Malware Families page 61 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

prb_backdoor backdoor
prb_backdoor is a type of backdoor malware often associated with cyberespionage activities.
prinz eugen ransomware
Prinz Eugen is a ransomware family known for encrypting files on compromised systems and demanding ransom payments for decryption keys.
proteus credential-stealertrojan
Proteus is a versatile malware family known for targeting financial services and government sectors.
providence ratbackdoor
Providence is a sophisticated remote access tool (RAT) observed in attacks against government and critical infrastructure sectors.
proxima ransomwaretrojan
Proxima is a sophisticated ransomware family known for targeting critical infrastructure sectors and financial services.
punisher ransomware
Punisher is a ransomware family known for targeting financial services and government sectors.
pupy (ELF) ratloader
Pupy is an open-source, cross-platform RAT and post-exploitation framework mainly written in python.
pupy (Python) rat
Pupy is an open-source, cross-platform remote administration tool (RAT) written in Python.
pupy (Windows) rat
Also known as Patpoopy. Pupy is an open-source, cross-platform RAT and post-exploitation framework mainly written in python.
purpleink backdoorrat
PurpleInk is a remote access trojan (RAT) known for its capabilities to establish backdoor access to compromised systems.
puzzlemaker dropperrat
The dropper module is used to install two executables that pretend to be legitimate files belonging to Microsoft Windows OS.
pwdump credential-stealer
pwdump is a credential dumper designed to extract password hashes from Windows systems.
pwnpos
PwnPOS is a point-of-sale malware designed to capture and exfiltrate credit card data from infected systems.
pyback backdoor
PyBack is a Python-based backdoor that is typically used for remote access and control.
pyrx trojanbackdoor
Pyrx is a Trojan and backdoor malware that primarily targets sectors such as technology, financial services, and government.
qilin-securotrop ratbackdoor
Qilin-Securotrop is a sophisticated remote access Trojan (RAT) used primarily for cyber espionage, targeting government and defense sectors.
qiulong backdoortrojan
Qiulong is an advanced persistent threat primarily used for cyber espionage, targeting critical sectors like government and energy globally.
qkG ransomware
Security researchers have discovered a new ransomware strain named qkG that targets only Office documents for encryption and infects the…
quicklock ransomware
Quicklock is a ransomware family known for encrypting data on victim systems, typically targeting sectors like government, energy, and…
quoter
Quoter is a malware with limited publicly available information, making it challenging to specify its behavior or targets.
r2r2
R2r2 is a lesser-known malware with limited available information and is unlikely to be widely recognized as a distinct family or variant.
r77 rootkit
Also known as r77 Rootkit. According to the author, r77 is a ring 3 rootkit that hides everything: * Files, directories * Processes & CPU usage * Registry keys &…
ra group ransomware
The RA Group is a cybercriminal organization known for deploying ransomware attacks targeting various industries.
rabbit hole
No detailed information is available for this malware, and it lacks a standard identification description.
radar spyware
Radar is a type of spyware known for its usage in surveillance activities.
radiant group ratspyware
Radiant Group is a sophisticated cyber-espionage group known for targeting government and technology sectors.
ralord ransomware
Ralord is a ransomware known for targeting various sectors, predominantly healthcare and financial services.
rancoz ransomwaretrojan
Rancoz is a ransomware family that first emerged in mid-2020, mainly targeting government and financial sectors.
ranion ransomware
Ranion is a ransomware as a service (RaaS) platform that allows cybercriminals to lease ransomware to execute attacks on various targets.
ransom corp ransomware
Ransom Corp is a notorious ransomware family that targets multiple sectors, focusing on financial and critical infrastructure.
ransombay ransomware
Ransombay is a ransomware targeting various industries, particularly in India and the US.
ransomcortex ransomware
Ransomcortex is a ransomware family that encrypts victims' data and demands payment for decryption.
ransomed ransomware
Ransomed is a ransomware type malware that encrypts files on the victim's system, demanding a ransom for decryption.
ransomedvc2 ransomware
RansomedVC2 aka RebornVC aka RansomedVC (rebrand) under new leadership.
ransomware blog ransomware
Ransomware Blog, also known as MedusaLocker, is a notorious ransomware that emerged in late 2019.
rapture rat
Rapture is a sophisticated remote access tool (RAT) often used in cyber espionage campaigns.
rarstar ransomware
This ransomware encrypts all user’s data on the PC (photos, documents, excel tables, music, videos, etc), adds its specific extension to…
rat_hodin rat
Rat_hodin is a remote access trojan used for cyber espionage, predominantly targeting government and critical infrastructure sectors.
raznatovic trojanrat
Raznatovic is a remote access trojan (RAT) used primarily for cyber espionage.
rbs_srv trojan
rbs_srv is a banking trojan primarily targeting financial institutions in North America.
rdasrv rat
rdasrv is a remote access trojan designed to stealthily infiltrate systems for surveillance and data exfiltration.
reGeorg webshell
reGeorg is an open-source web shell written in Python that can be used as a proxy to bypass firewall rules and tunnel data in and out of…
red ransomware ransomware
Red ransomware is known for encrypting files on victim systems and demanding a ransom for decryption keys.
redact
reynolds trojan
Reynolds is a piece of malware with insufficient public documentation.
rhysida ransomware
Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023.
risen ransomware
Risen, which is a fully optimized and high-speed program, is the result of our years of experience in the field of malware writing.
robbing hood ransomware
Robbing Hood is a ransomware family that targets financial services and government sectors.
rock ransomware
Also known as yellowalbatross. Rock, also known as YellowAlbatross, is a ransomware family targeting mainly government, financial, and tech sectors in the US, UK, and…
root rootkit
The 'root' malware is a type of rootkit often used to gain unauthorized access and maintain stealthy control over a compromised system.
route
route can be used to find or change information within the local system IP routing table.
rtm locker ransomware
Also known as Read The Manual Locker. RTM Locker, also known as Read The Manual Locker, is a ransomware family that encrypts files on infected systems, demanding a ransom…
rtpos
RTPOS is a type of point-of-sale malware designed to steal payment card data from infected systems.
run some wares
The malware 'run some wares' currently has no detailed description available, indicating limited public knowledge about its functionality…
rustylocker ransomware
RustyLocker is a ransomware family that encrypts files on compromised systems, often targeting government, financial services, and…
s1ngularity Stealer credential-stealer
According to StepSecurity, this is a stealer deployed through a compromised Nx package, targeting system environment properties…
sLoad downloaderscreen-capture
Also known as Starslord. sLoad is a PowerShell downloader that most frequently delivers Ramnit banker and includes noteworthy reconnaissance features.
sRDI loader
Also known as DAVESHELL. sRDI allows for the conversion of DLL files to position independent shellcode.
safepay ransomware
SafePay ransomware started in October 2024 as a new ransomware service, using some of the leaked LockBit source code.
sarcoma ransomware
Also known as Sarcoma Ransomware Group. Sarcoma is a ransomware group that emerged in October 2024 and has been actively targeting various organizations.
satancd ransomware
Satancd is a ransomware family known for encrypting files on victims' systems to extort payments.
satanlock ransomware
Connected to GD Lockersec and Babuk-Bjorka.
scanbox exploit-kit
ScanBox is a reconnaissance and exploitation framework used in watering hole attacks, often targeting media and government sectors.
scattered lapsus$ hunters ransomwarecredential-stealer
Scattered LAPSUS$ is a ransomware and credential-stealer campaign that has targeted a diverse range of industries, primarily focusing on…
schoolboys trojan
Schoolboys is a relatively obscure malware often associated with low-level cyberattacks targeting the education sector.
schtasks
Also known as schtasks.exe. schtasks is used to schedule execution of programs or scripts on a Windows system to run at a specific date and time.
secp0 ransomware
Secp0 is a ransomware that encrypts files on infected systems, demanding a ransom payment for decryption.
securotrop trojanbackdoor
Securotrop is an advanced malware family known for targeting government and financial sectors.
sedexp backdoorspyware
sedexp is a sophisticated backdoor and spyware tool used primarily in cyber-espionage campaigns.
seinup trojan
Seinup is a financial trojan known to target banking institutions.
sensayq trojan
Sensayq is a type of trojan malware that has been observed in various cybercrime activities.
settra
sevyware
shadow trojan
Shadow is a stealthy malware that operates primarily as a trojan.
shadowbyt3$ trojanspyware
Shadowbyt3$ is a sophisticated malware family often used in cyber espionage.
shadowhammer backdoor
Also known as DAYJOB. ShadowHammer is a targeted attack campaign that compromised a popular software update mechanism to distribute malware.
shareip ratbackdoor
Also known as remotecmd. Shareip, also known as remotecmd, is a remote access tool used by threat actors to gain unauthorized access to systems.
sharpboys
This malware is known as sharpboys. Further details about its behavior, targets, and capabilities are currently unavailable.
shinyhunters credential-stealer
ShinyHunters is a cybercriminal group known for breaching and selling databases from various industries including technology, retail, and…
sicari ratbackdoor
Sicari is a remote access trojan (RAT) known to target government and financial sectors, primarily in the United States and the United…
siegedsec ransomware
SiegedSec is a ransomware group known for targeting educational institutions and government sectors.
sihost trojan
sihost is a Trojan malware that has been identified as part of a larger malware family.
silent
Silent is a malware with limited public information.
silent ransom ransomware
Silent Ransom is a ransomware family known for encrypting victims' files and demanding payment for decryption keys.
sinobi backdoorrat
Sinobi is a remote access trojan primarily targeting governmental and military organizations in Japan.
skip-2.0 backdoor
Skip-2.0 is a backdoor specifically designed to target Microsoft SQL Server, allowing attackers to bypass standard security measures and…
skira team ratbackdoor
Skira Team is a threat actor group known for using Remote Access Trojans to target government, financial, and tech sectors.
skyrat rat
Skyrat is a remote access trojan often associated with advanced persistent threat (APT) groups.
slam ransomware
Slam is a ransomware family known for encrypting files on compromised systems and demanding a ransom for decryption.
slnrat rat
SLNRat is a remote access tool (RAT) used by cybercriminals to gain unauthorized access to infected systems.
slug rat
Slug is a remote access trojan (RAT) known for targeting specific sectors such as government and financial services.
smac ratbackdoor
Also known as speccom. SMAC, also known as Speccom, is a remote access Trojan (RAT) used primarily for cyber espionage.
solarmarker backdoorcredential-stealertrojan
Also known as Jupyter, Polazert, Yellow Cockatoo. Unit 42 notes that they identified a new version of SolarMarker, a malware family known for its infostealing and backdoor capabilities…
soleenya ratspyware
Soleenya is a remote access tool (RAT) often leveraged for cyber espionage.
soraya credential-stealer
Soraya is a malware designed to scrape memory for payment card data on point-of-sale systems.
space bears ratspyware
Space Bears is an advanced persistent threat (APT) malware family known for espionage operations targeting critical infrastructure sectors.
spirigatito
Spirigatito is a malware entity with unidentified characteristics due to limited available information.
splitloader downloaderloader
Splitloader is a malware family used primarily as a downloader and loader for other malicious payloads.
spring
No description available.
spwebmember spyware
spwebmember is a Microsoft SharePoint enumeration and data dumping tool written in .NET.