Malware Families page 57 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- axxes ransomware
- Axxes ransomware emerged as a rebranded version of the previously known Midas ransomware group, with roots also tracing back through Haron…
- azzasec ransomwarebotnet
- We are AzzaSec — a decentralized PMC (Private Military Contractor), RaaS (Ransomware-as-a-Service) syndicate, and botnet operator at the…
- b0 group backdoorrat
- The b0 group is a backdoor and remote access tool (RAT) commonly associated with cyber espionage campaigns targeting governmental entities…
- babuk-bjorka ransomware
- On January 26th, Babuk's dedicated leak site (DLS) was "relaunched".
- babylockerkz ransomware
- BabyLockerKZ is a variant of MedusaLocker ransomware, first observed in late 2023.
- backmydata ransomware
- BackMyData is a variant of the Phobos ransomware family, first observed in early 2024.
- badbazaar spywarekeyloggerscreen-capture
- BadBazaar is a type of malware primarily functioning as a spyware.
- balletspistol trojanbackdoor
- Balletspistol is a sophisticated Trojan that provides attackers with unauthorized remote access to affected systems.
- bancos trojan
- Bancos is a banking trojan primarily targeting financial institutions in Latin America.
- bangat trojanbackdoor
- Bangat is a malware family known for its trojan and backdoor capabilities, often used to gain unauthorized access and control over…
- barkiofork trojan
- Barkiofork is a trojan known for targeting government and telecommunications sectors.
- bavacai
- beast rat
- Beast is one of the early remote access trojans (RATs) that could be used to gain unauthorized access to a victim's computer.
- beendoor trojanscreen-capture
- BEENDOOR is a XMPP based trojan. It is capable of taking screenshots of the victim's desktop.
- belsen group ratspyware
- Belsen Group, also known as Belesn Group, is a cyber-espionage operation primarily targeting government and technology sectors.
- benzona trojan
- Benzona is a trojan malware typically used to infiltrate financial services and government sectors.
- bert ransomware
- BERT ransomware (also tracked as Water Pombero) first emerged in April 2025, rapidly targeting both Windows and Linux systems across Asia…
- bidon ransomware
- BIDON is a variant of the Monti ransomware family, first observed around mid‑2023.
- bifrose backdoorrat
- Bifrose is a family of backdoor Trojans and remote access tools (RATs) that allow attackers to gain unauthorized access to infected systems.
- bioload loaderdropper
- Bioload is a malware primarily used as a loader for other malicious payloads, often targeting financial institutions and the technology…
- bjorka trojan
- Hellcome Bjorkanism is a type of malware with trojan functionality.
- black nevas ransomware
- BlackNevas ransomware — also referred to as “Trial Recovery” — was first observed in November 2024.
- black shrantac trojan
- Black Shrantac is a type of trojan malware used primarily for espionage and data exfiltration, targeting financial services and government…
- black suit ransomware
- BlackSuit is a type of malicious software classified as ransomware.
- black witch
- Black Witch is a malware with limited available information.
- black x
- blackberserk ransomware
- Black Berserk is a relatively unsophisticated ransomware strain analyzed in late 2023.
- blackbit ransomware
- BlackBit ransomware was first observed in August 2022 and is a .NET-based strain that closely mimics the design and functionality of…
- blackbyte-crux ransomware
- BlackByte-Crux is a ransomware family that has been observed targeting critical infrastructure sectors such as financial services…
- blackfield ransomware
- Blackfield is a ransomware malware family known for targeting government and educational sectors, primarily in the United States and India.
- blackfile
- blackhunt ratcredential-stealer
- Blackhunt is a remote access tool and credential stealer known for targeting financial services, government, and technology industries.
- blackshrantac rat
- Blackshrantac is a remote access trojan (RAT) used in cyber espionage operations.
- blacksnake ransomware
- BlackSnake is a Ransomware-as-a-Service (RaaS) operation that first appeared in August 2022, when its operators began recruiting…
- blackwater backdoor
- Blackwater is a type of backdoor malware known for its ability to execute commands and control infected systems remotely.
- bluebox backdoortrojan
- Bluebox is a sophisticated piece of malware primarily targeting financial services and government sectors.
- bober ratbackdoor
- Bober is a Remote Access Trojan (RAT) that enables attackers to gain administrative control over infected systems.
- booba team
- bqtlock ransomware
- Bqtlock, also known as BaqiyatLock, is a ransomware family that targets financial and governmental sectors in the US and UK, encrypting…
- br0k3r ransomwarespyware
- Br0k3r is not a conventional ransomware gang, but rather an Iran-linked cyber espionage and access brokerage group leveraging its foothold…
- brain cipher ransomware
- In mid-June 2024, a new ransomware operation named Brain Cipher emerged, notably targeting Indonesia's National Data Center.
- bravox backdoorrat
- Bravox is a sophisticated remote access tool used by cyber threat actors to infiltrate targeted networks.
- brotherhood rat
- Brotherhood malware is a known Remote Access Trojan (RAT) used in cyber-espionage campaigns, primarily targeting government and defense…
- brute_ratel rat
- Brute Ratel is an advanced red-teaming tool that functions similarly to a remote access trojan.
- buddyransome ransomware
- Buddyransome is a ransomware that encrypts files on victim machines and demands a ransom payment for decryption keys.
- bugsleep backdoorrat
- Also known as MuddyRot. Bugsleep, also known as MuddyRot, is a stealthy remote access tool (RAT) primarily used by threat actors for cyber espionage.
- build_downer downloader
- build_downer is a downloader that has been used by BRONZE BUTLER since at least 2019.
- bytesfromheaven spywaretrojan
- Bytesfromheaven is a sophisticated espionage malware family designed to conduct reconnaissance and data exfiltration operations.
- c0d0so0 backdoorrat
- c0d0so0 is a sophisticated malware family used primarily for cyber espionage campaigns.
- c3rb3r ransomware
- c3rb3r is a ransomware family that encrypts victim files and demands a ransom for decryption.
- c99shell webshellbackdoor
- Also known as c99. C99shell is a PHP backdoor that provides a lot of functionality, for example: * run shell commands; * download/upload files from and to…
- cactus ransomware
- The CACTUS ransomware is said to have emerged around March 2023.
- campoloader loader
- Campoloader is a sophisticated malware loader often used in targeted attacks against government and financial institutions.
- catb ransomwaredropper
- CatB ransomware was first observed in late 2022, gaining attention for abusing DLL hijacking via the Microsoft Distributed Transaction…
- ccf32 spyware
- ccf32 is data collection malware that has been used since at least February 2019, most notably during the FunnyDream campaign; there is…
- cd00r backdoor
- cd00r is an open-source backdoor for UNIX and UNIX-variant operating systems that was orginally released in 2000.
- cephalus ratspyware
- Cephalus is a remote access tool used primarily in espionage campaigns targeting government and financial sectors.
- cerberimposter ransomware
- Cerber Imposer is a post-2019 rebrand of the Cerber ransomware family, resurfacing in late 2021 with updated targeting of enterprise…
- cerbersyslock ransomware
- CerBerSysLock first appeared in December 2017 as a cryptoransomware imposter, leveraging Cerber-style branding to deceive victims.
- certutil downloadertrojan
- Also known as certutil.exe. certutil is a command-line utility that can be used to obtain certificate authority information and configure Certificate Services.
- chilelocker ransomware
- ChileLocker first emerged in August 2022 and is considered part of the broader ARCrypter ransomware family.
- chort ransomware
- Chort is a relatively new data-extortion ransomware group that surfaced in late 2024, with confirmed activity beginning in…
- cicada3301 spywarerat
- Cicada3301 is associated with cyber-espionage activities, targeting various sectors such as government, education, and technology.
- cifty downloader
- Cifty is a family of downloader malware known for its capability to download and execute other malicious payloads.
- ciphbit ransomware
- Ciphbit is a ransomware family that encrypts files on infected systems, demanding a ransom for decryption.
- cipher.exe
- cipher.exe is a native Microsoft utility that manages encryption of directories and files on NTFS (New Technology File System) partitions…
- cipherforce trojanransomware
- For those out of the loop, you may already know us as TeamPCP or Shellforce, we have been active a while publishing data and writing…
- cipherwolf ratspyware
- Cipherwolf is a sophisticated remote access trojan (RAT) known for its espionage capabilities, primarily used to target government sectors…
- clearwater backdoor
- Clearwater malware is a type of backdoor used by threat actors to gain unauthorized access to targeted systems.
- cloak rat
- Cloak is a remote access tool (RAT) known for its stealth capabilities, often used by threat actors to maintain persistent access to…
- cloak.su ransomware
- Also known as locker leak. cloak.su, also known as locker leak, is a ransomware family targeting various sectors, most notably technology, financial services, and…
- clop torrents ransomware
- Clop is a ransomware family known for encrypting files on infected systems and demanding ransom payments for decryption keys.
- cmd
- Also known as cmd.exe. cmd is the Windows command-line interpreter that can be used to interact with systems and execute other processes and utilities.
- cmd organization
- cmoon backdoor
- Cmoon is a backdoor malware that facilitates remote access and command execution on compromised systems.
- coinbase cartel credential-stealer
- The Coinbase Cartel, also known as ShinyHunters, is a cybercriminal group known for targeting various industries with credential-stealing…
- coldbrew backdoortrojan
- Coldbrew is a sophisticated malware family primarily used to create backdoors in victim systems, enabling persistent access and data…
- colossus ransomware
- Colossus ransomware was first observed in September 2021, when ZeroFox researchers uncovered the variant attacking a U.S.-based automotive…
- concealment_troy trojan
- Concealment Troy is a sophisticated trojan that primarily targets government and defense sectors.
- contfr ransomware
- Launched around September 2024, ContFR is a French-speaking RaaS that uses a Tor-hosted platform to provide ransomware embedded in PDF…
- core ransomware
- Core ransomware surfaced in early 2025 as a new variant within the broader Makop family.
- crackshot downloader
- CRACKSHOT is a downloader that can download files, including binaries, and run them from the hard disk or execute them directly in memory.
- crazyhunter team rat
- Crazyhunter Team is associated with cyber espionage activities, often targeting sectors such as government, finance, and telecommunications.
- crosslock ransomware
- CrossLock ransomware was first observed in April 2023, targeting an IT services firm in Brazil using a double‑extortion…
- crpx0
- cry0
- crynox ransomware
- Crynox (sometimes referred to as “Crynox Ransomware”) appears to be a generic file-locker threat that appends .crynox to encrypted files…
- cryp70n1c0d3 ransomware
- Cryp70n1c0d3 is a ransomware strain that targets various sectors including financial services and government.
- crypt ransomware ransomware
- .crYpt MD5: 54EFAC23D7B524D56BEDBCE887E11849 Babuk Variant
- cryptbb ransomware
- CryptBB is a ransomware strain primarily known for encrypting files on infected systems and demanding a ransom for decryption keys.
- cryptedpay ransomware
- Cryptedpay is a ransomware family known for targeting financial services and technology sectors.
- cryptnet cryptominer
- Cryptnet is a malware family known for illicitly mining cryptocurrency on infected machines.
- crypto24 ransomware
- Crypto24, also known as Public Data Storage, is a ransomware family that encrypts files and demands a ransom for the decryption key.
- cs-137 ransomware
- Cs‑137 is a newly observed ransomware strain that first appeared in January 2025.
- csharp-streamer RAT rat
- csharp-streamer RAT is a remote access tool developed using C#.
- ctblocker ransomware
- aka Critroni CTB‑Locker emerged in mid‑2014, introducing a new era of ransomware by leveraging elliptic curve cryptography (ECC)…
- cyberex trojanransomware
- Cyberex is a malicious software family primarily known for its trojan and ransomware capabilities.
- cyclops ransomware
- Cyclops ransomware was rebranded as Knight around mid‑2023, emerging initially in early 2023.
- cylance
- Cylance is an endpoint security solution known for using artificial intelligence and machine learning to detect and prevent malware.
- cysxl rat
- Cysxl is a remote access tool (RAT) primarily utilized for espionage against government and telecommunications sectors.