Malware Families page 55 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

X3M Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
XAgentOSX trojanrat
Also known as OSX.Sofacy. XAgentOSX is a trojan that has been used by APT28 on OS X and appears to be a port of their standard CHOPSTICK or XAgent trojan.
XBTL ratspyware
XBTL is a remote access trojan (RAT) primarily focusing on data exfiltration from compromised systems.
XBot POS credential-stealertrojan
XBot POS is a type of malware designed to target point-of-sale systems, primarily used to steal credit card information.
XCSSET backdoorransomwarespyware
Also known as OSX.DubRobber. XCSSET is a modular macOS malware family delivered through infected Xcode projects and executed when the project is compiled.
XCry ransomware
XCry is a ransomware family that encrypts files on infected devices and demands a ransom for decryption.
XCrypt Ransomware ransomware
Also known as XCrypt. It’s directed to English speaking users, therefore is able to infect worldwide.
XD ransomware
XD ransomware is a type of malware that encrypts files on the victim's system, demanding a ransom for their decryption.
XD Locker ransomware
XD Locker is a ransomware family known for encrypting files and demanding ransom from victims.
XDSpy downloadercredential-stealer
According to ESET Research, XDDown is a primary malware component and is strictly a downloader.
XData ransomware
Also known as AESNI. XData is a ransomware variant also known as AESNI.
XFSADM rat
XFSADM is a remote access tool (RAT) primarily used for espionage and data exfiltration.
XFSCashNCR trojan
XFSCashNCR is a financial trojan targeting banking services.
XLoader credential-stealerkeyloggerspyware
Also known as Formbook. XLoader is an infostealer malware in use since at least 2016.
XLoader for Android trojan
XLoader for Android is a malicious Android app first observed targeting Japan, Korea, China, Taiwan, and Hong Kong in 2018.
XLoader for iOS spywaretrojan
XLoader for iOS is a malicious iOS application that is capable of gathering system information.
XMRLocker ransomware
XMRLocker is a ransomware known for encrypting victim files and demanding payment, often in cryptocurrency, for decryption keys.
XOR DDoS ddosbotnet
Also known as XORDDOS. XOR DDoS is a Linux-based malware family known for launching DDoS attacks.
XORIndex Loader downloaderloader
XORIndex Loader is a XOR-encoded loader that collects host data, decodes follow-on scripts and acts as a downloader for the BeaverTail…
XP PrivEsc (CVE-2014-4076) exploit-kit
XP PrivEsc (CVE-2014-4076) is an exploit targeting a vulnerability in Windows XP that allows local privilege escalation.
XP10 ransomware
Also known as FakeChrome Ransomware. XP10, also known as FakeChrome Ransomware, encrypts files on infected systems, demanding a ransom for decryption keys.
XPCTRA rat
Also known as Expectra. XPCTRA, also known as Expectra, is a Remote Access Trojan (RAT) that incorporates code from the Quasar RAT.
XRTN ransomware
XRTN is a ransomware belonging to the VaultCrypt family.
XRat ransomware
XRat is a ransomware malware that encrypts files on the affected system.
XRed backdoorwormkeylogger
According to eSentire, XRed, also known as Synaptics worm, is a backdoor that has been circulating since at least 2019.
XSLCmd rat
XSLCmd is a remote access Trojan (RAT) used primarily for espionage and data exfiltration.
XServer ratcredential-stealerloader
Also known as Filesnfer. XServer, also known as Filesnfer, is a remote access trojan (RAT) that enables attackers to gain unauthorized access to affected systems.
XTPLocker 5.0 Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
XTinyLoader loaderdownloader
Simple Loader used to download and install stealers, clippers and other malwares.
XTunnel trojan
Also known as Trojan.Shunnael, X-Tunnel, XAPS. XTunnel a VPN-like network proxy tool that can relay traffic between a C2 server and a victim.
XWorm ransomwarerat
Malware with wide range of capabilities ranging from RAT to ransomware.
XYZWare Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Xanity rat
Xanity is a remote access trojan (RAT) known for allowing attackers to remotely control infected systems.
Xanthe cryptominer
Xanthe malware is known for targeting Docker instances to deploy cryptocurrency miners.
Xaynnalc ransomware
Xaynnalc is a ransomware family known for encrypting files on compromised systems.
Xbash ransomwarecryptominerworm
Xbash is a malware family that has targeted Linux and Microsoft Windows servers.
Xbot credential-stealerransomware
Xbot is an Android malware family that was observed in 2016 primarily targeting Android users in Russia and Australia.
XcodeGhost trojan
XcodeGhost is iOS malware that infected at least 39 iOS apps in 2015 and potentially affected millions of users.
XehookStealer credential-stealerkeyloggertrojan
Xehook is a .NET-based malware targeting Windows systems.
XenArmor credential-stealer
Also known as XenArmor Suite. XenArmor is a suite of password recovery tools for various applications that have been observed to be abused in attacks alongside malware.
Xena rat
Xena RAT is a fully-functional, stable, state-of-the-art RAT, coded in a native language called Delphi, it has almost no dependencies.
XenoRAT ratkeylogger
XenoRAT is an open source remote access trojan written in C#.
Xenomorph rattrojancredential-stealer
Xenomorph is a Android Banking RAT developed by the Hadoken.Security actor.
Xenon Stealer credential-stealer
Xenon Stealer is a malware family primarily used for stealing credentials.
XeroWare ransomware
XeroWare is a ransomware family known for encrypting victims' files and demanding a ransom for the decryption key.
Xiangoop trojanransomware
Xiangoop is a sophisticated malware family that primarily targets financial institutions and governmental entities.
XiaoBa ransomware
XiaoBa is a type of ransomware known for encrypting files on the victim's system and demanding a ransom for decryption keys.
XiaoBa ransomware ransomware
XiaoBa ransomware is a family of malware that encrypts files on infected systems and demands a ransom for their decryption.
XiebroC2 ratbackdoor
XiebroC2 is a remote access trojan (RAT) primarily targeting government and technology sectors.
Xillen Stealer credential-stealer
Xillen Stealer is a credential-stealing malware used to extract sensitive information like passwords and login details from infected…
Xinglocker ransomware
Xinglocker is a ransomware variant that utilizes a customized version of Mountlocker's executable to encrypt victim systems and demand a…
Xinof keyloggertrojan
Xinof is a trojan and keylogger malware known for its ability to capture keystrokes and steal sensitive information from infected systems.
Xlockr ransomware
Xlockr is a ransomware family that encrypts files on an infected system, demanding a ransom payment for file decryption.
XmdXtazX ransomware
XmdXtazX is a type of ransomware designed to encrypt files on infected systems and demand payment for decryption.
Xncrypt ransomware
Xncrypt is a type of ransomware known for encrypting user files and demanding payment for decryption.
Xolzsec ransomware
ransomware written by self proclaimed script kiddies that should really be considered trollware
Xorist ransomware
Ransomware encrypted files will still have the original non-encrypted header of 0x33 bytes length
XoriumStealer credential-stealer
XoriumStealer is a credential-stealing malware family known for targeting financial services, technology, and government sectors.
Xpan ransomware
Xpan is a ransomware family that has been primarily observed targeting institutions in Brazil.
Xpert backdoorrat
Xpert is a sophisticated remote access tool noted for its use in cyber espionage campaigns.
XpertRAT rat
According to PCrisk, XpertRAT is a Remote Administration Trojan, a malicious program that allows cyber criminals to remotely access and…
Xploit exploit-kit
Xploit is a sophisticated exploit kit used in cyber espionage campaigns targeting technology and government sectors.
XploitSPY rattrojan
XploitSPY is an Android remote access trojan (RAT) designed to stealthily control infected devices.
Xsser ratspyware
Also known as mRAT. Xsser mRAT is a piece of malware that targets iOS devices that have software limitations removed.
Xtreme RAT ratkeyloggerscreen-capture
Also known as ExtRat. According to Trend MIcro, Extreme RAT (XTRAT, Xtreme Rat) is a Remote Access Trojan that can steal information.
XtremeRAT rattrojan
This malware has been used in targeted attacks as well as traditional cybercrime.
Xwo credential-stealer
In March 2019, AT&T Alien Labs identified a new malware family that is actively scanning for exposed web services and default passwords.
Xyligan trojan
Xyligan is a type of Trojan malware known for its extensive distribution across multiple platforms.
XyuEncrypt ransomware
XyuEncrypt is a ransomware that encrypts files on a victim's system, demanding a ransom for decryption.
YAHOYAH trojanbackdoor
Also known as KeyBoy. YAHOYAH is a Trojan used by Tropic Trooper as a second-stage backdoor.
YESROBOT rat
YESROBOT is a remote access trojan (RAT) used for cyber espionage activities.
YTStealer credential-stealer
According to Intezer, YTStealer is a malware whose objective is to steal YouTube authentication cookies.
YYTO Ransomware ransomware
uses the extension [email protected] and drops a ransom note named Readme.txt
YYYYBJQOQDU ransomware
YYYYBJQOQDU is a ransomware strain known for encrypting files and demanding a ransom for the decryption key.
YaRAT rat
According to PTSecurity, this RAT uses Yandex Disk as a C2.
Yakuza ransomware
Also known as Teslarvng Ransomware. Yakuza, also known as Teslarvng Ransomware, is a type of ransomware known for targeting various industries globally, encrypting files, and…
YamaBot botnet
Also known as Kaos. YamaBot is a botnet primarily targeting Japanese systems, associated with cybercrime activities.
Yanluowang ransomware
Also known as Dryxiphia. Yanluowang is a ransomware strain known for encrypting files and demanding cryptocurrency payment.
Yarraq ransomware
Yarraq is a ransomware that encrypts files by using asymmetric keys and adding '.yarraq' as extension to the end of filenames.
Yashma ransomware
Cisco Talos has identified a new, previously unknown threat actor of Vietnamese origin conducting a ransomware operation that began at…
Yasso webshell
According to Palo Alto Networks, Yasso is an open source multi-platform intranet-assisted penetration toolset that brings together a…
Yatron ransomware
Yatron is a type of ransomware that encrypts files on targeted systems and demands a ransom for decryption.
YellYouth rat
YellYouth is a Remote Access Trojan primarily used in cyber espionage operations.
Yellow Cockatoo RAT rat
Also known as Polazer. Yellow Cockatoo RAT, also known as Polazer, is a remote access Trojan used primarily for cyber espionage.
YiBackdoor backdoor
YiBackdoor is a backdoor malware family known for providing remote access to compromised systems.
YiSpecter spywaretrojan
YiSpecter is a family of iOS and Android malware, first detected in November 2014, targeting users in mainland China and Taiwan.
Yoddos ddos
Yoddos is a malware primarily used for conducting Distributed Denial of Service (DDoS) attacks.
Yogynicof ransomware
Yogynicof is a ransomware variant known for encrypting files and demanding a ransom for decryption.
Yokai backdoorrat
Yokai is known as a remote access trojan (RAT) that provides threat actors the capability to remotely control infected systems.
YoreKey ratspyware
YoreKey is a remote access trojan (RAT) known for being used in cyber espionage campaigns.
Yort trojan
The Yort malware is a trojan primarily involved in targeting financial services and government sectors.
Yoshikada ransomware
Yoshikada is a ransomware family that encrypts files on infected systems, demanding a ransom for decryption keys.
You Have Been Hacked!!! ransomwarecredential-stealer
You Have Been Hacked!!! is a ransomware variant that attempts to steal passwords from infected systems.
YouAreFucked Ransomware ransomware
Also known as FortuneCrypt. This is most likely to affect English speaking users, since the note is written in English.
YoungLotus backdoordownloader
Also known as DarkShare. Simple malware with proxy/RDP and download capabilities.
YourCyanide ransomware
Also known as GonnaCope, Kekpop, Kekware. According to Trend Micro, this is a ransomware written as a Windows commandline script, with obfuscation applied.
YourRansom Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Yunsip credential-stealertrojan
W32/Yunsip!tr.pws is classified as a password stealing trojan.
Z3 ransomware
Z3 is a ransomware strain that encrypts victims' files and demands a ransom payment for decryption.
ZHtrap botnetcryptominer
ZHtrap is a botnet malware known for its cryptomining capabilities and exploitation of IoT devices.