Malware Families page 55 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- X3M Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- XAgentOSX trojanrat
- Also known as OSX.Sofacy. XAgentOSX is a trojan that has been used by APT28 on OS X and appears to be a port of their standard CHOPSTICK or XAgent trojan.
- XBTL ratspyware
- XBTL is a remote access trojan (RAT) primarily focusing on data exfiltration from compromised systems.
- XBot POS credential-stealertrojan
- XBot POS is a type of malware designed to target point-of-sale systems, primarily used to steal credit card information.
- XCSSET backdoorransomwarespyware
- Also known as OSX.DubRobber. XCSSET is a modular macOS malware family delivered through infected Xcode projects and executed when the project is compiled.
- XCry ransomware
- XCry is a ransomware family that encrypts files on infected devices and demands a ransom for decryption.
- XCrypt Ransomware ransomware
- Also known as XCrypt. It’s directed to English speaking users, therefore is able to infect worldwide.
- XD ransomware
- XD ransomware is a type of malware that encrypts files on the victim's system, demanding a ransom for their decryption.
- XD Locker ransomware
- XD Locker is a ransomware family known for encrypting files and demanding ransom from victims.
- XDSpy downloadercredential-stealer
- According to ESET Research, XDDown is a primary malware component and is strictly a downloader.
- XData ransomware
- Also known as AESNI. XData is a ransomware variant also known as AESNI.
- XFSADM rat
- XFSADM is a remote access tool (RAT) primarily used for espionage and data exfiltration.
- XFSCashNCR trojan
- XFSCashNCR is a financial trojan targeting banking services.
- XLoader credential-stealerkeyloggerspyware
- Also known as Formbook. XLoader is an infostealer malware in use since at least 2016.
- XLoader for Android trojan
- XLoader for Android is a malicious Android app first observed targeting Japan, Korea, China, Taiwan, and Hong Kong in 2018.
- XLoader for iOS spywaretrojan
- XLoader for iOS is a malicious iOS application that is capable of gathering system information.
- XMRLocker ransomware
- XMRLocker is a ransomware known for encrypting victim files and demanding payment, often in cryptocurrency, for decryption keys.
- XOR DDoS ddosbotnet
- Also known as XORDDOS. XOR DDoS is a Linux-based malware family known for launching DDoS attacks.
- XORIndex Loader downloaderloader
- XORIndex Loader is a XOR-encoded loader that collects host data, decodes follow-on scripts and acts as a downloader for the BeaverTail…
- XP PrivEsc (CVE-2014-4076) exploit-kit
- XP PrivEsc (CVE-2014-4076) is an exploit targeting a vulnerability in Windows XP that allows local privilege escalation.
- XP10 ransomware
- Also known as FakeChrome Ransomware. XP10, also known as FakeChrome Ransomware, encrypts files on infected systems, demanding a ransom for decryption keys.
- XPCTRA rat
- Also known as Expectra. XPCTRA, also known as Expectra, is a Remote Access Trojan (RAT) that incorporates code from the Quasar RAT.
- XRTN ransomware
- XRTN is a ransomware belonging to the VaultCrypt family.
- XRat ransomware
- XRat is a ransomware malware that encrypts files on the affected system.
- XRed backdoorwormkeylogger
- According to eSentire, XRed, also known as Synaptics worm, is a backdoor that has been circulating since at least 2019.
- XSLCmd rat
- XSLCmd is a remote access Trojan (RAT) used primarily for espionage and data exfiltration.
- XServer ratcredential-stealerloader
- Also known as Filesnfer. XServer, also known as Filesnfer, is a remote access trojan (RAT) that enables attackers to gain unauthorized access to affected systems.
- XTPLocker 5.0 Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- XTinyLoader loaderdownloader
- Simple Loader used to download and install stealers, clippers and other malwares.
- XTunnel trojan
- Also known as Trojan.Shunnael, X-Tunnel, XAPS. XTunnel a VPN-like network proxy tool that can relay traffic between a C2 server and a victim.
- XWorm ransomwarerat
- Malware with wide range of capabilities ranging from RAT to ransomware.
- XYZWare Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Xanity rat
- Xanity is a remote access trojan (RAT) known for allowing attackers to remotely control infected systems.
- Xanthe cryptominer
- Xanthe malware is known for targeting Docker instances to deploy cryptocurrency miners.
- Xaynnalc ransomware
- Xaynnalc is a ransomware family known for encrypting files on compromised systems.
- Xbash ransomwarecryptominerworm
- Xbash is a malware family that has targeted Linux and Microsoft Windows servers.
- Xbot credential-stealerransomware
- Xbot is an Android malware family that was observed in 2016 primarily targeting Android users in Russia and Australia.
- XcodeGhost trojan
- XcodeGhost is iOS malware that infected at least 39 iOS apps in 2015 and potentially affected millions of users.
- XehookStealer credential-stealerkeyloggertrojan
- Xehook is a .NET-based malware targeting Windows systems.
- XenArmor credential-stealer
- Also known as XenArmor Suite. XenArmor is a suite of password recovery tools for various applications that have been observed to be abused in attacks alongside malware.
- Xena rat
- Xena RAT is a fully-functional, stable, state-of-the-art RAT, coded in a native language called Delphi, it has almost no dependencies.
- XenoRAT ratkeylogger
- XenoRAT is an open source remote access trojan written in C#.
- Xenomorph rattrojancredential-stealer
- Xenomorph is a Android Banking RAT developed by the Hadoken.Security actor.
- Xenon Stealer credential-stealer
- Xenon Stealer is a malware family primarily used for stealing credentials.
- XeroWare ransomware
- XeroWare is a ransomware family known for encrypting victims' files and demanding a ransom for the decryption key.
- Xiangoop trojanransomware
- Xiangoop is a sophisticated malware family that primarily targets financial institutions and governmental entities.
- XiaoBa ransomware
- XiaoBa is a type of ransomware known for encrypting files on the victim's system and demanding a ransom for decryption keys.
- XiaoBa ransomware ransomware
- XiaoBa ransomware is a family of malware that encrypts files on infected systems and demands a ransom for their decryption.
- XiebroC2 ratbackdoor
- XiebroC2 is a remote access trojan (RAT) primarily targeting government and technology sectors.
- Xillen Stealer credential-stealer
- Xillen Stealer is a credential-stealing malware used to extract sensitive information like passwords and login details from infected…
- Xinglocker ransomware
- Xinglocker is a ransomware variant that utilizes a customized version of Mountlocker's executable to encrypt victim systems and demand a…
- Xinof keyloggertrojan
- Xinof is a trojan and keylogger malware known for its ability to capture keystrokes and steal sensitive information from infected systems.
- Xlockr ransomware
- Xlockr is a ransomware family that encrypts files on an infected system, demanding a ransom payment for file decryption.
- XmdXtazX ransomware
- XmdXtazX is a type of ransomware designed to encrypt files on infected systems and demand payment for decryption.
- Xncrypt ransomware
- Xncrypt is a type of ransomware known for encrypting user files and demanding payment for decryption.
- Xolzsec ransomware
- ransomware written by self proclaimed script kiddies that should really be considered trollware
- Xorist ransomware
- Ransomware encrypted files will still have the original non-encrypted header of 0x33 bytes length
- XoriumStealer credential-stealer
- XoriumStealer is a credential-stealing malware family known for targeting financial services, technology, and government sectors.
- Xpan ransomware
- Xpan is a ransomware family that has been primarily observed targeting institutions in Brazil.
- Xpert backdoorrat
- Xpert is a sophisticated remote access tool noted for its use in cyber espionage campaigns.
- XpertRAT rat
- According to PCrisk, XpertRAT is a Remote Administration Trojan, a malicious program that allows cyber criminals to remotely access and…
- Xploit exploit-kit
- Xploit is a sophisticated exploit kit used in cyber espionage campaigns targeting technology and government sectors.
- XploitSPY rattrojan
- XploitSPY is an Android remote access trojan (RAT) designed to stealthily control infected devices.
- Xsser ratspyware
- Also known as mRAT. Xsser mRAT is a piece of malware that targets iOS devices that have software limitations removed.
- Xtreme RAT ratkeyloggerscreen-capture
- Also known as ExtRat. According to Trend MIcro, Extreme RAT (XTRAT, Xtreme Rat) is a Remote Access Trojan that can steal information.
- XtremeRAT rattrojan
- This malware has been used in targeted attacks as well as traditional cybercrime.
- Xwo credential-stealer
- In March 2019, AT&T Alien Labs identified a new malware family that is actively scanning for exposed web services and default passwords.
- Xyligan trojan
- Xyligan is a type of Trojan malware known for its extensive distribution across multiple platforms.
- XyuEncrypt ransomware
- XyuEncrypt is a ransomware that encrypts files on a victim's system, demanding a ransom for decryption.
- YAHOYAH trojanbackdoor
- Also known as KeyBoy. YAHOYAH is a Trojan used by Tropic Trooper as a second-stage backdoor.
- YESROBOT rat
- YESROBOT is a remote access trojan (RAT) used for cyber espionage activities.
- YTStealer credential-stealer
- According to Intezer, YTStealer is a malware whose objective is to steal YouTube authentication cookies.
- YYTO Ransomware ransomware
- uses the extension [email protected] and drops a ransom note named Readme.txt
- YYYYBJQOQDU ransomware
- YYYYBJQOQDU is a ransomware strain known for encrypting files and demanding a ransom for the decryption key.
- YaRAT rat
- According to PTSecurity, this RAT uses Yandex Disk as a C2.
- Yakuza ransomware
- Also known as Teslarvng Ransomware. Yakuza, also known as Teslarvng Ransomware, is a type of ransomware known for targeting various industries globally, encrypting files, and…
- YamaBot botnet
- Also known as Kaos. YamaBot is a botnet primarily targeting Japanese systems, associated with cybercrime activities.
- Yanluowang ransomware
- Also known as Dryxiphia. Yanluowang is a ransomware strain known for encrypting files and demanding cryptocurrency payment.
- Yarraq ransomware
- Yarraq is a ransomware that encrypts files by using asymmetric keys and adding '.yarraq' as extension to the end of filenames.
- Yashma ransomware
- Cisco Talos has identified a new, previously unknown threat actor of Vietnamese origin conducting a ransomware operation that began at…
- Yasso webshell
- According to Palo Alto Networks, Yasso is an open source multi-platform intranet-assisted penetration toolset that brings together a…
- Yatron ransomware
- Yatron is a type of ransomware that encrypts files on targeted systems and demands a ransom for decryption.
- YellYouth rat
- YellYouth is a Remote Access Trojan primarily used in cyber espionage operations.
- Yellow Cockatoo RAT rat
- Also known as Polazer. Yellow Cockatoo RAT, also known as Polazer, is a remote access Trojan used primarily for cyber espionage.
- YiBackdoor backdoor
- YiBackdoor is a backdoor malware family known for providing remote access to compromised systems.
- YiSpecter spywaretrojan
- YiSpecter is a family of iOS and Android malware, first detected in November 2014, targeting users in mainland China and Taiwan.
- Yoddos ddos
- Yoddos is a malware primarily used for conducting Distributed Denial of Service (DDoS) attacks.
- Yogynicof ransomware
- Yogynicof is a ransomware variant known for encrypting files and demanding a ransom for decryption.
- Yokai backdoorrat
- Yokai is known as a remote access trojan (RAT) that provides threat actors the capability to remotely control infected systems.
- YoreKey ratspyware
- YoreKey is a remote access trojan (RAT) known for being used in cyber espionage campaigns.
- Yort trojan
- The Yort malware is a trojan primarily involved in targeting financial services and government sectors.
- Yoshikada ransomware
- Yoshikada is a ransomware family that encrypts files on infected systems, demanding a ransom for decryption keys.
- You Have Been Hacked!!! ransomwarecredential-stealer
- You Have Been Hacked!!! is a ransomware variant that attempts to steal passwords from infected systems.
- YouAreFucked Ransomware ransomware
- Also known as FortuneCrypt. This is most likely to affect English speaking users, since the note is written in English.
- YoungLotus backdoordownloader
- Also known as DarkShare. Simple malware with proxy/RDP and download capabilities.
- YourCyanide ransomware
- Also known as GonnaCope, Kekpop, Kekware. According to Trend Micro, this is a ransomware written as a Windows commandline script, with obfuscation applied.
- YourRansom Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Yunsip credential-stealertrojan
- W32/Yunsip!tr.pws is classified as a password stealing trojan.
- Z3 ransomware
- Z3 is a ransomware strain that encrypts victims' files and demands a ransom payment for decryption.
- ZHtrap botnetcryptominer
- ZHtrap is a botnet malware known for its cryptomining capabilities and exploitation of IoT devices.