Malware Families page 60 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

mad liberator rat
Group is also currently known as MADDLL32 and Metatron.
magecart credential-stealertrojan
Magecart is a malware framework intended to steal credit card information from compromised eCommerce websites.
mailto ransomware
Also known as Koko Ransomware, NetWalker. NetWalker, also known as Mailto or Koko Ransomware, is a ransomware family that has been employed in targeted attacks against various…
malas backdoortrojan
Malas is a sophisticated backdoor trojan used primarily for cyber espionage activities.
malek team trojan
Malek Team is known for cyber espionage activities primarily targeting government and energy sectors in the Middle East.
malphas rat
Malphas is a remote access trojan (RAT) used for cyber-espionage, primarily targeting financial services, government, and technology…
mamona backdoor
Mamona is a sophisticated malware family known for deploying backdoors to gain unauthorized access to targeted systems.
mario esxi ransomware
Mario ESXi is a ransomware family that targets VMware ESXi servers.
mcafee
The 'mcafee' entry lacks specific information and may be mistakenly listed or improperly named as a malware.
mcrypt2019 ransomware
Mcrypt2019 is a ransomware family identified in mid-2019.
meek
meek is an open-source Tor plugin that tunnels Tor traffic through HTTPS connections.
megaMedusa ddos
MegaMedusa is NodeJS DDoS Machine Layer-7 provided by RipperSec Team.
meow
metaMain backdoor
metaMain is a backdoor used by Metador to maintain long-term access to compromised machines; it has also been used to decrypt Mafalda into…
metaencryptor ransomware
MetaEncryptor is a ransomware family known for encrypting files on infected systems and demanding a ransom payment for decryption keys.
miga trojan
The miga malware, associated with the slogan #MakeIsraelGreatAgain, is suspected to be politically motivated, primarily targeting…
miliphen
mim221 spywarecredential-stealer
MIM221 is a sophisticated malware used primarily for espionage and credential theft.
mimic backdoorkeylogger
Mimic is a sophisticated backdoor malware known for its capabilities in cyber espionage.
mimic-guram ransomware
Mimic v.10 Ransomware-as-a-Service (RaaS).
mindware trojanspyware
Mindware is a sophisticated malware often associated with cyber espionage activities targeting sensitive data from various industries.
miniBlindingCan ratdownloader
Also known as AIRDRY.V2, EventHorizon. miniBlindingCan is an HTTP(S) orchestrator.
miniRAT rat
miniRAT is a Remote Access Trojan (RAT) used for gaining unauthorized remote access to targeted devices.
miniTypeFrame rat
miniTYPEFRAME is a variant of TYPEFRAME, a RAT for Windows.
minteye
mnt6
mnt6 is a malware with limited public information.
mogilevich
Mogilevich is a malware entry in the MISP Galaxy database with no available description.
money message ransomware
Money Message is a ransomware family known for encrypting files and demanding payment for decryption.
monolock ransomware
Monolock is a ransomware family that encrypts victim files and demands a ransom.
morpheus rattrojan
Also known as HellCat. Morpheus, also known as HellCat, is a remote access trojan used by threat actors to conduct cyber-espionage activities.
mortalkombat ransomware
Mortalkombat is a ransomware variant first observed in early 2023.
mountlocker ransomware
MountLocker is a ransomware family known for encrypting victim data and demanding a ransom for decryption.
mozart loader
According to PCrisk, Mozart is malicious software that allows attackers (cyber criminals) to execute various commands on an infected…
ms13-089 exploit-kit
MS13-089 is a security vulnerability in Microsoft software that could allow remote code execution if a user views a specially crafted…
muliaka
The Muliaka malware currently lacks detailed public descriptions and specific information about its targets or capabilities.
mydata
The details on the 'mydata' malware are limited, and its specific operations and functionalities remain unclear.
n1n1n1 ransomware
N1N1N1 is a ransomware strain known for encrypting files and demanding a ransom payment in cryptocurrency.
nRansom ransomware
nRansom is a type of ransomware that locks the user's screen and demands payment in an unconventional manner.
naga backdoor
Naga is a backdoor malware known for its capabilities of remote access and control.
nasir security
Nasir Security is a malware entity with limited available information, making its specifics largely unknown in the threat landscape.
nblock backdoor
NBlock is known as a backdoor malware that provides unauthorized access to affected systems.
nbtstat
nbtstat is a utility used to troubleshoot NetBIOS name resolution.
nccTrojan trojan
nccTrojan is a type of trojan malware designed to perform various illicit activities on compromised systems.
neshta virus
Neshta is a 2005 Belarusian file infector virus written in Delphi.
netrunner rat
Netrunner is a sophisticated remote access tool utilized for cyber-espionage.
netsh
Also known as netsh.exe. netsh is a scripting utility used to interact with networking components on local or remote systems.
netstat
netstat is an operating system utility that displays active TCP connections, listening ports, and network statistics.
ngrok
ngrok is a legitimate reverse proxy tool that can create a secure tunnel to servers located behind firewalls or on local machines that do…
nightspire rat
Nightspire is a remote access trojan predominantly used for cyber espionage.
nitlove credential-stealertrojan
Nitlove is a credential-stealing trojan malware that primarily focuses on harvesting login information from infected systems.
nitrogen backdoorransomware
Nitrogen is a type of malware used for gaining unauthorized access and executing commands on targeted systems, often seen in cybercrime…
njRAT rat
Also known as Njw0rm, LV, Bladabindi. njRAT is a remote access tool (RAT) that was first observed in 2012.
nmass malware rat
Nmass malware is a Remote Access Trojan (RAT) built using .NET with a hardcoded encryption key.
noescape ransomware
NoEscape is a ransomware family that targets multiple industries, including financial services, government, and healthcare.
noname
Noname is a malware entity for which no specific information is currently available.
nova ransomware
Nova is a rebranded version of the RALord ransomware, targeting financial and government sectors, predominantly in the United States and…
nullbulge
A hacktivist group protecting artists' rights and ensuring fair compensation for their work.
nvrmre botnettrojan
nvrmre, also known as Lemon, is a sophisticated botnet malware targeting primarily financial services and technology sectors.
oRAT rat
SentinelOne describes this as a malware written in Go, mixing own custom code with code from public repositories.
obscura backdoortrojan
Obscura is a stealthy backdoor Trojan that provides remote access to compromised systems.
obsidian orb
oceans
The oceans malware is a sophisticated and potentially modular threat with capabilities yet to be fully understood.
octovillan trojanransomware
Octovillan is a sophisticated piece of malware designed to target financial and governmental sectors.
of Ransomware: OpenToYou (Formerly known as OpenToDecrypt) ransomware
This ransomware is originated in English, therefore could be used worldwide.
offwhite
Offwhite is a lesser-known malware with limited information available.
orca rat
Orca is a sophisticated remote access Trojan (RAT) used primarily for cyber espionage.
orion ransomware
Jan13, 2026: We believe the group might be related to Babuk-Bjorka.
osiris ransomware
Osiris is a ransomware family known for encrypting files on victim machines and demanding ransom payments for decryption keys.
ostap downloaderloader
Ostap is a commodity JScript downloader first seen in campaigns in 2016.
osyolorz collective rat
Osyolorz Collective is a remote access trojan (RAT) utilized primarily for cyber-espionage.
ox thief credential-stealer
Ox Thief is an information-stealing malware primarily focused on harvesting credentials, often distributed through phishing campaigns.
p0sT5n1F3r spywarewebshell
According to Yarix digital security, this is a malware that allows to sniff on HTTPS traffic, implemented as Apache module.
p0wnyshell webshell
Also known as Ponyshell, Pownyshell. P0wnyshell is a webshell that allows attackers to execute arbitrary commands on a compromised web server.
paladin rat
Paladin RAT is a variant of Gh0st RAT used by PittyPanda active since at least 2011.
paradise ransomware
Paradise ransomware is known for encrypting files and demanding a ransom in exchange for the decryption key.
paradise2 ransomware
Paradise2 is a ransomware family used by cybercriminals to encrypt victim data and demand ransoms for decryption keys.
parasite_http ratbackdoor
Parasite_http is a remote access trojan (RAT) utilized primarily for cyber espionage purposes.
payload
The 'payload' malware lacks detailed description and specific behavioral characteristics, making it challenging to categorize precisely.
payoutsking ransomware
Payouts King Group. We are not RaaS. No affiliates are accepted. We use Tox messaging protocol.
pbot botnetddos
PBot is a peer-to-peer botnet derived from the Mirai source code.
pcTattletale spyware
According to TechCrunch, this is a remote surveillance app that allows ordinary consumers to buy software capable of tracking people and…
pear ransomware
ABOUT US: "Pure Extraction And Ransom (PEAR) Team is the community of highly responsible and strictly disciplined members.
perfctl trojankeylogger
Also known as perfcc. Perfctl, also known as perfcc, is a trojan malware that specifically targets government and financial sectors.
pgift downloader
Also known as ReRol. Information gathering and downloading tool used to deliver second stage malware to the infected system
phalcon
Phalcon is a malware with limited publicly available information, making it difficult to categorize its functions or targets at this time.
phantom trojanrat
Phantom is a remote access Trojan (RAT) known for targeting government, energy, and financial sectors.
php.shin_webshell webshell
A PHP webshell that allows file system management, data exfiltration and command execution.
pipcreat trojandownloader
Pipcreat is a malware designed to steal credentials and deliver further payloads, primarily targeting financial services and retail sectors.
piratelock ransomware
Piratelock is a ransomware family known for encrypting data and demanding ransom payments in cryptocurrency.
play ransomware
Also known as PlayCrypt. Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations…
playboy
No specific information is currently available about the 'playboy' malware.
playwork trojanspyware
Playwork is a sophisticated malware family primarily targeting government and financial services sectors in North America.
ployx trojan
Ployx is a trojan malware family primarily targeting the technology and financial services sectors.
pngdowner downloader
pngdowner is malware used by Putter Panda.
polyvice rat
Also known as Chily. PolyVice, also known as Chily, is a remote access trojan used primarily for cyber espionage.
portless backdoorcredential-stealer
Portless is a malware that lacks a typical port signature, complicating detection efforts.
poscardstealer credential-stealer
PosCardStealer is malware designed to extract payment card information from point-of-sale systems.
poweRAT rat
poweRAT is a remote access trojan (RAT) known for targeting financial services and government sectors.
powerkatz credential-stealer
PowerKatz is a PowerShell-based variant of Mimikatz used for extracting credentials.
powershell_web_backdoor backdoorwebshell
Powershell Web Backdoor is a malicious script designed to provide unauthorized remote access through a web interface.