Malware Families page 6 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

BeaverTail (Javascript) loaderspywaretrojan
BeaverTail is a JavaScript malware primarily distributed through NPM packages.
BeaverTail (OS X) rat
BeaverTail is a remote access tool (RAT) that targets OS X systems.
Bedep loaderbotnet
Bedep has been mostly observed in ad-fraud campaigns, although it can also generally load modules for different tasks.
Bee rat
Malware family observed in conjunction with PlugX infrastructure in 2013.
BeepService loadertrojan
BeepService is a malicious software tool designed to facilitate the loading of other payloads and perform unauthorized actions on infected…
BeethoveN ransomware
BeethoveN is a ransomware strain known for encrypting files on affected systems and demanding a ransom for recovery.
Behinder webshell
A webshell for multiple web languages (asp/aspx, jsp/jspx, php), openly distributed through Github.
Bella rat
Bella is a remote access trojan known for its capability to execute commands, capture screenshots, and exfiltrate sensitive data.
BellaCiao rat
BellaCiao is a remote access trojan (RAT) observed in 2023.
Belonard trojan
Once set up in the system, Trojan.Belonard replaces the list of available game servers in the game client and creates proxies on the…
BendyBear downloaderloader
BendyBear is an x64 shellcode for a stage-zero implant designed to download malware from a C2 server.
Berbew backdoor
Berbew, also known as Padodor, is a backdoor Trojan that installs itself on a system to enable remote access by an attacker.
Berbomthum rat
Berbomthum is a remote access trojan primarily used in cyber espionage campaigns targeting government entities.
BernhardPOS trojan
BernhardPOS is a point-of-sale malware that targets credit card data typically used in the retail and hospitality industries.
Berserk Stealer credential-stealer
Berserk Stealer is a credential-stealing malware family used to exfiltrate sensitive information such as login credentials from infected…
Best Crypt ransomware
Best Crypt is a ransomware program known for encrypting files on infected systems and demanding a ransom in cryptocurrency for decryption.
BestChangeRu ransomware
BestChangeRu is a type of ransomware that targets financial and technology sectors.
BestKorea trojanbackdoor
BestKorea is a state-sponsored malware linked to North Korean threat actors, primarily used for cyber-espionage against government and…
BetaBot credential-stealertrojanspyware
Also known as Neurevt. Cybereason concludes that Betabot is a sophisticated infostealer malware that’s evolved significantly since it first appeared in late 2012.
Bezigate backdoortrojan
Bezigate is a Trojan horse that opens a back door on the compromised computer.
BfBot botnetcredential-stealer
BfBot is a type of botnet malware primarily used to perform credential-stealing operations.
BiBi wiper
Also known as BiBi-Windows. A Windows version of the BiBi wiper that was found by BlackBerry.
BiBi-Linux wiper
According to Security Joes, this malware is an x64 ELF executable, lacking obfuscation or protective measures.
BianLian (Android) trojancredential-stealer
Also known as Hydra. BianLian is an Android banking trojan known for targeting financial institutions by stealing user credentials.
BianLian (ELF) ransomware
BianLian is a ransomware family known for encrypting files on compromised systems.
BianLian (Windows) ransomware
BianLian is a GoLang-based ransomware that continues to breach several industries and demand large ransom amounts.
Bianlian ransomware
Also known as Hydra. BianLian used subtle techniques to exploit, enumerate, and move laterally in victim networks to remain undetected and aggressively worked…
Bifrost backdoorrat
Also known as elf.bifrose. Linux version of the bifrose malware that originally targeted Windows platform only.
BigBobRoss ransomware
BigBobRoss ransomware is the cryptovirus that requires a ransom in Bitcoin to return encrypted files marked with .obfuscated appendix.
BigBossHorse ransomware
BigBossHorse is a ransomware family known for encrypting files and demanding a ransom payment.
BigViktor botnetddos
A DDoS bot abusing CVE-2020-8515 to target DrayTek Vigor routers.
Biglock ransomware
Biglock is a ransomware family known for encrypting victim data and demanding payment for the decryption key.
BillGates botnetddosbackdoor
BillGates is a modularized malware, of supposedly Chinese origin.
Binanen dropperspyware
Binanen is a dropper that drops and executes a section of itself into a hidden dummy process.
Binary Validator dropperspyware
Binary Validator is a Mach-O binary file used during Operation Triangulation.
BingoMod downloaderspyware
BingoMod is a malware family known for its capabilities in downloading and executing additional payloads and conducting espionage…
BioData spyware
BioData is a spyware family targeting the healthcare and public sector industries.
BioSet ransomware
BioSet is a sophisticated ransomware family known for targeting sectors like healthcare, government, and technology industries.
Biodox wiper
Biodox is a wiper malware typically used in espionage campaigns targeting the healthcare and governmental sectors.
Birbware ransomware
Ransomware
Bisonal rat
Bisonal is a remote access tool (RAT) that has been used by Tonto Team against public and private sector organizations in Russia, South…
BitCrypt ransomware
BitCrypt is a type of ransomware that encrypts files on the infected machine and demands a ransom for the decryption key.
BitCrypt 2.0 ransomware
BitCrypt 2.0 is a ransomware variant known for encrypting victims' files and demanding bitcoin as ransom.
BitCryptor ransomware
Ransomware Has a GUI. CryptoGraphic Locker family. Newer CoinVault variant.
BitKangoroo ransomware
BitKangoroo is a ransomware family that encrypts user data and demands a ransom for decryption keys.
BitPaymer ransomware
Also known as wp_encrypt, FriedEx, IEncrypt. BitPaymer is a ransomware variant first observed in August 2017 targeting hospitals in the U.K.
BitPyLock ransomware
BitPyLock is a ransomware known for encrypting files on infected systems and demanding a ransom payment in cryptocurrency.
BitRAT ratcredential-stealercryptominer
According to Bitdefender, BitRAT is a notorious remote access trojan (RAT) marketed on underground cybercriminal web markets and forums.
BitRansomware ransomware
BitRansomware is a type of ransomware designed to encrypt files on infected systems and demand a ransom for decryption.
BitStak ransomware
BitStak is a type of ransomware known for encrypting files on infected systems and demanding a ransom for their release.
Bitshifter ransomware
Bitshifter is a type of ransomware that encrypts victim data and demands ransom in exchange for decryption keys.
Bitsran dropperransomware
Also known as SHADYCAT. SHADYCAT is a dropper and spreader component for the HERMES 2.1 RANSOMWARE radical edition.
Bitter RAT rat
Bitter RAT is a remote access trojan primarily focused on cyber espionage.
BizHack ransomware
BizHack is a type of ransomware known for encrypting victims' files and demanding payment for the decryption key.
Bizzaro trojancredential-stealer
Kaspersky Labs characterizes Bizarro as yet another banking Trojan family originating from Brazil that is now found in other regions of…
Black Basta ransomware
Black Basta is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022…
Black Basta (ELF) ransomware
ESXi encrypting ransomware, using a combination of the stream cipher ChaCha20 and RSA.
Black Basta (Windows) ransomware
Also known as no_name_software. "Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their…
Black Feather ransomware
Black Feather is a type of ransomware used by cybercriminals to encrypt files and demand payment for their decryption.
Black Ruby ransomwarecryptominer
Also known as BlackRuby. A new ransomware was discovered this week by MalwareHunterTeam called Black Ruby.
Black Worm ransomware
Black Worm is a ransomware strain known for encrypting files and demanding a ransom for their decryption.
Black claw ransomware
Black Claw is a ransomware family that encrypts victim systems, demanding a ransom for decryption.
BlackBasta ransomware
Black Basta is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their…
BlackByte ransomwareworm
BlackByte is recently discovered Ransomware with a .NET DLL core payload wrapped in JavaScript.
BlackByte 2.0 Ransomware ransomware
BlackByte 2.0 Ransomware is a replacement for BlackByte Ransomware.
BlackByte Ransomware ransomware
BlackByte Ransomware is uniquely associated with BlackByte operations.
BlackCat ransomware
Also known as ALPHV, Noberus. BlackCat is ransomware written in Rust that has been offered via the Ransomware-as-a-Service (RaaS) model.
BlackEnergy botnetddostrojan
Also known as Black Energy. BlackEnergy is a malware toolkit that has been used by both criminal and APT actors.
BlackEnergy 3
BlackEnergy 3 is a malware toolkit that has been used by both criminal and APT actors.
BlackFireEye ransomware
BlackFireEye is a ransomware strain known for encrypting files on infected systems and demanding a ransom for decryption.
BlackGuard credential-stealerspyware
According to Zscaler, BlackGuard has the capability to steal all types of information related to Crypto wallets, VPN, Messengers, FTP…
BlackHat-Mehtihack ransomware
BlackHat-Mehtihack is a type of ransomware targeting various industries.
BlackHole rat
C# RAT (Remote Adminitration Tool) - Educational purposes only
BlackKingdom ransomware
BlackKingdom is a ransomware strain used in cybercrime operations.
BlackKingdom Ransomware ransomware
BlackKingdom is a ransomware family that emerged in early 2020.
BlackLotus exploit-kit
BlackLotus is an advanced malware family known for its capability to bypass secure boot mechanisms and persist on a system through UEFI…
BlackMagic ransomware
BlackMagic is a ransomware that encrypts files on the infected system, demanding a ransom for decryption.
BlackMatter (ELF) ransomware
BlackMatter is a ransomware malware family that emerged in 2021, targeting various sectors including financial services, government, and…
BlackMatter (Windows) ransomware
According to PCrisk, BlackMatter is a piece of malicious software categorized as ransomware.
BlackMist ransomware
BlackMist is a ransomware malware known for encrypting files on victim machines and demanding a ransom for decryption keys.
BlackMoon ransomware
BlackMoon is a ransomware family known for targeting South Korean users, particularly within the financial services and telecommunications…
BlackMould webshell
BlackMould is a web shell based on China Chopper for servers running Microsoft IIS.
BlackNET RAT botnetcredential-stealercryptominer
Advanced and modern Windows botnet with PHP panel developed using VB.NET.
BlackNix rat
BlackNix RAT is a remote access tool coded in Delphi, designed to give attackers control over compromised systems.
BlackNix RAT rat
BlackNix RAT is a remote access tool used primarily for cyber-espionage.
BlackPOS credential-stealer
Also known as Kaptoxa, MMon, POSWDS. BlackPOS infects computers running on Windows that have credit card readers connected to them and are part of a POS system.
BlackPink ransomware
BlackPink is a ransomware strain that encrypts victim's files and demands a ransom for decryption.
BlackRemote rat
Also known as BlackRAT. BlackRemote, also known as BlackRAT, is a remote access tool used primarily for espionage activities.
BlackRevolution rattrojan
BlackRevolution is a sophisticated remote access trojan (RAT) used in cyber-espionage campaigns targeting government and technology sectors.
BlackRose ransomware
BlackRose is a ransomware known for encrypting files and demanding payment in cryptocurrency for their decryption.
BlackRouter ransomware
Also known as BLACKHEART. BlackRouter is a ransomware family known for encrypting files on infected systems and demanding a ransom for decryption.
BlackShades rat
BlackShades is a remote access trojan (RAT) that allows attackers to remotely control infected computers.
BlackShades Crypter ransomware
Also known as SilentShade, BlackShades. BlackShades Crypter, also known as SilentShade and BlackShades, is ransomware used to encrypt files, demanding a ransom for decryption keys.
BlackSheep ransomware
BlackSheep is a ransomware family known for encrypting files on victim machines and demanding a ransom for their decryption.
BlackSoul trojan
BlackSoul is a trojan malware known for executing unauthorized commands on infected systems.
BlackSuit (ELF) ransomware
According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.
BlackSuit (Windows) ransomware
According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.
BlackSun ransomware
BlackSun is a ransomware family known for encrypting victim's data and demanding payment for decryption.
BlackWorm ransomware
BlackWorm Ransomware is a malicious computer infection that encrypts your files, and then does everything it can to prevent you from…
Blackout ransomware
Blackout is a type of ransomware targeting multiple sectors by encrypting files and demanding ransom payments for decryption keys.