Malware Families page 59 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

hermes ransomwarewiper
Hermes is a ransomware family first observed in the wild in February 2017, believed to have been developed by a group operating out of Asia.
heyoka backdoorrat
Heyoka is a known malware family primarily used for cyber espionage.
himalayaa backdoor
Himalayaa is a backdoor that allows unauthorized access to compromised systems.
himan
himan is a malware with limited available information.
holyghost ransomware
HolyGhost is a ransomware group first publicly reported in July 2022, believed to be operated by a North Korean state-sponsored threat…
homeland ratspyware
Homeland is a remote access tool (RAT) that has been used in cyber espionage campaigns targeting government and infrastructure sectors in…
htpRAT rat
htpRAT is a Remote Access Trojan (RAT) used to gain unauthorized access and control over infected computers.
http_troy trojan
Http_troy is a trojan primarily leveraged for data exfiltration and reconnaissance activities within financial and government sectors.
httpclient backdoor
httpclient is malware used by Putter Panda.
httpdropper dropper
Also known as httpdr0pper. HTTPDropper is a type of malware designed to stealthily introduce other malicious software into a system by using HTTP for communication.
hunters trojanrat
Also known as Hunters International. Hunters is a malware family associated with cybercrime operations, often targeting financial services and technology sectors.
hyflock ransomware
Hyflock is a ransomware family known for encrypting victims' files and demanding a ransom payment in exchange for decryption.
iGZa4C ransomware
iGZa4C is a ransomware variant known for encrypting files on infected systems and demanding payment for decryption.
iKitten spyware
Also known as OSX/MacDownloader. iKitten is a macOS exfiltration agent also known as OSX/MacDownloader.
iLock ransomware
iLock is a ransomware that encrypts files on the infected system and demands a ransom for decryption.
iLockLight ransomware
iLockLight is a ransomware variant known for encrypting files and demanding a ransom payment for decryption.
iMuler downloaderdropperbackdoor
Also known as Revir. The threat was a multi-stage malware displaying a decoy that appeared to the victim as a Chinese language article on the long-running…
iRansom ransomware
iRansom is a ransomware that encrypts files on the victim's system, demanding a ransom for their decryption.
iSpy Keylogger keyloggercredential-stealer
iSpy Keylogger is a notorious malware family known for its ability to capture keystrokes and steal sensitive information from infected…
ifconfig
ifconfig is a Unix-based utility used to gather information about and interact with the TCP/IP settings on a system.
imn crew trojan
IMN Crew is a sophisticated threat actor associated with cyber espionage and targeting government and financial sectors.
inc ransom ransomware
Inc Ransom is a ransomware family known for encrypting files on compromised systems and demanding ransom payments for decryption.
insane ransomware ransomware
Insane is a relatively obscure ransomware family first reported in late 2021, with few confirmed incidents in public threat intelligence.
inter
No description available for the malware named 'inter'.
interlock ransomware
Interlock is a ransomware family known for encrypting files on infected systems and demanding a ransom for decryption keys.
invaderx
Invaderx is a piece of malware with limited available information.
iox webshell
A maliciously abused open source tool for port forwarding & intranet proxy.
ipconfig
ipconfig is a Windows utility that can be used to find information about a system's TCP/IP, DNS, DHCP, and adapter configuration.
ironchain
Ironchain is a malware with limited public information available.
izis backdoortrojan
Izis is a sophisticated malware family known for its backdoor and trojan capabilities, primarily targeting financial and government…
j group
The 'j group' malware is known with limited information available.
j ransomware ransomware
J ransomware is a malicious software targeting various industries by encrypting files on compromised systems and demanding a ransom for…
jCandy ransomware
jCandy is a ransomware strain that encrypts victims' files and demands a ransom for decryption.
jRAT ratbackdoorspyware
Also known as JSocket, AlienSpy, Frutas. jRAT is a cross-platform, Java-based backdoor originally available for purchase in 2012.
jSpy spywareratkeylogger
jSpy is a sophisticated remote access tool (RAT) used for cyber-espionage.
jason credential-stealerexploit-kit
Jason is a graphic tool implemented to perform Microsoft exchange account brute-force in order to “harvest” the highest possible emails…
jo of satan ransomware
Jo of Satan is a ransomware family known for encrypting files and demanding a ransom from victims to restore access.
join.me rat
join.me is a remote access program from the producers of LogMeIn that provides quick access to another computer over an internet browser.
js.wd downloader
The threat actor of this family compromised Chrome extension developer accounts and attached malicious code to the extensions.
jspRAT rat
jspRAT is a remote access tool (RAT) primarily used for cyber espionage activities.
jsworm ransomware
JSWorm is a ransomware family that first appeared in May 2019 and is notable for undergoing multiple rebrands and evolutions, later…
kairos
karma ransomware
Karma is a ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
kasseika ransomware
Kasseika is a ransomware variant first publicly reported in January 2024, identified as a new evolution of the BlackMatter/LockBit…
kawa
kazu rat
Kazu is a remote access trojan used to infiltrate government, financial, and technology sectors, providing attackers with stealthy access…
kerberods backdoorrootkit
Kerberods is a Linux-based malware that primarily functions as a backdoor and rootkit, targeting financial, government, and healthcare…
key group
No detailed information is currently available about the malware named 'key group.' Further research and analysis are required to…
kfos backdoor
Kfos is a backdoor malware often used in attacks targeting the financial services and government sectors.
killada rat
Killada is a remote access Trojan (RAT) known for its espionage capabilities targeting governmental and energy sectors.
killsec ransomware
KillSec is a ransomware family known for encrypting files and demanding a ransom for the decryption key.
killsec3 ransomware
Killsec3 is a ransomware family that targets government and financial services sectors primarily in the United States and United Kingdom.
kirov backdoorrat
Kirov is a sophisticated malware often used for cyber espionage activities.
kitty-socks5
Kitty-socks5 is a malicious software component designed to facilitate SOCKS5 proxy operations, enabling threat actors to redirect and…
kittykatkrew ddos
Kittykatkrew is a malware variant primarily known for its use in DDoS attacks.
kkRAT ratscreen-capture
According to Zscaler, a malware sharing similarities with GhostRAT and Big Bad Wolf.
knight ransomware
Also known as Cyclops. Knight, also known as Cyclops, is a ransomware family that targets critical infrastructure and various industries.
kraken ransomware
Kraken, also known as HelloKitty, is a ransomware family known for operating a leak site where they publish stolen data from victims.
krybit ransomware
Krybit is a ransomware family that targets the financial and technology sectors.
krypt ransomware
Krypt is a ransomware malware family known for encrypting user data and demanding ransom payments.
kryptina ransomware
Kryptina is a ransomware family known for encrypting files on infected systems and demanding payment for the decryption key.
kryptos ratspyware
Kryptos is a remote access tool primarily used for espionage against government and technology sectors.
kuiper trojan
Kuiper is a trojan malware with minimal distinguishing features publicly documented.
kuza
kuza is a piece of malware with limited public information regarding its capabilities, targets, or origins.
kyber
Kyber is a relatively obscure malware strain with limited available public information.
la piovra ratspyware
La Piovra is a sophisticated remote access tool (RAT) used primarily for espionage purposes.
lamashtu rat
Lamashtu is a Remote Access Trojan (RAT) known for targeting government and defense sectors.
lambda
No information is available about the malware named 'lambda', including its operation, types, or targeted sectors and regions.
lamialocker ransomware
Lamialocker is a ransomware family known for encrypting files and demanding a ransom for file restoration.
lampion downloader
Malware is delivered by emails, containing links to ZIP files or ZIP attachments.
late.lol
The late.lol malware is associated with affiliates known by handles such as @Mr.C, @Empathy, @jayze, @Widow, and @Memory.
lcryptorx ransomware
Lcryptorx is a ransomware family known for encrypting data and demanding ransom payments in the financial services and healthcare sectors.
leak bazaar credential-stealer
Leak Bazaar is a platform facilitating the sale and distribution of stolen data on the dark web.
leakeddata credential-stealer
Leakeddata is a credential-stealer malware that primarily targets financial services, retail, and technology sectors.
leaknet
In the cyber-undergrounds, we're exploring shadowed corridors of the digital world in search of inside information.
lilyofthevalley
No description is currently available for the malware known as lilyofthevalley.
limedownloader downloaderloader
LimeDownloader is a lightweight malware primarily used to download and execute additional malicious payloads.
limeminer cryptominer
LimeMiner is a cryptomining malware that can infect systems to mine cryptocurrency without the user's consent.
linkc backdoorrat
LinkC is a Remote Access Trojan (RAT) often utilized by advanced persistent threat (APT) groups to gain unauthorized access and control…
lockbit4 ransomware
LockBit 4.0 is a variant of ransomware that targets multiple industries worldwide.
lockbit5 ransomware
LockBit 5 is a sophisticated ransomware family that targets a wide range of industries by encrypting files and demanding a ransom for…
lockdata ransomware
Lockdata is a ransomware strain that encrypts user files to demand a ransom payment for their decryption.
lockscreen ransomware
Lockscreen malware is a type of ransomware that restricts access to the user's device by displaying a persistent screen overlay.
locus backdoor
Locus is a backdoor malware with limited publicly available information.
lokilocker ransomwarewiper
Lokilocker is a ransomware family known for encrypting files and, in certain cases, acting as a wiper by irreversibly deleting data from…
looChiper ransomware
LooChiper is a Ransomware. It uses a nice but scary name: LooCipher. The name is at the same time an allusion to its capabilities (thank…
lorenz ransomware
Tesorion describes Lorenz as a ransomware with design and implementation flaws, leading to impossible decryption with tools provided by…
losttrust backdoorcredential-stealer
LostTrust is a sophisticated backdoor malware used in cyber-espionage campaigns.
lsassDumper credential-stealer
This in Go written malware is lsass process memory dumper, which was custom developed by threat actors according to Security Joes.
lsd
LSD is a malware with insufficient public data available.
luckbit ransomware
Luckbit is a form of ransomware that targets financial and technology sectors.
lukalocker ransomware
Lukalocker is a ransomware family that encrypts victims' files and demands payment.
lulzsec muslims ddos
LulzSec Muslims is associated with the hacktivist group known for launching DDoS attacks, targeting government and media entities.
lunalock ransomware
Lunalock is a ransomware family known for encrypting users' data and demanding ransom for decryption keys.
lynx rat
Lynx is a remote access Trojan known for its use in cyber espionage campaigns targeting government and telecommunications sectors.
lynxr rat
Lynxr is a remote access trojan (RAT) used for cyber espionage activities targeting government, financial, and tech organizations.
lyrix backdoortrojan
Lyrix is a backdoor malware family used in cyber-espionage campaigns targeting sensitive sectors such as government and public utilities.
m0yv virusransomware
Modular x86/x64 file infector created/used by Maze ransomware developer.
m3rx trojan
M3rx is a trojan malware known for clandestine operations typically involving unauthorized access and data exfiltration.
macOS.OSAMiner cryptominertrojan
macOS.OSAMiner is a Monero mining trojan that was first observed in 2018; security researchers assessed macOS.OSAMiner may have been…