Malware Families page 58 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- d0glun ransomware
- D0glun is a crypto-ransomware strain first observed in January 2025, believed to be derived from Babuk via an intermediary variant known…
- d4rk4rmy trojanransomware
- D4rk4rmy is a sophisticated trojan and ransomware malware family targeting government and financial sectors.
- dan0n ransomware
- dAn0n is a data-extortion actor that first appeared in April 2024.
- dark shinigami ransomware
- Dark Shinigami is a ransomware known to target government and financial sectors.
- darkhav0c ransomware
- Darkhav0c is a ransomware strain known for encrypting files on infected systems and demanding a ransom payment for decryption.
- darkrace ransomware
- DarkRace is a moderately destructive ransomware strain observed since 2024.
- darkrypt ransomware
- Darkrypt is a ransomware malware family known for encrypting files on infected systems and demanding a ransom for their decryption.
- darkvault trojan
- DarkVault is a sophisticated trojan used primarily for cyber-espionage, targeting financial and governmental institutions in the US and…
- darkwave trojanbackdoor
- Darkwave is a Python-based malware typically used as a backdoor.
- darkylock ransomware
- Darky Lock is a commodity-style ransomware strain first identified in July 2022, derived from publicly available Babuk source code.
- datacarry backdoorspyware
- Datacarry is a sophisticated malware family used for cyber-espionage operations.
- dataf locker ransomware
- DataF Locker is a ransomware variant first observed in 2024, closely tied to the Babuk ransomware lineage.
- ddoor backdoor
- Ddoor is a backdoor trojan primarily used for unauthorized remote access and control.
- deadbydawn ransomware
- Deadbydawn is a ransomware family known for encrypting files on victims' systems and demanding payment for decryption keys.
- deadlock
- death
- Death malware has no detailed description available and lacks specific targeting information or categorization.
- deathgrip ransomware
- DeathGrip is a Ransomware-as-a-Service (RaaS) that emerged around June 2024, offering malware payloads built with leaked LockBit 3.0 and…
- delta backdoortrojan
- Delta is a sophisticated backdoor Trojan used by advanced persistent threat groups to target critical sectors globally.
- desolated rat
- Desolated is a sophisticated remote access trojan (RAT) known for targeting government and financial sectors.
- desolator trojanwiper
- Desolator is a sophisticated trojan and wiper used in cyber-espionage campaigns.
- devman spywaretrojan
- Devman is a mobile malware targeting Android devices.
- devman2 backdoortrojan
- Devman2 is a sophisticated backdoor trojan used for cyber-espionage activities, primarily targeting the government and financial sectors…
- dharma ransomware
- Also known as Arena, Crysis, Wadhrama. Dharma is a prolific ransomware family active since at least 2016, evolving from the earlier CrySiS ransomware.
- direwolf trojancredential-stealer
- Direwolf is a banking Trojan known for targeting financial institutions primarily in the US and Canada.
- dispossessor trojan
- Dispossessor is a malware variant known for its trojan capabilities, often used to gain unauthorized access and control over a victim's…
- dmsSpy spyware
- dmsSpy is a sophisticated spyware used primarily for espionage.
- dnWipe wiper
- dnWipe is a destructive malware that primarily targets data integrity by wiping data on infected systems.
- doenerium credential-stealerspyware
- Open sourced javascript info stealer, with the capabilities of stealing crypto wallets, password, cookies and modify discord clients…
- donex ransomware
- The ransomware group known as DoNex was first identified in mid-March 2024.
- donut_injector loader
- Also known as Donut. Donut is an open-source in-memory injector/loader, designed for execution of VBScript, JScript, EXE, DLL files and dotNET assemblies.
- doommageddon
- down_new downloader
- down_new is a downloader that has been used by BRONZE BUTLER since at least 2019.
- dragonforce ransomware
- Research on the operators of the DragonForce ransomware was conducted, and it was identified that the group emerged around mid-November…
- dsquery
- Also known as dsquery.exe. dsquery is a command-line utility that can be used to query Active Directory for information from a system within a domain.
- dunghill ransomware
- Dunghill Leak is the publicly branded data leak site (DLS) operated by the Dark Angels ransomware group, established circa January 2023.
- dynamichttp rat
- According to its source repository, dynamichttp is a Mythic C2 Profile, which simply provides a way to get HTTP messages off the wire and…
- eBayWall ransomware
- eBayWall is a ransomware that encrypts files on infected systems, demanding payment for decryption.
- eCh0raix ransomware
- Anomali researchers have observed a new ransomware family, dubbed eCh0raix, targeting QNAP Network Attached Storage (NAS) devices.
- eSurv spyware
- eSurv is mobile surveillanceware designed for the lawful intercept market that was developed over the course of many years.
- el dorado ransomwaretrojan
- This group is believed to be connected to Lost Trust.
- elcometa backdoorrat
- Elcometa is a malware associated with cyber espionage, primarily targeting government and aerospace sectors in Eastern Europe.
- elf.iocontrol backdoor
- Also known as OrpraCab, QueueCat. IOControl is a Linux backdoor which targets ARM-based IoT and OT systems, which a particular focus on Fuel and Industrial Control Systems.
- elf.wellmess backdoortrojan
- WellMess is designed to execute arbitrary commands and exfiltrate system information.
- elonmusknow trojan
- Elonmusknow is a Trojan malware that targets the technology sector, particularly in the United States.
- elpaco ransomwaredropper
- Elpaco is a variant of Mimic ransomware that emerged around August 2023.
- emansrepo credential-stealerspyware
- Emansrepo is an infostealer malware family designed to exfiltrate sensitive information from infected systems.
- embrago rattrojan
- Embrago is a remote access trojan (RAT) often used in cyber espionage campaigns.
- enciphered ransomware
- Enciphered, also known as xoriste, is a type of ransomware that targets financial services and technology sectors primarily in the United…
- encrypthub ransomware
- EncryptHub is a ransomware family known for targeting organizations in various sectors, encrypting their data, and demanding a ransom for…
- encryptoJJS ransomware
- EncryptoJJS is a piece of ransomware known for encrypting files on the victim's machine and demanding a ransom for decryption keys.
- eruption ransomware
- Eruption is a ransomware that has been rebranded to Sabbath.
- esentutl
- Also known as esentutl.exe. esentutl is a command-line tool that provides database utilities for the Windows Extensible Storage Engine.
- evilginx2 credential-stealer
- evilginx2 is an open-source adversary-in-the-middle (AiTM) attack framework based on the open-source nginx web server.
- exitium wiperransomware
- Exitium is a destructive malware family known for its dual capabilities of data wiping and ransomware.
- ext4
- The ext4 malware currently lacks a specific description and is not widely documented.
- fakersa trojanspyware
- Fakersa is a malware family known for targeting specific sectors, particularly within the Middle East.
- fancyfilter spywarerootkit
- Also known as 0xFancyFilter. FancyFilter is a piece of code that documents code overlap between frameworks used by Regin and Equation Group.
- farattack ratbackdoor
- Farattack is a sophisticated remote access Trojan (RAT) used primarily for cyber espionage activities.
- fargo ransomware
- Fargo is a ransomware variant that surfaced in 2022, primarily targeting Microsoft SQL Server (MSSQL) systems.
- faust ransomware
- Faust is a variant of the well-known Phobos ransomware, part of a Ransomware-as-a-Service (RaaS) ecosystem active since around May 2019.
- fengine trojan
- Fengine is a trojan malware family primarily targeting government and technology sectors.
- fletchen ransomware
- Fletchen is a ransomware strain that encrypts files on infected systems, primarily targeting government and financial services.
- floodor trojanbotnet
- Floodor is a malware trojan known for its involvement in orchestrating large-scale botnet operations.
- fog backdoortrojan
- Fog is a sophisticated malware primarily used for espionage and data exfiltration.
- forbiks ransomwaretrojan
- Also known as Forbix. Forbiks, also known as Forbix, is a ransomware family that targets financial and technology sectors primarily in the US, UK, and Canada.
- frag
- The malware known as 'frag' has no detailed description available, and its operational specifics or targets are not well-documented.
- freeworld ransomware
- FreeWorld is a ransomware variant first observed in September 2023, and is believed to be derived from the Mimic ransomware family.
- frozen ransomware
- Frozen is a ransomware family known for encrypting files and demanding ransom from victims.
- ftp downloader
- Also known as ftp.exe. ftp is a utility commonly available with operating systems to transfer information over the File Transfer Protocol (FTP).
- fulcrumsec rat
- Fulcrumsec is an advanced remote access tool used primarily for cyber espionage.
- funksec rat
- Funksec is a malicious remote access tool (RAT) primarily used in cyber-espionage campaigns against financial services and government…
- fusion rat
- Fusion is a sophisticated remote access trojan (RAT) often used in cyber-espionage operations targeting the government and defense sectors.
- gamapos credential-stealertrojan
- Also known as pios. GamePos is a point-of-sale (PoS) malware family that is primarily used to steal payment card information from compromised systems.
- gangbang
- garrantydecrypt ransomware
- Michael Gillespie found a new ransomware that appends the .garrantydecrypt extension and drops a ransom note named #RECOVERY_FILES#.txt
- gazprom backdoor
- Gazprom is a malware with limited available information.
- gcman backdoorrat
- Gcman is a sophisticated backdoor and remote access tool primarily used for financial espionage and targeting government entities.
- gd lockersec ransomware
- Our team members are from different countries and we are not interested in anything else, we are only interested in dollars.
- genesis ransomware
- Financial interests only. We do not provide or work with affiliate programs, no collaborations either. The requested payment must be made…
- get_pwd credential-stealertrojan
- Get_pwd is a malware known for extracting credentials from compromised systems.
- gh0st RAT ratbackdoor
- Also known as Mydoor, Moudoor. gh0st RAT is a remote access tool (RAT). The source code is public and it has been used by multiple groups.
- ghost ransomware
- Also known as Ucul. aka Cring / Ghost (Cring) Beginning early 2021, Ghost actors began attacking victims whose internet facing services ran outdated versions…
- global trojan
- Also known as GLOBAL GROUP. Global is a cyber threat group sometimes associated with the alias GLOBAL GROUP.
- globe ransomware
- Globe is a ransomware family that first appeared in August 2016, notable for its highly customizable codebase that allows operators to…
- goDoH trojan
- Proof of concept for data exfiltration via DoH, written in Go.
- gokcpdoor backdoor
- According to LAC, this malware is written in Go and was observed in 2022 used by an unknown China-based APT across several incidents in…
- good day ransomware
- Good Day is a ransomware variant within the ARCrypter family, first observed in May 2023.
- goontact spyware
- Goontact is a mobile spyware targeting Android and iOS devices, often distributed through phishing techniques.
- grelos credential-stealer
- grelos is a skimmer used for magecart-style attacks.
- grep
- The name 'grep' generally refers to a command-line utility for searching plain-text data for matching strings.
- grinch trojan
- Grinch is a trojan known for its stealthy operations, often used in cybercrime activities.
- gsecdump credential-stealer
- gsecdump is a publicly-available credential dumper used to obtain password hashes and LSA secrets from Windows operating systems.
- gunra trojan
- Gunra is a banking trojan designed to steal sensitive information such as online banking credentials.
- gwisin ransomware
- Gwisin is a targeted ransomware group first publicly reported in July 2022, believed to operate primarily within South Korea.
- handala trojan
- Handala is a trojan known to target government entities, primarily in the Palestinian territories.
- hcdLoader rat
- hcdLoader is a remote access tool (RAT) that has been used by APT18.
- hellcat ransomware
- Hellcat is a ransomware family that primarily targets government and financial sectors in the US and Russia.
- helldown trojanbackdoor
- Helldown is a sophisticated trojan and backdoor malware family used primarily in cyber-espionage campaigns targeting government and…
- hellogookie rat
- Hellogookie is a remote access trojan (RAT) primarily targeting financial and government sectors in Asia.
- help_restoremydata ransomware
- .help_restoremydata ext : .help_restoremydata note : HOW_TO_RECOVERY_FILES.html mail : [email protected] md5…