Malware Families page 6 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- BeaverTail (Javascript) loaderspywaretrojan
- BeaverTail is a JavaScript malware primarily distributed through NPM packages.
- BeaverTail (OS X) rat
- BeaverTail is a remote access tool (RAT) that targets OS X systems.
- Bedep loaderbotnet
- Bedep has been mostly observed in ad-fraud campaigns, although it can also generally load modules for different tasks.
- Bee rat
- Malware family observed in conjunction with PlugX infrastructure in 2013.
- BeepService loadertrojan
- BeepService is a malicious software tool designed to facilitate the loading of other payloads and perform unauthorized actions on infected…
- BeethoveN ransomware
- BeethoveN is a ransomware strain known for encrypting files on affected systems and demanding a ransom for recovery.
- Behinder webshell
- A webshell for multiple web languages (asp/aspx, jsp/jspx, php), openly distributed through Github.
- Bella rat
- Bella is a remote access trojan known for its capability to execute commands, capture screenshots, and exfiltrate sensitive data.
- BellaCiao rat
- BellaCiao is a remote access trojan (RAT) observed in 2023.
- Belonard trojan
- Once set up in the system, Trojan.Belonard replaces the list of available game servers in the game client and creates proxies on the…
- BendyBear downloaderloader
- BendyBear is an x64 shellcode for a stage-zero implant designed to download malware from a C2 server.
- Berbew backdoor
- Berbew, also known as Padodor, is a backdoor Trojan that installs itself on a system to enable remote access by an attacker.
- Berbomthum rat
- Berbomthum is a remote access trojan primarily used in cyber espionage campaigns targeting government entities.
- BernhardPOS trojan
- BernhardPOS is a point-of-sale malware that targets credit card data typically used in the retail and hospitality industries.
- Berserk Stealer credential-stealer
- Berserk Stealer is a credential-stealing malware family used to exfiltrate sensitive information such as login credentials from infected…
- Best Crypt ransomware
- Best Crypt is a ransomware program known for encrypting files on infected systems and demanding a ransom in cryptocurrency for decryption.
- BestChangeRu ransomware
- BestChangeRu is a type of ransomware that targets financial and technology sectors.
- BestKorea trojanbackdoor
- BestKorea is a state-sponsored malware linked to North Korean threat actors, primarily used for cyber-espionage against government and…
- BetaBot credential-stealertrojanspyware
- Also known as Neurevt. Cybereason concludes that Betabot is a sophisticated infostealer malware that’s evolved significantly since it first appeared in late 2012.
- Bezigate backdoortrojan
- Bezigate is a Trojan horse that opens a back door on the compromised computer.
- BfBot botnetcredential-stealer
- BfBot is a type of botnet malware primarily used to perform credential-stealing operations.
- BiBi wiper
- Also known as BiBi-Windows. A Windows version of the BiBi wiper that was found by BlackBerry.
- BiBi-Linux wiper
- According to Security Joes, this malware is an x64 ELF executable, lacking obfuscation or protective measures.
- BianLian (Android) trojancredential-stealer
- Also known as Hydra. BianLian is an Android banking trojan known for targeting financial institutions by stealing user credentials.
- BianLian (ELF) ransomware
- BianLian is a ransomware family known for encrypting files on compromised systems.
- BianLian (Windows) ransomware
- BianLian is a GoLang-based ransomware that continues to breach several industries and demand large ransom amounts.
- Bianlian ransomware
- Also known as Hydra. BianLian used subtle techniques to exploit, enumerate, and move laterally in victim networks to remain undetected and aggressively worked…
- Bifrost backdoorrat
- Also known as elf.bifrose. Linux version of the bifrose malware that originally targeted Windows platform only.
- BigBobRoss ransomware
- BigBobRoss ransomware is the cryptovirus that requires a ransom in Bitcoin to return encrypted files marked with .obfuscated appendix.
- BigBossHorse ransomware
- BigBossHorse is a ransomware family known for encrypting files and demanding a ransom payment.
- BigViktor botnetddos
- A DDoS bot abusing CVE-2020-8515 to target DrayTek Vigor routers.
- Biglock ransomware
- Biglock is a ransomware family known for encrypting victim data and demanding payment for the decryption key.
- BillGates botnetddosbackdoor
- BillGates is a modularized malware, of supposedly Chinese origin.
- Binanen dropperspyware
- Binanen is a dropper that drops and executes a section of itself into a hidden dummy process.
- Binary Validator dropperspyware
- Binary Validator is a Mach-O binary file used during Operation Triangulation.
- BingoMod downloaderspyware
- BingoMod is a malware family known for its capabilities in downloading and executing additional payloads and conducting espionage…
- BioData spyware
- BioData is a spyware family targeting the healthcare and public sector industries.
- BioSet ransomware
- BioSet is a sophisticated ransomware family known for targeting sectors like healthcare, government, and technology industries.
- Biodox wiper
- Biodox is a wiper malware typically used in espionage campaigns targeting the healthcare and governmental sectors.
- Birbware ransomware
- Ransomware
- Bisonal rat
- Bisonal is a remote access tool (RAT) that has been used by Tonto Team against public and private sector organizations in Russia, South…
- BitCrypt ransomware
- BitCrypt is a type of ransomware that encrypts files on the infected machine and demands a ransom for the decryption key.
- BitCrypt 2.0 ransomware
- BitCrypt 2.0 is a ransomware variant known for encrypting victims' files and demanding bitcoin as ransom.
- BitCryptor ransomware
- Ransomware Has a GUI. CryptoGraphic Locker family. Newer CoinVault variant.
- BitKangoroo ransomware
- BitKangoroo is a ransomware family that encrypts user data and demands a ransom for decryption keys.
- BitPaymer ransomware
- Also known as wp_encrypt, FriedEx, IEncrypt. BitPaymer is a ransomware variant first observed in August 2017 targeting hospitals in the U.K.
- BitPyLock ransomware
- BitPyLock is a ransomware known for encrypting files on infected systems and demanding a ransom payment in cryptocurrency.
- BitRAT ratcredential-stealercryptominer
- According to Bitdefender, BitRAT is a notorious remote access trojan (RAT) marketed on underground cybercriminal web markets and forums.
- BitRansomware ransomware
- BitRansomware is a type of ransomware designed to encrypt files on infected systems and demand a ransom for decryption.
- BitStak ransomware
- BitStak is a type of ransomware known for encrypting files on infected systems and demanding a ransom for their release.
- Bitshifter ransomware
- Bitshifter is a type of ransomware that encrypts victim data and demands ransom in exchange for decryption keys.
- Bitsran dropperransomware
- Also known as SHADYCAT. SHADYCAT is a dropper and spreader component for the HERMES 2.1 RANSOMWARE radical edition.
- Bitter RAT rat
- Bitter RAT is a remote access trojan primarily focused on cyber espionage.
- BizHack ransomware
- BizHack is a type of ransomware known for encrypting victims' files and demanding payment for the decryption key.
- Bizzaro trojancredential-stealer
- Kaspersky Labs characterizes Bizarro as yet another banking Trojan family originating from Brazil that is now found in other regions of…
- Black Basta ransomware
- Black Basta is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022…
- Black Basta (ELF) ransomware
- ESXi encrypting ransomware, using a combination of the stream cipher ChaCha20 and RSA.
- Black Basta (Windows) ransomware
- Also known as no_name_software. "Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their…
- Black Feather ransomware
- Black Feather is a type of ransomware used by cybercriminals to encrypt files and demand payment for their decryption.
- Black Ruby ransomwarecryptominer
- Also known as BlackRuby. A new ransomware was discovered this week by MalwareHunterTeam called Black Ruby.
- Black Worm ransomware
- Black Worm is a ransomware strain known for encrypting files and demanding a ransom for their decryption.
- Black claw ransomware
- Black Claw is a ransomware family that encrypts victim systems, demanding a ransom for decryption.
- BlackBasta ransomware
- Black Basta is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their…
- BlackByte ransomwareworm
- BlackByte is recently discovered Ransomware with a .NET DLL core payload wrapped in JavaScript.
- BlackByte 2.0 Ransomware ransomware
- BlackByte 2.0 Ransomware is a replacement for BlackByte Ransomware.
- BlackByte Ransomware ransomware
- BlackByte Ransomware is uniquely associated with BlackByte operations.
- BlackCat ransomware
- Also known as ALPHV, Noberus. BlackCat is ransomware written in Rust that has been offered via the Ransomware-as-a-Service (RaaS) model.
- BlackEnergy botnetddostrojan
- Also known as Black Energy. BlackEnergy is a malware toolkit that has been used by both criminal and APT actors.
- BlackEnergy 3
- BlackEnergy 3 is a malware toolkit that has been used by both criminal and APT actors.
- BlackFireEye ransomware
- BlackFireEye is a ransomware strain known for encrypting files on infected systems and demanding a ransom for decryption.
- BlackGuard credential-stealerspyware
- According to Zscaler, BlackGuard has the capability to steal all types of information related to Crypto wallets, VPN, Messengers, FTP…
- BlackHat-Mehtihack ransomware
- BlackHat-Mehtihack is a type of ransomware targeting various industries.
- BlackHole rat
- C# RAT (Remote Adminitration Tool) - Educational purposes only
- BlackKingdom ransomware
- BlackKingdom is a ransomware strain used in cybercrime operations.
- BlackKingdom Ransomware ransomware
- BlackKingdom is a ransomware family that emerged in early 2020.
- BlackLotus exploit-kit
- BlackLotus is an advanced malware family known for its capability to bypass secure boot mechanisms and persist on a system through UEFI…
- BlackMagic ransomware
- BlackMagic is a ransomware that encrypts files on the infected system, demanding a ransom for decryption.
- BlackMatter (ELF) ransomware
- BlackMatter is a ransomware malware family that emerged in 2021, targeting various sectors including financial services, government, and…
- BlackMatter (Windows) ransomware
- According to PCrisk, BlackMatter is a piece of malicious software categorized as ransomware.
- BlackMist ransomware
- BlackMist is a ransomware malware known for encrypting files on victim machines and demanding a ransom for decryption keys.
- BlackMoon ransomware
- BlackMoon is a ransomware family known for targeting South Korean users, particularly within the financial services and telecommunications…
- BlackMould webshell
- BlackMould is a web shell based on China Chopper for servers running Microsoft IIS.
- BlackNET RAT botnetcredential-stealercryptominer
- Advanced and modern Windows botnet with PHP panel developed using VB.NET.
- BlackNix rat
- BlackNix RAT is a remote access tool coded in Delphi, designed to give attackers control over compromised systems.
- BlackNix RAT rat
- BlackNix RAT is a remote access tool used primarily for cyber-espionage.
- BlackPOS credential-stealer
- Also known as Kaptoxa, MMon, POSWDS. BlackPOS infects computers running on Windows that have credit card readers connected to them and are part of a POS system.
- BlackPink ransomware
- BlackPink is a ransomware strain that encrypts victim's files and demands a ransom for decryption.
- BlackRemote rat
- Also known as BlackRAT. BlackRemote, also known as BlackRAT, is a remote access tool used primarily for espionage activities.
- BlackRevolution rattrojan
- BlackRevolution is a sophisticated remote access trojan (RAT) used in cyber-espionage campaigns targeting government and technology sectors.
- BlackRose ransomware
- BlackRose is a ransomware known for encrypting files and demanding payment in cryptocurrency for their decryption.
- BlackRouter ransomware
- Also known as BLACKHEART. BlackRouter is a ransomware family known for encrypting files on infected systems and demanding a ransom for decryption.
- BlackShades rat
- BlackShades is a remote access trojan (RAT) that allows attackers to remotely control infected computers.
- BlackShades Crypter ransomware
- Also known as SilentShade, BlackShades. BlackShades Crypter, also known as SilentShade and BlackShades, is ransomware used to encrypt files, demanding a ransom for decryption keys.
- BlackSheep ransomware
- BlackSheep is a ransomware family known for encrypting files on victim machines and demanding a ransom for their decryption.
- BlackSoul trojan
- BlackSoul is a trojan malware known for executing unauthorized commands on infected systems.
- BlackSuit (ELF) ransomware
- According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.
- BlackSuit (Windows) ransomware
- According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.
- BlackSun ransomware
- BlackSun is a ransomware family known for encrypting victim's data and demanding payment for decryption.
- BlackWorm ransomware
- BlackWorm Ransomware is a malicious computer infection that encrypts your files, and then does everything it can to prevent you from…
- Blackout ransomware
- Blackout is a type of ransomware targeting multiple sectors by encrypting files and demanding ransom payments for decryption keys.