojan
According to Avira, this is a banking trojan targeting Japan.
Wslink loaderbackdoor
Also known as FinickyFrogfish. Wslink, also known as FinickyFrogfish, is a sophisticated loader and backdoor malware used by advanced persistent threat actors.
WyrmSpy spywarerat
Also known as AndroidControl. WyrmSpy, also known as AndroidControl, is a sophisticated Android spyware that is used primarily for cyber-espionage.
WyvernLocker ransomware
WyvernLocker is a ransomware that encrypts files on infected systems and demands a ransom for decryption.
X Locker 5.0 ransomware
X Locker 5.0 is a ransomware variant that encrypts files on the victim's system and demands a ransom for decryption.
X-Agent (Android) spywaretrojan
Also known as Popr-d30. X-Agent (Android), also known as Popr-d30, is an Android malware variant used by threat actors for espionage purposes.
X-Agent (OS X) ratspywarebackdoor
X-Agent (OS X) is part of a malware suite used by APT28, also known as Fancy Bear.
X-Agent (iOS) ratspyware
X-Agent (iOS) is a remote access tool primarily used for cyber espionage activities.
X-Agent for Android spywarerat
X-Agent for Android is Android malware that was placed in a repackaged version of a Ukrainian artillery targeting application.
X-Files ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
X-Files Stealer credential-stealer
X-Files Stealer is a credential-stealing malware often used by cybercriminals to extract sensitive information from infected systems.
X-Tunnel (.NET) backdoorrat
This is a rewrite of win.xtunnel using the .NET framework that surfaced late 2017.
X-ZIGZAG rat
The author of X-ZIGZAG claims that it is a lightweight and stealthy Windows Remote Access Trojan (RAT) designed for educational purposes.