Malware Families page 56 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

ZIPLINE backdoor
ZIPLINE is a passive backdoor that was used during Cutting Edge on compromised Secure Connect VPNs for reverse shell and proxy…
ZLib backdoor
ZLib is a full-featured backdoor that was used as a second-stage implant during Operation Dust Storm since at least 2014.
ZOMBIE SLAYER ransomware
Zombie Slayer is a ransomware known for encrypting critical files and demanding payment for their release.
ZStealer credential-stealer
Also known as Z*Stealer. ZStealer is an information stealer malware commonly used by the cybercrime group Void Balaur.
ZUpdater downloadertrojan
Also known as Zpevdo. ZUpdater, also known as Zpevdo, is a downloader trojan used to deploy additional payloads onto infected systems.
ZXZ Ramsomware ransomware
Originated in English, could affect users worldwide, however so far only reports from Saudi Arabia.
Zacinlo rootkitscreen-capturespyware
Also known as s5mark. Bitdefender describes the primary features of the family as follows: Presence of a rootkit driver that protects itself as well as its…
Zanubis trojan
According to cyware, Zanubis malware pretends to be a malicious PDF application.
ZarDoor backdoor
ZarDoor is a backdoor primarily used in targeted cyber-espionage campaigns against the public sector, particularly in the United States.
ZariqaCrypt ransomware
ZariqaCrypt is a ransomware variant that encrypts files on infected systems, demanding payment for decryption keys.
Zcrypt ransomware
Also known as Zcryptor. Zcrypt, also known as Zcryptor, is a type of ransomware that encrypts files on the infected system and demands a ransom for decryption.
Zebrocy trojandownloader
Also known as Zekapab. Zebrocy is a Trojan that has been used by APT28 since at least November 2015.
Zebrocy (AutoIT) backdoorspywaretrojan
Zebrocy is a malware family closely associated with APT28, used for espionage purposes.
Zedhou trojan
Zedhou is a Trojan malware known to operate stealthily and is designed to perform various malicious activities on compromised systems.
ZekwaCrypt Ransomware ransomware
First spotted in May 2016, however made a big comeback in January 2017.
Zelta Free ransomware
Zelta Free is a ransomware family known for encrypting files and demanding payment in cryptocurrency.
Zen trojan
Zen is a banking trojan known for targeting financial institutions and stealing sensitive user information.
Zen trojanspyware
Zen is Android malware that was first seen in 2013.
ZenCrypt ransomware
ZenCrypt is a type of ransomware that encrypts files on infected systems, demanding a ransom for their decryption.
Zenis Ransomware ransomware
A new ransomware was discovered this week by MalwareHunterTeam called Zenis Ransomware.
Zeoticus ransomware
Zeoticus is a ransomware family known for encrypting files on victims' machines and demanding a cryptocurrency ransom for decryption keys.
Zeppelin ransomware
Zeppelin is a strain of ransomware that encrypts the victim's files and demands a ransom for decryption.
ZergHelper spyware
ZergHelper is iOS riskware that was unique due to its apparent evasion of Apple's App Store review process.
Zergeca botnetbackdoorddos
Zergeca is a DDoS-botnet and backdoor written in Golang.
Zero Tolerance Gang ransomwaretrojan
Also known as Ztg. Zero Tolerance Gang, also known as Ztg, is a ransomware family targeted at financial services, government, and technology sectors.
Zero-Fucks ransomware
Zero-Fucks is a type of ransomware known for encrypting files on infected systems, demanding a ransom in exchange for decryption keys.
ZeroBot botnetddos
Also known as ZeroStresser. ZeroBot is a Go-based botnet that spreads primarily through IoT and web application vulnerabilities.
ZeroCleare wiper
Also known as ZEROCLEAR. ZeroCleare is a wiper malware that has been used in conjunction with the RawDisk driver since at least 2019 by suspected Iran-nexus threat…
ZeroCrypt Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
ZeroEvil credential-stealerscreen-capturedownloader
ZeroEvil is a malware that seems to be distributed by an ARSguarded VBS loader.
ZeroLocker ransomware
ZeroLocker is a type of ransomware that encrypts files on the victim's system and demands a ransom for the decryption key.
ZeroRansom ransomware
ZeroRansom is a type of ransomware known for encrypting files on infected systems and demanding a ransom payment for recovery.
ZeroT trojan
ZeroT is a Trojan used by TA459, often in conjunction with PlugX.
Zeroaccess rootkitbotnet
Also known as Max++, Sirefef, Smiscer. Zeroaccess is a kernel-mode Rootkit that attempts to add victims to the ZeroAccess botnet, often for monetary gain.
Zeronine ransomware
Zeronine is a ransomware that encrypts victims' files, demanding payment for decryption.
Zeropadypt wiper
Also known as Ouroboros. Zeropadypt, also known as Ouroboros, is a destructive malware primarily functioning as a wiper, targeting organizations in the financial…
Zeus botnetcredential-stealertrojan
Also known as Zbot. According to CrowdStrike, The two primary goals of the Zeus trojan horse virus are stealing people's financial information and adding…
Zeus MailSniffer trojancredential-stealer
Zeus MailSniffer is a variant of the Zeus Trojan, primarily targeting the financial services sector.
Zeus OpenSSL credential-stealerbotnet
Also known as XSphinx. This family describes the Zeus-variant that includes a version of OpenSSL and usually is downloaded by Zloader.
Zeus Panda trojancredential-stealer
Zeus Panda is a Trojan designed to steal banking information and other sensitive credentials for exfiltration.
Zeus Sphinx trojancredential-stealer
This family describes the vanilla Zeus-variant that includes TOR (and Polipo proxy).
ZeusAction trojancredential-stealer
ZeusAction is a banking Trojan primarily used to steal credentials from users in order to commit financial fraud.
Zezin rat
Zezin is a sophisticated remote access trojan (RAT) primarily used in cyber espionage operations targeting government and public sector…
ZhCat spywaretrojan
ZhCat is a sophisticated spyware and trojan malware known for its covert surveillance capabilities, often targeting government and…
ZhMimikatz credential-stealerkeylogger
ZhMimikatz is a malicious tool primarily designed for credential theft.
Zhen ransomware
Zhen is a ransomware variant known for encrypting files on victim systems and demanding a ransom for decryption keys.
Ziggy ransomware
Ziggy is a ransomware strain that encrypts files and demands a ransom in exchange for a decryption key.
Zilla ransomware
Zilla is a sophisticated ransomware family known for encrypting files and demanding cryptocurrency payments for decryption.
Zimbra ransomware
Zimbra is a ransomware strain often distributed via phishing emails.
ZimbraCryptor ransomware
ZimbraCryptor is a type of ransomware known for encrypting files on targeted systems and demanding a ransom for their release.
ZingoStealer credential-stealerspyware
Also known as Ginzo. ZingoStealer, also known as Ginzo, is an information stealer malware written in .NET.
ZinoCrypt Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
ZipLocker ransomware
ZipLocker is a type of ransomware that encrypts files and demands a ransom for decryption.
Zipper ransomware
Zipper is a ransomware family targeting vulnerabilities in various sectors to encrypt files and demand ransom.
ZitMo trojan
Also known as ZeuS-in-the-Mobile. ZitMo, also known as ZeuS-in-the-Mobile, is a mobile banking trojan targeting Android and Symbian devices.
ZiyangRAT rat
ZiyangRAT is a remote access trojan often used in cyber espionage campaigns targeting governmental and technology sectors, particularly in…
Zloader loadertrojancredential-stealer
Also known as DELoader, SILENTNIGHT, Terdot. This family describes the (initially small) loader, which downloads Zeus OpenSSL.
Zlob trojanspyware
Zlob is a Trojan that was first identified in 2007, often masquerading as a video codec or an update prompt.
Zoldon ransomware
Zoldon is a ransomware known for encrypting files and demanding a ransom for their recovery.
Zollard worm
Also known as darlloz. Zollard, also known as Darlloz, is a Linux-based worm that primarily targets Internet of Things (IoT) devices.
ZooPark spyware
ZooPark is an Android spyware campaign targeting political entities in the Middle East.
Zorab ransomware
Zorab is a ransomware variant that encrypts files and demands payment for decryption.
ZorgoCry ransomware
ZorgoCry is a type of ransomware that encrypts files on the victim's system and demands a ransom payment in cryptocurrency.
Zorro ransomware
Zorro is a ransomware family that encrypts files on infected systems, demanding a ransom in cryptocurrency for decryption keys.
Zox rat
Also known as Gresim, ZoxRPC, ZoxPNG. Zox is a remote access tool that has been used by Axiom since at least 2008.
Ztorg trojan
Also known as Qysly. Ztorg, also known as Qysly, is a family of Android trojans primarily used for ad fraud and privilege escalation.
ZuRu downloaderspyware
A malware that was observed being embedded alongside legitimate applications (such as iTerm2) offered for download on suspicious websites…
Zumanek trojan
According to ESET, this malware family was active exclusively in Brazil until the middle of 2020.
ZuoRAT rat
According to Black Lotus Labs, ZuoRAT is a MIPS file compiled for SOHO routers that can enumerate a host and internal LAN, capture packets…
Zupdax trojan
Zupdax is a trojan that has been observed in the wild.
ZxShell ratbackdoor
Also known as Sensocode. ZxShell is a remote administration tool and backdoor that can be downloaded from the Internet, particularly from Chinese hacker websites.
ZxxZ trojandownloader
Also known as MuuyDownloader. ZxxZ is a trojan written in Visual C++ that has been used by BITTER since at least August 2021, including against Bangladeshi government…
Zyka Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Zyklon ransomware
Also known as GNL Locker, Zyklon Locker. Zyklon is a ransomware variant belonging to the Hidden Tear family, specifically a GNL Locker variant.
ZynorRAT rat
ZynorRAT is a Remote Access Trojan used for cyber espionage activities.
a1project ransomware
The locker is written in C/C++/ASM. It supports all systems starting from Windows 2003, has a separate binary for ESXi, and uses a unified…
aGl0bGVyCg ransomware
Ransomware that encrypts files on infected systems and demands a ransom payment to decrypt them.
aZaZeL ransomwarerootkit
aZaZeL is a ransomware family known for encrypting files on infected systems and demanding a ransom for their release.
abantes trojanbackdoor
Abantes is a sophisticated trojan and backdoor malware family known to target the financial sector, government, and technology industries.
abyss-data ransomware
The abyss-data malware is a ransomware family known to target various critical sectors.
adbupd backdoor
adbupd is a backdoor used by PLATINUM that is similar to Dipsind.
adminlocker ransomware
AdminLocker was first observed around December 2021 and appears to be a lone operator or small group, with no clear…
ailock ransomware
AiLock is a Ransomware-as-a-Service (RaaS) group first identified in March 2025.
alp-001 trojan
alp-001 is a sophisticated Trojan malware used primarily in cyber-espionage campaigns.
ank ransomware
Ank is known as a ransomware strain that has been used in attacks targeting financial services, government institutions, and…
antibrok3rs
Antibrok3rs emerged as an access broker (not a ransomware operator itself) linked to the aftermath of the 2023 MOVEit supply-chain…
apos backdoor
Apos is a type of malware known to primarily target financial institutions.
aptlock ransomware
Aptlock surfaced in early 2025 and is characterized by a single-extortion model combined with threats of data leakage.
arachna leak ransomware
Arachna Leak is a ransomware family known for encrypting victims' files and threatening to leak sensitive information unless a ransom is…
arcane ransomware
Arcane first emerged in mid-2021 under the UNC2190 cluster and later rebranded as Sabbath, continuing its operations against critical…
arcrypter ransomware
ArcRypt (also known as ARCrypter or ChileLocker) was first identified in August 2022, originally targeting government entities in Latin…
arcus media trojan
Arcus Media is a trojan known for targeting media and technology industries.
argonauts group rat
The Argonauts Group is known for conducting cyber espionage activities primarily targeting government and defense sectors.
arkana security ransomware
Arkana Security is a type of ransomware designed to encrypt victims' files and demand a ransom for decryption.
astralocker ransomware
AstraLocker first appeared in 2021, likely as a fork of Babuk ransomware using leaked source code.
at
Also known as at.exe. at is used to schedule tasks on a system to run at a specified date or time.
attrib
Also known as attrib.exe. attrib is a Windows utility used to display, set or remove attributes assigned to files or directories.
audit team
No information is available about the 'audit team' malware.
aurora ransomware
Also known as OneKeyLocker. Aurora, also known as OneKeyLocker, is a ransomware family targeting multiple sectors including financial services and public sector…
aware spywaretrojan
Aware is a spyware and trojan malware used to silently monitor and exfiltrate information from infected systems, primarily targeting…