Malware Families page 59 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- hermes ransomwarewiper
- Hermes is a ransomware family first observed in the wild in February 2017, believed to have been developed by a group operating out of Asia.
- heyoka backdoorrat
- Heyoka is a known malware family primarily used for cyber espionage.
- himalayaa backdoor
- Himalayaa is a backdoor that allows unauthorized access to compromised systems.
- himan
- himan is a malware with limited available information.
- holyghost ransomware
- HolyGhost is a ransomware group first publicly reported in July 2022, believed to be operated by a North Korean state-sponsored threat…
- homeland ratspyware
- Homeland is a remote access tool (RAT) that has been used in cyber espionage campaigns targeting government and infrastructure sectors in…
- htpRAT rat
- htpRAT is a Remote Access Trojan (RAT) used to gain unauthorized access and control over infected computers.
- http_troy trojan
- Http_troy is a trojan primarily leveraged for data exfiltration and reconnaissance activities within financial and government sectors.
- httpclient backdoor
- httpclient is malware used by Putter Panda.
- httpdropper dropper
- Also known as httpdr0pper. HTTPDropper is a type of malware designed to stealthily introduce other malicious software into a system by using HTTP for communication.
- hunters trojanrat
- Also known as Hunters International. Hunters is a malware family associated with cybercrime operations, often targeting financial services and technology sectors.
- hyflock ransomware
- Hyflock is a ransomware family known for encrypting victims' files and demanding a ransom payment in exchange for decryption.
- iGZa4C ransomware
- iGZa4C is a ransomware variant known for encrypting files on infected systems and demanding payment for decryption.
- iKitten spyware
- Also known as OSX/MacDownloader. iKitten is a macOS exfiltration agent also known as OSX/MacDownloader.
- iLock ransomware
- iLock is a ransomware that encrypts files on the infected system and demands a ransom for decryption.
- iLockLight ransomware
- iLockLight is a ransomware variant known for encrypting files and demanding a ransom payment for decryption.
- iMuler downloaderdropperbackdoor
- Also known as Revir. The threat was a multi-stage malware displaying a decoy that appeared to the victim as a Chinese language article on the long-running…
- iRansom ransomware
- iRansom is a ransomware that encrypts files on the victim's system, demanding a ransom for their decryption.
- iSpy Keylogger keyloggercredential-stealer
- iSpy Keylogger is a notorious malware family known for its ability to capture keystrokes and steal sensitive information from infected…
- ifconfig
- ifconfig is a Unix-based utility used to gather information about and interact with the TCP/IP settings on a system.
- imn crew trojan
- IMN Crew is a sophisticated threat actor associated with cyber espionage and targeting government and financial sectors.
- inc ransom ransomware
- Inc Ransom is a ransomware family known for encrypting files on compromised systems and demanding ransom payments for decryption.
- insane ransomware ransomware
- Insane is a relatively obscure ransomware family first reported in late 2021, with few confirmed incidents in public threat intelligence.
- inter
- No description available for the malware named 'inter'.
- interlock ransomware
- Interlock is a ransomware family known for encrypting files on infected systems and demanding a ransom for decryption keys.
- invaderx
- Invaderx is a piece of malware with limited available information.
- iox webshell
- A maliciously abused open source tool for port forwarding & intranet proxy.
- ipconfig
- ipconfig is a Windows utility that can be used to find information about a system's TCP/IP, DNS, DHCP, and adapter configuration.
- ironchain
- Ironchain is a malware with limited public information available.
- izis backdoortrojan
- Izis is a sophisticated malware family known for its backdoor and trojan capabilities, primarily targeting financial and government…
- j group
- The 'j group' malware is known with limited information available.
- j ransomware ransomware
- J ransomware is a malicious software targeting various industries by encrypting files on compromised systems and demanding a ransom for…
- jCandy ransomware
- jCandy is a ransomware strain that encrypts victims' files and demands a ransom for decryption.
- jRAT ratbackdoorspyware
- Also known as JSocket, AlienSpy, Frutas. jRAT is a cross-platform, Java-based backdoor originally available for purchase in 2012.
- jSpy spywareratkeylogger
- jSpy is a sophisticated remote access tool (RAT) used for cyber-espionage.
- jason credential-stealerexploit-kit
- Jason is a graphic tool implemented to perform Microsoft exchange account brute-force in order to “harvest” the highest possible emails…
- jo of satan ransomware
- Jo of Satan is a ransomware family known for encrypting files and demanding a ransom from victims to restore access.
- join.me rat
- join.me is a remote access program from the producers of LogMeIn that provides quick access to another computer over an internet browser.
- js.wd downloader
- The threat actor of this family compromised Chrome extension developer accounts and attached malicious code to the extensions.
- jspRAT rat
- jspRAT is a remote access tool (RAT) primarily used for cyber espionage activities.
- jsworm ransomware
- JSWorm is a ransomware family that first appeared in May 2019 and is notable for undergoing multiple rebrands and evolutions, later…
- kairos
- karma ransomware
- Karma is a ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
- kasseika ransomware
- Kasseika is a ransomware variant first publicly reported in January 2024, identified as a new evolution of the BlackMatter/LockBit…
- kawa
- kazu rat
- Kazu is a remote access trojan used to infiltrate government, financial, and technology sectors, providing attackers with stealthy access…
- kerberods backdoorrootkit
- Kerberods is a Linux-based malware that primarily functions as a backdoor and rootkit, targeting financial, government, and healthcare…
- key group
- No detailed information is currently available about the malware named 'key group.' Further research and analysis are required to…
- kfos backdoor
- Kfos is a backdoor malware often used in attacks targeting the financial services and government sectors.
- killada rat
- Killada is a remote access Trojan (RAT) known for its espionage capabilities targeting governmental and energy sectors.
- killsec ransomware
- KillSec is a ransomware family known for encrypting files and demanding a ransom for the decryption key.
- killsec3 ransomware
- Killsec3 is a ransomware family that targets government and financial services sectors primarily in the United States and United Kingdom.
- kirov backdoorrat
- Kirov is a sophisticated malware often used for cyber espionage activities.
- kitty-socks5
- Kitty-socks5 is a malicious software component designed to facilitate SOCKS5 proxy operations, enabling threat actors to redirect and…
- kittykatkrew ddos
- Kittykatkrew is a malware variant primarily known for its use in DDoS attacks.
- kkRAT ratscreen-capture
- According to Zscaler, a malware sharing similarities with GhostRAT and Big Bad Wolf.
- knight ransomware
- Also known as Cyclops. Knight, also known as Cyclops, is a ransomware family that targets critical infrastructure and various industries.
- kraken ransomware
- Kraken, also known as HelloKitty, is a ransomware family known for operating a leak site where they publish stolen data from victims.
- krybit ransomware
- Krybit is a ransomware family that targets the financial and technology sectors.
- krypt ransomware
- Krypt is a ransomware malware family known for encrypting user data and demanding ransom payments.
- kryptina ransomware
- Kryptina is a ransomware family known for encrypting files on infected systems and demanding payment for the decryption key.
- kryptos ratspyware
- Kryptos is a remote access tool primarily used for espionage against government and technology sectors.
- kuiper trojan
- Kuiper is a trojan malware with minimal distinguishing features publicly documented.
- kuza
- kuza is a piece of malware with limited public information regarding its capabilities, targets, or origins.
- kyber
- Kyber is a relatively obscure malware strain with limited available public information.
- la piovra ratspyware
- La Piovra is a sophisticated remote access tool (RAT) used primarily for espionage purposes.
- lamashtu rat
- Lamashtu is a Remote Access Trojan (RAT) known for targeting government and defense sectors.
- lambda
- No information is available about the malware named 'lambda', including its operation, types, or targeted sectors and regions.
- lamialocker ransomware
- Lamialocker is a ransomware family known for encrypting files and demanding a ransom for file restoration.
- lampion downloader
- Malware is delivered by emails, containing links to ZIP files or ZIP attachments.
- late.lol
- The late.lol malware is associated with affiliates known by handles such as @Mr.C, @Empathy, @jayze, @Widow, and @Memory.
- lcryptorx ransomware
- Lcryptorx is a ransomware family known for encrypting data and demanding ransom payments in the financial services and healthcare sectors.
- leak bazaar credential-stealer
- Leak Bazaar is a platform facilitating the sale and distribution of stolen data on the dark web.
- leakeddata credential-stealer
- Leakeddata is a credential-stealer malware that primarily targets financial services, retail, and technology sectors.
- leaknet
- In the cyber-undergrounds, we're exploring shadowed corridors of the digital world in search of inside information.
- lilyofthevalley
- No description is currently available for the malware known as lilyofthevalley.
- limedownloader downloaderloader
- LimeDownloader is a lightweight malware primarily used to download and execute additional malicious payloads.
- limeminer cryptominer
- LimeMiner is a cryptomining malware that can infect systems to mine cryptocurrency without the user's consent.
- linkc backdoorrat
- LinkC is a Remote Access Trojan (RAT) often utilized by advanced persistent threat (APT) groups to gain unauthorized access and control…
- lockbit4 ransomware
- LockBit 4.0 is a variant of ransomware that targets multiple industries worldwide.
- lockbit5 ransomware
- LockBit 5 is a sophisticated ransomware family that targets a wide range of industries by encrypting files and demanding a ransom for…
- lockdata ransomware
- Lockdata is a ransomware strain that encrypts user files to demand a ransom payment for their decryption.
- lockscreen ransomware
- Lockscreen malware is a type of ransomware that restricts access to the user's device by displaying a persistent screen overlay.
- locus backdoor
- Locus is a backdoor malware with limited publicly available information.
- lokilocker ransomwarewiper
- Lokilocker is a ransomware family known for encrypting files and, in certain cases, acting as a wiper by irreversibly deleting data from…
- looChiper ransomware
- LooChiper is a Ransomware. It uses a nice but scary name: LooCipher. The name is at the same time an allusion to its capabilities (thank…
- lorenz ransomware
- Tesorion describes Lorenz as a ransomware with design and implementation flaws, leading to impossible decryption with tools provided by…
- losttrust backdoorcredential-stealer
- LostTrust is a sophisticated backdoor malware used in cyber-espionage campaigns.
- lsassDumper credential-stealer
- This in Go written malware is lsass process memory dumper, which was custom developed by threat actors according to Security Joes.
- lsd
- LSD is a malware with insufficient public data available.
- luckbit ransomware
- Luckbit is a form of ransomware that targets financial and technology sectors.
- lukalocker ransomware
- Lukalocker is a ransomware family that encrypts victims' files and demands payment.
- lulzsec muslims ddos
- LulzSec Muslims is associated with the hacktivist group known for launching DDoS attacks, targeting government and media entities.
- lunalock ransomware
- Lunalock is a ransomware family known for encrypting users' data and demanding ransom for decryption keys.
- lynx rat
- Lynx is a remote access Trojan known for its use in cyber espionage campaigns targeting government and telecommunications sectors.
- lynxr rat
- Lynxr is a remote access trojan (RAT) used for cyber espionage activities targeting government, financial, and tech organizations.
- lyrix backdoortrojan
- Lyrix is a backdoor malware family used in cyber-espionage campaigns targeting sensitive sectors such as government and public utilities.
- m0yv virusransomware
- Modular x86/x64 file infector created/used by Maze ransomware developer.
- m3rx trojan
- M3rx is a trojan malware known for clandestine operations typically involving unauthorized access and data exfiltration.
- macOS.OSAMiner cryptominertrojan
- macOS.OSAMiner is a Monero mining trojan that was first observed in 2018; security researchers assessed macOS.OSAMiner may have been…