Malware Families page 54 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Wave Stealer credential-stealer
- Wave Stealer is an infostealer offered as Malware-as-a-Service by a French-speaking actor called "Wave".
- WavyExfiller
- WavyExfiller is a malware used to exfiltrate sensitive information from compromised systems.
- Wcry Ransomware ransomwareworm
- It’s directed to English speaking users, therefore is able to infect worldwide.
- WeChat Ransom ransomwarecredential-stealer
- Also known as UNNAMED1989. Over 100,000 thousand computers in China have been infected in just a few days with poorly-written ransomware that encrypts local files…
- WeControl trojan
- WeControl is a piece of malware identified as a Trojan, commonly used to gain unauthorized access to targeted systems.
- WeSteal trojancredential-stealer
- WeSteal is a piece of malware designed primarily to steal cryptocurrency from compromised systems.
- WebC2-AdSpace botnetbackdoor
- WebC2-AdSpace is a malware family known for using web-based command and control mechanisms.
- WebC2-Ausov ratwebshell
- WebC2-Ausov is a Remote Access Trojan (RAT) designed to establish command and control over infected systems, often used in targeted…
- WebC2-Bolid rat
- WebC2-Bolid is a Remote Access Trojan (RAT) used primarily against government and energy sectors in Eastern Europe, leveraging web-based…
- WebC2-Cson webshellrat
- WebC2-Cson is a web-based malware family used to establish Command and Control (C2) communication channels.
- WebC2-DIV ratwebshell
- WebC2-DIV is a remote access tool used to establish command and control channels for unauthorized access and persistence in target systems.
- WebC2-GreenCat webshellbackdoor
- WebC2-GreenCat is a malware variant known for utilizing web-based backdoors to enable remote command and control operations.
- WebC2-Head webshell
- WebC2-Head is a web-based command and control (C2) malware that allows attackers to execute commands and manage compromised systems via a…
- WebC2-Kt3 webshell
- WebC2-Kt3 is a sophisticated webshell used for persistent access to compromised networks.
- WebC2-Qbp webshellrat
- WebC2-Qbp is a malware family known to operate as a remote access tool and web shell, often used for command and control operations.
- WebC2-Rave rat
- WebC2-Rave is a form of remote access trojan (RAT) that facilitates unauthorized control over infected systems.
- WebC2-Table webshellbackdoor
- WebC2-Table is a web-based backdoor that facilitates remote access to compromised systems.
- WebC2-UGX rat
- WebC2-UGX is a remote access tool used for establishing command and control communications over the web.
- WebC2-Yahoo webshell
- WebC2-Yahoo is a piece of malware primarily used to set up command and control (C2) infrastructure through web-based methods.
- WebMonitor RAT rat
- Also known as RevCode. On its website, Webmonitor RAT is described as 'a very powerful, user-friendly, easy-to-setup and state-of-the-art monitoring tool.
- WebbyTea downloader
- WebbyTea is an HTTP(S) downloader that uses AES for C&C trafic encryption.
- WellMail backdoorspyware
- WellMail is a lightweight malware written in Golang used by APT29, similar in design and structure to WellMess.
- WellMess backdoorrattrojan
- WellMess is lightweight malware family with variants written in .NET and Golang that has been in use since at least 2018 by APT29.
- Wesker ransomware
- Wesker is a type of ransomware known for encrypting files and demanding a ransom for decryption.
- Wevtutil
- Wevtutil is a Windows command-line utility that enables administrators to retrieve information about event logs and publishers.
- WhatAFuck ransomware
- WhatAFuck is a ransomware strain designed to encrypt files and demand ransom payments for decryption.
- WhiskerSpy spyware
- WhiskerSpy is a cyber-espionage malware family primarily targeting entities in Hong Kong and China.
- WhisperGate wiperransomware
- Also known as PAYWIPE. WhisperGate is a multi-stage wiper designed to look like ransomware that has been used against multiple government, non-profit, and…
- WhiteBird backdoor
- According to Dr.Web, WhiteBird is a backdoor written in C++ and designed to operate in both 32-bit and 64-bit Microsoft Windows operating…
- WhiteBlackCrypt ransomwaretrojan
- Also known as WARYLOOK. WhiteBlackCrypt, also known as WARYLOOK, is a ransomware family that targets financial services and public sector entities, encrypting…
- WhiteRabbit ransomware
- WhiteRabbit is a ransomware variant known for targeting the financial and hospitality sectors.
- WhiteRose ransomware
- A new ransomware has been discovered by MalwareHunterTeam that is based off of the InfiniteTear ransomware family, of which BlackRuby and…
- WhiteShadow spywareloader
- WhiteShadow is a type of malware known for its capabilities as both spyware and a loader, which enables it to deploy additional malicious…
- WhiteSnake Stealer credential-stealerkeyloggerspyware
- WhiteSnake Stealer, discovered in February 2022, is a sophisticated .NET data-stealing malware that targets browsers, applications, and…
- WhoLocker ransomware
- WhoLocker is a form of ransomware that encrypts the victim's files and demands a ransom for decryption.
- WhyCry ransomware
- WhyCry is a type of ransomware that encrypts victims' files and demands a ransom for decryption.
- WiRAT rat
- WiRAT is a remote access tool designed to steal information and execute arbitrary commands on target systems.
- Wiarp backdoortrojan
- Wiarp is a trojan used by Elderwood to open a backdoor on compromised hosts.
- WickedLocker HT Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- WikiLoader loader
- Also known as WailingCrab. WikiLoader, also known as WailingCrab, is a malware loader known for its ability to execute follow-on payloads.
- WildFire ransomware
- WildFire is a ransomware family that encrypts files on infected systems and demands a ransom for decryption.
- WildFire Locker ransomware
- Also known as Hades Locker. Ransomware Zyklon variant
- Win32.HsIdir rat
- Win32.HsIdir is an advanced remote administrator tool systems was done by the original author HS32-Idir, it is the development of the…
- WinDealer spywaretrojan
- WinDealer is an information stealer malware used by the threat actor LuoYu.
- WinInetLoader loaderdropper
- Also known as LIDSHOT. WinInetLoader, also known as LIDSHOT, is a malware loader primarily used in cyber espionage campaigns.
- WinMM backdoor
- WinMM is a full-featured, simple backdoor used by Naikon.
- WinPot trojan
- Also known as ATMPot. WinPot is created to make ATMs by a popular ATM vendor to automatically dispense all cash from their most valuable cassettes.
- WinRarer Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- WinScreeny backdoor
- Backdoor used in the EvilPlayout campaign against Iran's State Broadcaster.
- WinUpdatesDisabler ransomware
- WinUpdatesDisabler is ransomware that targets Windows systems by disabling updates and encrypting user data.
- WinWord64 ransomware
- WinWord64 is a type of ransomware known for encrypting files on infected systems and demanding ransom payments in cryptocurrency for file…
- WindTail spyware
- WindTail is a macOS surveillance implant used by Windshift.
- Windows Credential Editor credential-stealer
- Also known as WCE. Windows Credential Editor is a password dumping tool.
- Windows Remote Desktop
- Windows Remote Desktop is the remote access software built into the Windows operating system.
- Windows10 ransomware
- Windows10 is a ransomware variant that encrypts files on infected systems, demanding payment for decryption keys.
- Windows_Security Ransonware ransomwaretrojan
- Also known as WS Go Ransonware, Trojan.Encoder.6491. This is most likely to affect English speaking users, since the note is written in English.
- Winexe
- Winexe is a lightweight, open source tool similar to PsExec designed to allow system administrators to execute commands on remote servers.
- Wingbird backdoor
- Wingbird is a backdoor that appears to be a version of commercial software FinFisher.
- WininiCrypt ransomware
- WininiCrypt is a type of ransomware designed to encrypt files on infected systems and demand a ransom for their decryption.
- Winnix Cryptor Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Winnti (ELF) backdoor
- Winnti (ELF) is a sophisticated malware family used by advanced threat actors for cyber espionage.
- Winnti (OS X) backdoor
- Winnti (OS X) is a variant of the Winnti malware family, primarily known for targeting government and technology sectors in multiple…
- Winnti (Windows) backdoorrat
- Also known as BleDoor, JUMPALL, Pasteboy. Winnti is a well-known malware family used by a Chinese state-sponsored threat group.
- Winnti for Linux trojanbackdoor
- Winnti for Linux is a trojan, seen since at least 2015, designed specifically for targeting Linux systems.
- Winnti for Windows rat
- Winnti for Windows is a modular remote access Trojan (RAT) that has been used likely by multiple groups to carry out intrusions in various…
- WinorDLL64 downloaderbackdoor
- According to ESET Research, this is a payload downloaded by win.wslink.
- Winos rat
- Winos is a Remote Access Trojan (RAT) characterized by its ability to execute arbitrary commands on compromised systems.
- Winsecure ransomware
- Winsecure is a ransomware family that encrypts files on compromised systems, demanding a cryptocurrency payment for decryption.
- Winsloader loader
- Winsloader is a malware loader used to deploy additional malicious payloads on targeted systems.
- Wiper wiper
- Wiper is a family of destructive malware used in March 2013 during breaches of South Korean banks and media companies.
- WireLurker trojan
- WireLurker is a family of macOS malware that targets iOS devices connected over USB.
- WireLurker (OS X) trojan
- WireLurker is a malware family targeting OS X and iOS devices, primarily distributed through trojanized applications from third-party app…
- WireLurker (iOS) trojan
- The iOS malware that is installed over USB by osx.wirelurker
- WireX ddos
- WireX is a botnet malware that primarily affects Android devices.
- Wirenet (ELF) credential-stealerkeylogger
- Wirenet (ELF) is a malware designed to target Linux systems, primarily focusing on stealing credentials.
- Wirenet (OS X) keyloggercredential-stealer
- Wirenet is a piece of malware targeting Linux and OS X systems.
- WmRAT ratscreen-capture
- According to Proofpoint, WmRAT is a remote access trojan (RAT) written in C++ that uses sockets for communications and has standard RAT…
- WndTest
- No description available.
- WolfRAT rat
- WolfRAT is malware based on a leaked version of Dendroid that has primarily targeted Thai users.
- WolfsBane rat
- WolfsBane is a remote access trojan designed for cyber espionage activities, primarily targeting government and technology sectors in the…
- Wonknu rat
- Wonknu is a sophisticated Remote Access Trojan (RAT) primarily targeting government and technology sectors.
- WoodRat ransomwarerat
- WoodRat is a malware that combines the functionalities of a ransomware and a remote access trojan (RAT), used by attackers to encrypt the…
- Woody RAT rat
- Woody RAT is a remote access trojan (RAT) that has been used since at least August 2021 against Russian organizations.
- Woolger keyloggercredential-stealer
- Also known as WoolenLogger. Woolger, also known as WoolenLogger, is a malware family primarily aimed at stealing credentials through keylogging techniques.
- WorldWind credential-stealerkeyloggertrojan
- WorldWind is an information-stealer malware designed to exfiltrate sensitive data such as credentials from targeted systems.
- WormLocker ransomwareworm
- Also known as WormLckr. WormLocker is a self-propagating ransomware that encrypts files on infected systems and demands a ransom for decryption.
- WpBruteBot botnetcredential-stealer
- WpBruteBot is a botnet malware that targets WordPress sites using brute-force attacks to compromise login credentials.
- Wroba trojan
- According to Avira, this is a banking trojan targeting Japan.
- Wslink loaderbackdoor
- Also known as FinickyFrogfish. Wslink, also known as FinickyFrogfish, is a sophisticated loader and backdoor malware used by advanced persistent threat actors.
- WyrmSpy spywarerat
- Also known as AndroidControl. WyrmSpy, also known as AndroidControl, is a sophisticated Android spyware that is used primarily for cyber-espionage.
- WyvernLocker ransomware
- WyvernLocker is a ransomware that encrypts files on infected systems and demands a ransom for decryption.
- X Locker 5.0 ransomware
- X Locker 5.0 is a ransomware variant that encrypts files on the victim's system and demands a ransom for decryption.
- X-Agent (Android) spywaretrojan
- Also known as Popr-d30. X-Agent (Android), also known as Popr-d30, is an Android malware variant used by threat actors for espionage purposes.
- X-Agent (OS X) ratspywarebackdoor
- X-Agent (OS X) is part of a malware suite used by APT28, also known as Fancy Bear.
- X-Agent (iOS) ratspyware
- X-Agent (iOS) is a remote access tool primarily used for cyber espionage activities.
- X-Agent for Android spywarerat
- X-Agent for Android is Android malware that was placed in a repackaged version of a Ukrainian artillery targeting application.
- X-Files ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- X-Files Stealer credential-stealer
- X-Files Stealer is a credential-stealing malware often used by cybercriminals to extract sensitive information from infected systems.
- X-Tunnel (.NET) backdoorrat
- This is a rewrite of win.xtunnel using the .NET framework that surfaced late 2017.
- X-ZIGZAG rat
- The author of X-ZIGZAG claims that it is a lightweight and stealthy Windows Remote Access Trojan (RAT) designed for educational purposes.