Malware Families page 57 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

axxes ransomware
Axxes ransomware emerged as a rebranded version of the previously known Midas ransomware group, with roots also tracing back through Haron…
azzasec ransomwarebotnet
We are AzzaSec — a decentralized PMC (Private Military Contractor), RaaS (Ransomware-as-a-Service) syndicate, and botnet operator at the…
b0 group backdoorrat
The b0 group is a backdoor and remote access tool (RAT) commonly associated with cyber espionage campaigns targeting governmental entities…
babuk-bjorka ransomware
On January 26th, Babuk's dedicated leak site (DLS) was "relaunched".
babylockerkz ransomware
BabyLockerKZ is a variant of MedusaLocker ransomware, first observed in late 2023.
backmydata ransomware
BackMyData is a variant of the Phobos ransomware family, first observed in early 2024.
badbazaar spywarekeyloggerscreen-capture
BadBazaar is a type of malware primarily functioning as a spyware.
balletspistol trojanbackdoor
Balletspistol is a sophisticated Trojan that provides attackers with unauthorized remote access to affected systems.
bancos trojan
Bancos is a banking trojan primarily targeting financial institutions in Latin America.
bangat trojanbackdoor
Bangat is a malware family known for its trojan and backdoor capabilities, often used to gain unauthorized access and control over…
barkiofork trojan
Barkiofork is a trojan known for targeting government and telecommunications sectors.
bavacai
beast rat
Beast is one of the early remote access trojans (RATs) that could be used to gain unauthorized access to a victim's computer.
beendoor trojanscreen-capture
BEENDOOR is a XMPP based trojan. It is capable of taking screenshots of the victim's desktop.
belsen group ratspyware
Belsen Group, also known as Belesn Group, is a cyber-espionage operation primarily targeting government and technology sectors.
benzona trojan
Benzona is a trojan malware typically used to infiltrate financial services and government sectors.
bert ransomware
BERT ransomware (also tracked as Water Pombero) first emerged in April 2025, rapidly targeting both Windows and Linux systems across Asia…
bidon ransomware
BIDON is a variant of the Monti ransomware family, first observed around mid‑2023.
bifrose backdoorrat
Bifrose is a family of backdoor Trojans and remote access tools (RATs) that allow attackers to gain unauthorized access to infected systems.
bioload loaderdropper
Bioload is a malware primarily used as a loader for other malicious payloads, often targeting financial institutions and the technology…
bjorka trojan
Hellcome Bjorkanism is a type of malware with trojan functionality.
black nevas ransomware
BlackNevas ransomware — also referred to as “Trial Recovery” — was first observed in November 2024.
black shrantac trojan
Black Shrantac is a type of trojan malware used primarily for espionage and data exfiltration, targeting financial services and government…
black suit ransomware
BlackSuit is a type of malicious software classified as ransomware.
black witch
Black Witch is a malware with limited available information.
black x
blackberserk ransomware
Black Berserk is a relatively unsophisticated ransomware strain analyzed in late 2023.
blackbit ransomware
BlackBit ransomware was first observed in August 2022 and is a .NET-based strain that closely mimics the design and functionality of…
blackbyte-crux ransomware
BlackByte-Crux is a ransomware family that has been observed targeting critical infrastructure sectors such as financial services…
blackfield ransomware
Blackfield is a ransomware malware family known for targeting government and educational sectors, primarily in the United States and India.
blackfile
blackhunt ratcredential-stealer
Blackhunt is a remote access tool and credential stealer known for targeting financial services, government, and technology industries.
blackshrantac rat
Blackshrantac is a remote access trojan (RAT) used in cyber espionage operations.
blacksnake ransomware
BlackSnake is a Ransomware-as-a-Service (RaaS) operation that first appeared in August 2022, when its operators began recruiting…
blackwater backdoor
Blackwater is a type of backdoor malware known for its ability to execute commands and control infected systems remotely.
bluebox backdoortrojan
Bluebox is a sophisticated piece of malware primarily targeting financial services and government sectors.
bober ratbackdoor
Bober is a Remote Access Trojan (RAT) that enables attackers to gain administrative control over infected systems.
booba team
bqtlock ransomware
Bqtlock, also known as BaqiyatLock, is a ransomware family that targets financial and governmental sectors in the US and UK, encrypting…
br0k3r ransomwarespyware
Br0k3r is not a conventional ransomware gang, but rather an Iran-linked cyber espionage and access brokerage group leveraging its foothold…
brain cipher ransomware
In mid-June 2024, a new ransomware operation named Brain Cipher emerged, notably targeting Indonesia's National Data Center.
bravox backdoorrat
Bravox is a sophisticated remote access tool used by cyber threat actors to infiltrate targeted networks.
brotherhood rat
Brotherhood malware is a known Remote Access Trojan (RAT) used in cyber-espionage campaigns, primarily targeting government and defense…
brute_ratel rat
Brute Ratel is an advanced red-teaming tool that functions similarly to a remote access trojan.
buddyransome ransomware
Buddyransome is a ransomware that encrypts files on victim machines and demands a ransom payment for decryption keys.
bugsleep backdoorrat
Also known as MuddyRot. Bugsleep, also known as MuddyRot, is a stealthy remote access tool (RAT) primarily used by threat actors for cyber espionage.
build_downer downloader
build_downer is a downloader that has been used by BRONZE BUTLER since at least 2019.
bytesfromheaven spywaretrojan
Bytesfromheaven is a sophisticated espionage malware family designed to conduct reconnaissance and data exfiltration operations.
c0d0so0 backdoorrat
c0d0so0 is a sophisticated malware family used primarily for cyber espionage campaigns.
c3rb3r ransomware
c3rb3r is a ransomware family that encrypts victim files and demands a ransom for decryption.
c99shell webshellbackdoor
Also known as c99. C99shell is a PHP backdoor that provides a lot of functionality, for example: * run shell commands; * download/upload files from and to…
cactus ransomware
The CACTUS ransomware is said to have emerged around March 2023.
campoloader loader
Campoloader is a sophisticated malware loader often used in targeted attacks against government and financial institutions.
catb ransomwaredropper
CatB ransomware was first observed in late 2022, gaining attention for abusing DLL hijacking via the Microsoft Distributed Transaction…
ccf32 spyware
ccf32 is data collection malware that has been used since at least February 2019, most notably during the FunnyDream campaign; there is…
cd00r backdoor
cd00r is an open-source backdoor for UNIX and UNIX-variant operating systems that was orginally released in 2000.
cephalus ratspyware
Cephalus is a remote access tool used primarily in espionage campaigns targeting government and financial sectors.
cerberimposter ransomware
Cerber Imposer is a post-2019 rebrand of the Cerber ransomware family, resurfacing in late 2021 with updated targeting of enterprise…
cerbersyslock ransomware
CerBerSysLock first appeared in December 2017 as a cryptoransomware imposter, leveraging Cerber-style branding to deceive victims.
certutil downloadertrojan
Also known as certutil.exe. certutil is a command-line utility that can be used to obtain certificate authority information and configure Certificate Services.
chilelocker ransomware
ChileLocker first emerged in August 2022 and is considered part of the broader ARCrypter ransomware family.
chort ransomware
Chort is a relatively new data-extortion ransomware group that surfaced in late 2024, with confirmed activity beginning in…
cicada3301 spywarerat
Cicada3301 is associated with cyber-espionage activities, targeting various sectors such as government, education, and technology.
cifty downloader
Cifty is a family of downloader malware known for its capability to download and execute other malicious payloads.
ciphbit ransomware
Ciphbit is a ransomware family that encrypts files on infected systems, demanding a ransom for decryption.
cipher.exe
cipher.exe is a native Microsoft utility that manages encryption of directories and files on NTFS (New Technology File System) partitions…
cipherforce trojanransomware
For those out of the loop, you may already know us as TeamPCP or Shellforce, we have been active a while publishing data and writing…
cipherwolf ratspyware
Cipherwolf is a sophisticated remote access trojan (RAT) known for its espionage capabilities, primarily used to target government sectors…
clearwater backdoor
Clearwater malware is a type of backdoor used by threat actors to gain unauthorized access to targeted systems.
cloak rat
Cloak is a remote access tool (RAT) known for its stealth capabilities, often used by threat actors to maintain persistent access to…
cloak.su ransomware
Also known as locker leak. cloak.su, also known as locker leak, is a ransomware family targeting various sectors, most notably technology, financial services, and…
clop torrents ransomware
Clop is a ransomware family known for encrypting files on infected systems and demanding ransom payments for decryption keys.
cmd
Also known as cmd.exe. cmd is the Windows command-line interpreter that can be used to interact with systems and execute other processes and utilities.
cmd organization
cmoon backdoor
Cmoon is a backdoor malware that facilitates remote access and command execution on compromised systems.
coinbase cartel credential-stealer
The Coinbase Cartel, also known as ShinyHunters, is a cybercriminal group known for targeting various industries with credential-stealing…
coldbrew backdoortrojan
Coldbrew is a sophisticated malware family primarily used to create backdoors in victim systems, enabling persistent access and data…
colossus ransomware
Colossus ransomware was first observed in September 2021, when ZeroFox researchers uncovered the variant attacking a U.S.-based automotive…
concealment_troy trojan
Concealment Troy is a sophisticated trojan that primarily targets government and defense sectors.
contfr ransomware
Launched around September 2024, ContFR is a French-speaking RaaS that uses a Tor-hosted platform to provide ransomware embedded in PDF…
core ransomware
Core ransomware surfaced in early 2025 as a new variant within the broader Makop family.
crackshot downloader
CRACKSHOT is a downloader that can download files, including binaries, and run them from the hard disk or execute them directly in memory.
crazyhunter team rat
Crazyhunter Team is associated with cyber espionage activities, often targeting sectors such as government, finance, and telecommunications.
crosslock ransomware
CrossLock ransomware was first observed in April 2023, targeting an IT services firm in Brazil using a double‑extortion…
crpx0
cry0
crynox ransomware
Crynox (sometimes referred to as “Crynox Ransomware”) appears to be a generic file-locker threat that appends .crynox to encrypted files…
cryp70n1c0d3 ransomware
Cryp70n1c0d3 is a ransomware strain that targets various sectors including financial services and government.
crypt ransomware ransomware
.crYpt MD5: 54EFAC23D7B524D56BEDBCE887E11849 Babuk Variant
cryptbb ransomware
CryptBB is a ransomware strain primarily known for encrypting files on infected systems and demanding a ransom for decryption keys.
cryptedpay ransomware
Cryptedpay is a ransomware family known for targeting financial services and technology sectors.
cryptnet cryptominer
Cryptnet is a malware family known for illicitly mining cryptocurrency on infected machines.
crypto24 ransomware
Crypto24, also known as Public Data Storage, is a ransomware family that encrypts files and demands a ransom for the decryption key.
cs-137 ransomware
Cs‑137 is a newly observed ransomware strain that first appeared in January 2025.
csharp-streamer RAT rat
csharp-streamer RAT is a remote access tool developed using C#.
ctblocker ransomware
aka Critroni CTB‑Locker emerged in mid‑2014, introducing a new era of ransomware by leveraging elliptic curve cryptography (ECC)…
cyberex trojanransomware
Cyberex is a malicious software family primarily known for its trojan and ransomware capabilities.
cyclops ransomware
Cyclops ransomware was rebranded as Knight around mid‑2023, emerging initially in early 2023.
cylance
Cylance is an endpoint security solution known for using artificial intelligence and machine learning to detect and prevent malware.
cysxl rat
Cysxl is a remote access tool (RAT) primarily utilized for espionage against government and telecommunications sectors.