Malware Families page 56 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- ZIPLINE backdoor
- ZIPLINE is a passive backdoor that was used during Cutting Edge on compromised Secure Connect VPNs for reverse shell and proxy…
- ZLib backdoor
- ZLib is a full-featured backdoor that was used as a second-stage implant during Operation Dust Storm since at least 2014.
- ZOMBIE SLAYER ransomware
- Zombie Slayer is a ransomware known for encrypting critical files and demanding payment for their release.
- ZStealer credential-stealer
- Also known as Z*Stealer. ZStealer is an information stealer malware commonly used by the cybercrime group Void Balaur.
- ZUpdater downloadertrojan
- Also known as Zpevdo. ZUpdater, also known as Zpevdo, is a downloader trojan used to deploy additional payloads onto infected systems.
- ZXZ Ramsomware ransomware
- Originated in English, could affect users worldwide, however so far only reports from Saudi Arabia.
- Zacinlo rootkitscreen-capturespyware
- Also known as s5mark. Bitdefender describes the primary features of the family as follows: Presence of a rootkit driver that protects itself as well as its…
- Zanubis trojan
- According to cyware, Zanubis malware pretends to be a malicious PDF application.
- ZarDoor backdoor
- ZarDoor is a backdoor primarily used in targeted cyber-espionage campaigns against the public sector, particularly in the United States.
- ZariqaCrypt ransomware
- ZariqaCrypt is a ransomware variant that encrypts files on infected systems, demanding payment for decryption keys.
- Zcrypt ransomware
- Also known as Zcryptor. Zcrypt, also known as Zcryptor, is a type of ransomware that encrypts files on the infected system and demands a ransom for decryption.
- Zebrocy trojandownloader
- Also known as Zekapab. Zebrocy is a Trojan that has been used by APT28 since at least November 2015.
- Zebrocy (AutoIT) backdoorspywaretrojan
- Zebrocy is a malware family closely associated with APT28, used for espionage purposes.
- Zedhou trojan
- Zedhou is a Trojan malware known to operate stealthily and is designed to perform various malicious activities on compromised systems.
- ZekwaCrypt Ransomware ransomware
- First spotted in May 2016, however made a big comeback in January 2017.
- Zelta Free ransomware
- Zelta Free is a ransomware family known for encrypting files and demanding payment in cryptocurrency.
- Zen trojan
- Zen is a banking trojan known for targeting financial institutions and stealing sensitive user information.
- Zen trojanspyware
- Zen is Android malware that was first seen in 2013.
- ZenCrypt ransomware
- ZenCrypt is a type of ransomware that encrypts files on infected systems, demanding a ransom for their decryption.
- Zenis Ransomware ransomware
- A new ransomware was discovered this week by MalwareHunterTeam called Zenis Ransomware.
- Zeoticus ransomware
- Zeoticus is a ransomware family known for encrypting files on victims' machines and demanding a cryptocurrency ransom for decryption keys.
- Zeppelin ransomware
- Zeppelin is a strain of ransomware that encrypts the victim's files and demands a ransom for decryption.
- ZergHelper spyware
- ZergHelper is iOS riskware that was unique due to its apparent evasion of Apple's App Store review process.
- Zergeca botnetbackdoorddos
- Zergeca is a DDoS-botnet and backdoor written in Golang.
- Zero Tolerance Gang ransomwaretrojan
- Also known as Ztg. Zero Tolerance Gang, also known as Ztg, is a ransomware family targeted at financial services, government, and technology sectors.
- Zero-Fucks ransomware
- Zero-Fucks is a type of ransomware known for encrypting files on infected systems, demanding a ransom in exchange for decryption keys.
- ZeroBot botnetddos
- Also known as ZeroStresser. ZeroBot is a Go-based botnet that spreads primarily through IoT and web application vulnerabilities.
- ZeroCleare wiper
- Also known as ZEROCLEAR. ZeroCleare is a wiper malware that has been used in conjunction with the RawDisk driver since at least 2019 by suspected Iran-nexus threat…
- ZeroCrypt Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- ZeroEvil credential-stealerscreen-capturedownloader
- ZeroEvil is a malware that seems to be distributed by an ARSguarded VBS loader.
- ZeroLocker ransomware
- ZeroLocker is a type of ransomware that encrypts files on the victim's system and demands a ransom for the decryption key.
- ZeroRansom ransomware
- ZeroRansom is a type of ransomware known for encrypting files on infected systems and demanding a ransom payment for recovery.
- ZeroT trojan
- ZeroT is a Trojan used by TA459, often in conjunction with PlugX.
- Zeroaccess rootkitbotnet
- Also known as Max++, Sirefef, Smiscer. Zeroaccess is a kernel-mode Rootkit that attempts to add victims to the ZeroAccess botnet, often for monetary gain.
- Zeronine ransomware
- Zeronine is a ransomware that encrypts victims' files, demanding payment for decryption.
- Zeropadypt wiper
- Also known as Ouroboros. Zeropadypt, also known as Ouroboros, is a destructive malware primarily functioning as a wiper, targeting organizations in the financial…
- Zeus botnetcredential-stealertrojan
- Also known as Zbot. According to CrowdStrike, The two primary goals of the Zeus trojan horse virus are stealing people's financial information and adding…
- Zeus MailSniffer trojancredential-stealer
- Zeus MailSniffer is a variant of the Zeus Trojan, primarily targeting the financial services sector.
- Zeus OpenSSL credential-stealerbotnet
- Also known as XSphinx. This family describes the Zeus-variant that includes a version of OpenSSL and usually is downloaded by Zloader.
- Zeus Panda trojancredential-stealer
- Zeus Panda is a Trojan designed to steal banking information and other sensitive credentials for exfiltration.
- Zeus Sphinx trojancredential-stealer
- This family describes the vanilla Zeus-variant that includes TOR (and Polipo proxy).
- ZeusAction trojancredential-stealer
- ZeusAction is a banking Trojan primarily used to steal credentials from users in order to commit financial fraud.
- Zezin rat
- Zezin is a sophisticated remote access trojan (RAT) primarily used in cyber espionage operations targeting government and public sector…
- ZhCat spywaretrojan
- ZhCat is a sophisticated spyware and trojan malware known for its covert surveillance capabilities, often targeting government and…
- ZhMimikatz credential-stealerkeylogger
- ZhMimikatz is a malicious tool primarily designed for credential theft.
- Zhen ransomware
- Zhen is a ransomware variant known for encrypting files on victim systems and demanding a ransom for decryption keys.
- Ziggy ransomware
- Ziggy is a ransomware strain that encrypts files and demands a ransom in exchange for a decryption key.
- Zilla ransomware
- Zilla is a sophisticated ransomware family known for encrypting files and demanding cryptocurrency payments for decryption.
- Zimbra ransomware
- Zimbra is a ransomware strain often distributed via phishing emails.
- ZimbraCryptor ransomware
- ZimbraCryptor is a type of ransomware known for encrypting files on targeted systems and demanding a ransom for their release.
- ZingoStealer credential-stealerspyware
- Also known as Ginzo. ZingoStealer, also known as Ginzo, is an information stealer malware written in .NET.
- ZinoCrypt Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- ZipLocker ransomware
- ZipLocker is a type of ransomware that encrypts files and demands a ransom for decryption.
- Zipper ransomware
- Zipper is a ransomware family targeting vulnerabilities in various sectors to encrypt files and demand ransom.
- ZitMo trojan
- Also known as ZeuS-in-the-Mobile. ZitMo, also known as ZeuS-in-the-Mobile, is a mobile banking trojan targeting Android and Symbian devices.
- ZiyangRAT rat
- ZiyangRAT is a remote access trojan often used in cyber espionage campaigns targeting governmental and technology sectors, particularly in…
- Zloader loadertrojancredential-stealer
- Also known as DELoader, SILENTNIGHT, Terdot. This family describes the (initially small) loader, which downloads Zeus OpenSSL.
- Zlob trojanspyware
- Zlob is a Trojan that was first identified in 2007, often masquerading as a video codec or an update prompt.
- Zoldon ransomware
- Zoldon is a ransomware known for encrypting files and demanding a ransom for their recovery.
- Zollard worm
- Also known as darlloz. Zollard, also known as Darlloz, is a Linux-based worm that primarily targets Internet of Things (IoT) devices.
- ZooPark spyware
- ZooPark is an Android spyware campaign targeting political entities in the Middle East.
- Zorab ransomware
- Zorab is a ransomware variant that encrypts files and demands payment for decryption.
- ZorgoCry ransomware
- ZorgoCry is a type of ransomware that encrypts files on the victim's system and demands a ransom payment in cryptocurrency.
- Zorro ransomware
- Zorro is a ransomware family that encrypts files on infected systems, demanding a ransom in cryptocurrency for decryption keys.
- Zox rat
- Also known as Gresim, ZoxRPC, ZoxPNG. Zox is a remote access tool that has been used by Axiom since at least 2008.
- Ztorg trojan
- Also known as Qysly. Ztorg, also known as Qysly, is a family of Android trojans primarily used for ad fraud and privilege escalation.
- ZuRu downloaderspyware
- A malware that was observed being embedded alongside legitimate applications (such as iTerm2) offered for download on suspicious websites…
- Zumanek trojan
- According to ESET, this malware family was active exclusively in Brazil until the middle of 2020.
- ZuoRAT rat
- According to Black Lotus Labs, ZuoRAT is a MIPS file compiled for SOHO routers that can enumerate a host and internal LAN, capture packets…
- Zupdax trojan
- Zupdax is a trojan that has been observed in the wild.
- ZxShell ratbackdoor
- Also known as Sensocode. ZxShell is a remote administration tool and backdoor that can be downloaded from the Internet, particularly from Chinese hacker websites.
- ZxxZ trojandownloader
- Also known as MuuyDownloader. ZxxZ is a trojan written in Visual C++ that has been used by BITTER since at least August 2021, including against Bangladeshi government…
- Zyka Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Zyklon ransomware
- Also known as GNL Locker, Zyklon Locker. Zyklon is a ransomware variant belonging to the Hidden Tear family, specifically a GNL Locker variant.
- ZynorRAT rat
- ZynorRAT is a Remote Access Trojan used for cyber espionage activities.
- a1project ransomware
- The locker is written in C/C++/ASM. It supports all systems starting from Windows 2003, has a separate binary for ESXi, and uses a unified…
- aGl0bGVyCg ransomware
- Ransomware that encrypts files on infected systems and demands a ransom payment to decrypt them.
- aZaZeL ransomwarerootkit
- aZaZeL is a ransomware family known for encrypting files on infected systems and demanding a ransom for their release.
- abantes trojanbackdoor
- Abantes is a sophisticated trojan and backdoor malware family known to target the financial sector, government, and technology industries.
- abyss-data ransomware
- The abyss-data malware is a ransomware family known to target various critical sectors.
- adbupd backdoor
- adbupd is a backdoor used by PLATINUM that is similar to Dipsind.
- adminlocker ransomware
- AdminLocker was first observed around December 2021 and appears to be a lone operator or small group, with no clear…
- ailock ransomware
- AiLock is a Ransomware-as-a-Service (RaaS) group first identified in March 2025.
- alp-001 trojan
- alp-001 is a sophisticated Trojan malware used primarily in cyber-espionage campaigns.
- ank ransomware
- Ank is known as a ransomware strain that has been used in attacks targeting financial services, government institutions, and…
- antibrok3rs
- Antibrok3rs emerged as an access broker (not a ransomware operator itself) linked to the aftermath of the 2023 MOVEit supply-chain…
- apos backdoor
- Apos is a type of malware known to primarily target financial institutions.
- aptlock ransomware
- Aptlock surfaced in early 2025 and is characterized by a single-extortion model combined with threats of data leakage.
- arachna leak ransomware
- Arachna Leak is a ransomware family known for encrypting victims' files and threatening to leak sensitive information unless a ransom is…
- arcane ransomware
- Arcane first emerged in mid-2021 under the UNC2190 cluster and later rebranded as Sabbath, continuing its operations against critical…
- arcrypter ransomware
- ArcRypt (also known as ARCrypter or ChileLocker) was first identified in August 2022, originally targeting government entities in Latin…
- arcus media trojan
- Arcus Media is a trojan known for targeting media and technology industries.
- argonauts group rat
- The Argonauts Group is known for conducting cyber espionage activities primarily targeting government and defense sectors.
- arkana security ransomware
- Arkana Security is a type of ransomware designed to encrypt victims' files and demand a ransom for decryption.
- astralocker ransomware
- AstraLocker first appeared in 2021, likely as a fork of Babuk ransomware using leaked source code.
- at
- Also known as at.exe. at is used to schedule tasks on a system to run at a specified date or time.
- attrib
- Also known as attrib.exe. attrib is a Windows utility used to display, set or remove attributes assigned to files or directories.
- audit team
- No information is available about the 'audit team' malware.
- aurora ransomware
- Also known as OneKeyLocker. Aurora, also known as OneKeyLocker, is a ransomware family targeting multiple sectors including financial services and public sector…
- aware spywaretrojan
- Aware is a spyware and trojan malware used to silently monitor and exfiltrate information from infected systems, primarily targeting…