Malware Families page 60 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- mad liberator rat
- Group is also currently known as MADDLL32 and Metatron.
- magecart credential-stealertrojan
- Magecart is a malware framework intended to steal credit card information from compromised eCommerce websites.
- mailto ransomware
- Also known as Koko Ransomware, NetWalker. NetWalker, also known as Mailto or Koko Ransomware, is a ransomware family that has been employed in targeted attacks against various…
- malas backdoortrojan
- Malas is a sophisticated backdoor trojan used primarily for cyber espionage activities.
- malek team trojan
- Malek Team is known for cyber espionage activities primarily targeting government and energy sectors in the Middle East.
- malphas rat
- Malphas is a remote access trojan (RAT) used for cyber-espionage, primarily targeting financial services, government, and technology…
- mamona backdoor
- Mamona is a sophisticated malware family known for deploying backdoors to gain unauthorized access to targeted systems.
- mario esxi ransomware
- Mario ESXi is a ransomware family that targets VMware ESXi servers.
- mcafee
- The 'mcafee' entry lacks specific information and may be mistakenly listed or improperly named as a malware.
- mcrypt2019 ransomware
- Mcrypt2019 is a ransomware family identified in mid-2019.
- meek
- meek is an open-source Tor plugin that tunnels Tor traffic through HTTPS connections.
- megaMedusa ddos
- MegaMedusa is NodeJS DDoS Machine Layer-7 provided by RipperSec Team.
- meow
- metaMain backdoor
- metaMain is a backdoor used by Metador to maintain long-term access to compromised machines; it has also been used to decrypt Mafalda into…
- metaencryptor ransomware
- MetaEncryptor is a ransomware family known for encrypting files on infected systems and demanding a ransom payment for decryption keys.
- miga trojan
- The miga malware, associated with the slogan #MakeIsraelGreatAgain, is suspected to be politically motivated, primarily targeting…
- miliphen
- mim221 spywarecredential-stealer
- MIM221 is a sophisticated malware used primarily for espionage and credential theft.
- mimic backdoorkeylogger
- Mimic is a sophisticated backdoor malware known for its capabilities in cyber espionage.
- mimic-guram ransomware
- Mimic v.10 Ransomware-as-a-Service (RaaS).
- mindware trojanspyware
- Mindware is a sophisticated malware often associated with cyber espionage activities targeting sensitive data from various industries.
- miniBlindingCan ratdownloader
- Also known as AIRDRY.V2, EventHorizon. miniBlindingCan is an HTTP(S) orchestrator.
- miniRAT rat
- miniRAT is a Remote Access Trojan (RAT) used for gaining unauthorized remote access to targeted devices.
- miniTypeFrame rat
- miniTYPEFRAME is a variant of TYPEFRAME, a RAT for Windows.
- minteye
- mnt6
- mnt6 is a malware with limited public information.
- mogilevich
- Mogilevich is a malware entry in the MISP Galaxy database with no available description.
- money message ransomware
- Money Message is a ransomware family known for encrypting files and demanding payment for decryption.
- monolock ransomware
- Monolock is a ransomware family that encrypts victim files and demands a ransom.
- morpheus rattrojan
- Also known as HellCat. Morpheus, also known as HellCat, is a remote access trojan used by threat actors to conduct cyber-espionage activities.
- mortalkombat ransomware
- Mortalkombat is a ransomware variant first observed in early 2023.
- mountlocker ransomware
- MountLocker is a ransomware family known for encrypting victim data and demanding a ransom for decryption.
- mozart loader
- According to PCrisk, Mozart is malicious software that allows attackers (cyber criminals) to execute various commands on an infected…
- ms13-089 exploit-kit
- MS13-089 is a security vulnerability in Microsoft software that could allow remote code execution if a user views a specially crafted…
- muliaka
- The Muliaka malware currently lacks detailed public descriptions and specific information about its targets or capabilities.
- mydata
- The details on the 'mydata' malware are limited, and its specific operations and functionalities remain unclear.
- n1n1n1 ransomware
- N1N1N1 is a ransomware strain known for encrypting files and demanding a ransom payment in cryptocurrency.
- nRansom ransomware
- nRansom is a type of ransomware that locks the user's screen and demands payment in an unconventional manner.
- naga backdoor
- Naga is a backdoor malware known for its capabilities of remote access and control.
- nasir security
- Nasir Security is a malware entity with limited available information, making its specifics largely unknown in the threat landscape.
- nblock backdoor
- NBlock is known as a backdoor malware that provides unauthorized access to affected systems.
- nbtstat
- nbtstat is a utility used to troubleshoot NetBIOS name resolution.
- nccTrojan trojan
- nccTrojan is a type of trojan malware designed to perform various illicit activities on compromised systems.
- neshta virus
- Neshta is a 2005 Belarusian file infector virus written in Delphi.
- netrunner rat
- Netrunner is a sophisticated remote access tool utilized for cyber-espionage.
- netsh
- Also known as netsh.exe. netsh is a scripting utility used to interact with networking components on local or remote systems.
- netstat
- netstat is an operating system utility that displays active TCP connections, listening ports, and network statistics.
- ngrok
- ngrok is a legitimate reverse proxy tool that can create a secure tunnel to servers located behind firewalls or on local machines that do…
- nightspire rat
- Nightspire is a remote access trojan predominantly used for cyber espionage.
- nitlove credential-stealertrojan
- Nitlove is a credential-stealing trojan malware that primarily focuses on harvesting login information from infected systems.
- nitrogen backdoorransomware
- Nitrogen is a type of malware used for gaining unauthorized access and executing commands on targeted systems, often seen in cybercrime…
- njRAT rat
- Also known as Njw0rm, LV, Bladabindi. njRAT is a remote access tool (RAT) that was first observed in 2012.
- nmass malware rat
- Nmass malware is a Remote Access Trojan (RAT) built using .NET with a hardcoded encryption key.
- noescape ransomware
- NoEscape is a ransomware family that targets multiple industries, including financial services, government, and healthcare.
- noname
- Noname is a malware entity for which no specific information is currently available.
- nova ransomware
- Nova is a rebranded version of the RALord ransomware, targeting financial and government sectors, predominantly in the United States and…
- nullbulge
- A hacktivist group protecting artists' rights and ensuring fair compensation for their work.
- nvrmre botnettrojan
- nvrmre, also known as Lemon, is a sophisticated botnet malware targeting primarily financial services and technology sectors.
- oRAT rat
- SentinelOne describes this as a malware written in Go, mixing own custom code with code from public repositories.
- obscura backdoortrojan
- Obscura is a stealthy backdoor Trojan that provides remote access to compromised systems.
- obsidian orb
- oceans
- The oceans malware is a sophisticated and potentially modular threat with capabilities yet to be fully understood.
- octovillan trojanransomware
- Octovillan is a sophisticated piece of malware designed to target financial and governmental sectors.
- of Ransomware: OpenToYou (Formerly known as OpenToDecrypt) ransomware
- This ransomware is originated in English, therefore could be used worldwide.
- offwhite
- Offwhite is a lesser-known malware with limited information available.
- orca rat
- Orca is a sophisticated remote access Trojan (RAT) used primarily for cyber espionage.
- orion ransomware
- Jan13, 2026: We believe the group might be related to Babuk-Bjorka.
- osiris ransomware
- Osiris is a ransomware family known for encrypting files on victim machines and demanding ransom payments for decryption keys.
- ostap downloaderloader
- Ostap is a commodity JScript downloader first seen in campaigns in 2016.
- osyolorz collective rat
- Osyolorz Collective is a remote access trojan (RAT) utilized primarily for cyber-espionage.
- ox thief credential-stealer
- Ox Thief is an information-stealing malware primarily focused on harvesting credentials, often distributed through phishing campaigns.
- p0sT5n1F3r spywarewebshell
- According to Yarix digital security, this is a malware that allows to sniff on HTTPS traffic, implemented as Apache module.
- p0wnyshell webshell
- Also known as Ponyshell, Pownyshell. P0wnyshell is a webshell that allows attackers to execute arbitrary commands on a compromised web server.
- paladin rat
- Paladin RAT is a variant of Gh0st RAT used by PittyPanda active since at least 2011.
- paradise ransomware
- Paradise ransomware is known for encrypting files and demanding a ransom in exchange for the decryption key.
- paradise2 ransomware
- Paradise2 is a ransomware family used by cybercriminals to encrypt victim data and demand ransoms for decryption keys.
- parasite_http ratbackdoor
- Parasite_http is a remote access trojan (RAT) utilized primarily for cyber espionage purposes.
- payload
- The 'payload' malware lacks detailed description and specific behavioral characteristics, making it challenging to categorize precisely.
- payoutsking ransomware
- Payouts King Group. We are not RaaS. No affiliates are accepted. We use Tox messaging protocol.
- pbot botnetddos
- PBot is a peer-to-peer botnet derived from the Mirai source code.
- pcTattletale spyware
- According to TechCrunch, this is a remote surveillance app that allows ordinary consumers to buy software capable of tracking people and…
- pear ransomware
- ABOUT US: "Pure Extraction And Ransom (PEAR) Team is the community of highly responsible and strictly disciplined members.
- perfctl trojankeylogger
- Also known as perfcc. Perfctl, also known as perfcc, is a trojan malware that specifically targets government and financial sectors.
- pgift downloader
- Also known as ReRol. Information gathering and downloading tool used to deliver second stage malware to the infected system
- phalcon
- Phalcon is a malware with limited publicly available information, making it difficult to categorize its functions or targets at this time.
- phantom trojanrat
- Phantom is a remote access Trojan (RAT) known for targeting government, energy, and financial sectors.
- php.shin_webshell webshell
- A PHP webshell that allows file system management, data exfiltration and command execution.
- pipcreat trojandownloader
- Pipcreat is a malware designed to steal credentials and deliver further payloads, primarily targeting financial services and retail sectors.
- piratelock ransomware
- Piratelock is a ransomware family known for encrypting data and demanding ransom payments in cryptocurrency.
- play ransomware
- Also known as PlayCrypt. Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations…
- playboy
- No specific information is currently available about the 'playboy' malware.
- playwork trojanspyware
- Playwork is a sophisticated malware family primarily targeting government and financial services sectors in North America.
- ployx trojan
- Ployx is a trojan malware family primarily targeting the technology and financial services sectors.
- pngdowner downloader
- pngdowner is malware used by Putter Panda.
- polyvice rat
- Also known as Chily. PolyVice, also known as Chily, is a remote access trojan used primarily for cyber espionage.
- portless backdoorcredential-stealer
- Portless is a malware that lacks a typical port signature, complicating detection efforts.
- poscardstealer credential-stealer
- PosCardStealer is malware designed to extract payment card information from point-of-sale systems.
- poweRAT rat
- poweRAT is a remote access trojan (RAT) known for targeting financial services and government sectors.
- powerkatz credential-stealer
- PowerKatz is a PowerShell-based variant of Mimikatz used for extracting credentials.
- powershell_web_backdoor backdoorwebshell
- Powershell Web Backdoor is a malicious script designed to provide unauthorized remote access through a web interface.