Malware Families page 61 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- prb_backdoor backdoor
- prb_backdoor is a type of backdoor malware often associated with cyberespionage activities.
- prinz eugen ransomware
- Prinz Eugen is a ransomware family known for encrypting files on compromised systems and demanding ransom payments for decryption keys.
- proteus credential-stealertrojan
- Proteus is a versatile malware family known for targeting financial services and government sectors.
- providence ratbackdoor
- Providence is a sophisticated remote access tool (RAT) observed in attacks against government and critical infrastructure sectors.
- proxima ransomwaretrojan
- Proxima is a sophisticated ransomware family known for targeting critical infrastructure sectors and financial services.
- punisher ransomware
- Punisher is a ransomware family known for targeting financial services and government sectors.
- pupy (ELF) ratloader
- Pupy is an open-source, cross-platform RAT and post-exploitation framework mainly written in python.
- pupy (Python) rat
- Pupy is an open-source, cross-platform remote administration tool (RAT) written in Python.
- pupy (Windows) rat
- Also known as Patpoopy. Pupy is an open-source, cross-platform RAT and post-exploitation framework mainly written in python.
- purpleink backdoorrat
- PurpleInk is a remote access trojan (RAT) known for its capabilities to establish backdoor access to compromised systems.
- puzzlemaker dropperrat
- The dropper module is used to install two executables that pretend to be legitimate files belonging to Microsoft Windows OS.
- pwdump credential-stealer
- pwdump is a credential dumper designed to extract password hashes from Windows systems.
- pwnpos
- PwnPOS is a point-of-sale malware designed to capture and exfiltrate credit card data from infected systems.
- pyback backdoor
- PyBack is a Python-based backdoor that is typically used for remote access and control.
- pyrx trojanbackdoor
- Pyrx is a Trojan and backdoor malware that primarily targets sectors such as technology, financial services, and government.
- qilin-securotrop ratbackdoor
- Qilin-Securotrop is a sophisticated remote access Trojan (RAT) used primarily for cyber espionage, targeting government and defense sectors.
- qiulong backdoortrojan
- Qiulong is an advanced persistent threat primarily used for cyber espionage, targeting critical sectors like government and energy globally.
- qkG ransomware
- Security researchers have discovered a new ransomware strain named qkG that targets only Office documents for encryption and infects the…
- quicklock ransomware
- Quicklock is a ransomware family known for encrypting data on victim systems, typically targeting sectors like government, energy, and…
- quoter
- Quoter is a malware with limited publicly available information, making it challenging to specify its behavior or targets.
- r2r2
- R2r2 is a lesser-known malware with limited available information and is unlikely to be widely recognized as a distinct family or variant.
- r77 rootkit
- Also known as r77 Rootkit. According to the author, r77 is a ring 3 rootkit that hides everything: * Files, directories * Processes & CPU usage * Registry keys &…
- ra group ransomware
- The RA Group is a cybercriminal organization known for deploying ransomware attacks targeting various industries.
- rabbit hole
- No detailed information is available for this malware, and it lacks a standard identification description.
- radar spyware
- Radar is a type of spyware known for its usage in surveillance activities.
- radiant group ratspyware
- Radiant Group is a sophisticated cyber-espionage group known for targeting government and technology sectors.
- ralord ransomware
- Ralord is a ransomware known for targeting various sectors, predominantly healthcare and financial services.
- rancoz ransomwaretrojan
- Rancoz is a ransomware family that first emerged in mid-2020, mainly targeting government and financial sectors.
- ranion ransomware
- Ranion is a ransomware as a service (RaaS) platform that allows cybercriminals to lease ransomware to execute attacks on various targets.
- ransom corp ransomware
- Ransom Corp is a notorious ransomware family that targets multiple sectors, focusing on financial and critical infrastructure.
- ransombay ransomware
- Ransombay is a ransomware targeting various industries, particularly in India and the US.
- ransomcortex ransomware
- Ransomcortex is a ransomware family that encrypts victims' data and demands payment for decryption.
- ransomed ransomware
- Ransomed is a ransomware type malware that encrypts files on the victim's system, demanding a ransom for decryption.
- ransomedvc2 ransomware
- RansomedVC2 aka RebornVC aka RansomedVC (rebrand) under new leadership.
- ransomware blog ransomware
- Ransomware Blog, also known as MedusaLocker, is a notorious ransomware that emerged in late 2019.
- rapture rat
- Rapture is a sophisticated remote access tool (RAT) often used in cyber espionage campaigns.
- rarstar ransomware
- This ransomware encrypts all user’s data on the PC (photos, documents, excel tables, music, videos, etc), adds its specific extension to…
- rat_hodin rat
- Rat_hodin is a remote access trojan used for cyber espionage, predominantly targeting government and critical infrastructure sectors.
- raznatovic trojanrat
- Raznatovic is a remote access trojan (RAT) used primarily for cyber espionage.
- rbs_srv trojan
- rbs_srv is a banking trojan primarily targeting financial institutions in North America.
- rdasrv rat
- rdasrv is a remote access trojan designed to stealthily infiltrate systems for surveillance and data exfiltration.
- reGeorg webshell
- reGeorg is an open-source web shell written in Python that can be used as a proxy to bypass firewall rules and tunnel data in and out of…
- red ransomware ransomware
- Red ransomware is known for encrypting files on victim systems and demanding a ransom for decryption keys.
- redact
- reynolds trojan
- Reynolds is a piece of malware with insufficient public documentation.
- rhysida ransomware
- Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023.
- risen ransomware
- Risen, which is a fully optimized and high-speed program, is the result of our years of experience in the field of malware writing.
- robbing hood ransomware
- Robbing Hood is a ransomware family that targets financial services and government sectors.
- rock ransomware
- Also known as yellowalbatross. Rock, also known as YellowAlbatross, is a ransomware family targeting mainly government, financial, and tech sectors in the US, UK, and…
- root rootkit
- The 'root' malware is a type of rootkit often used to gain unauthorized access and maintain stealthy control over a compromised system.
- route
- route can be used to find or change information within the local system IP routing table.
- rtm locker ransomware
- Also known as Read The Manual Locker. RTM Locker, also known as Read The Manual Locker, is a ransomware family that encrypts files on infected systems, demanding a ransom…
- rtpos
- RTPOS is a type of point-of-sale malware designed to steal payment card data from infected systems.
- run some wares
- The malware 'run some wares' currently has no detailed description available, indicating limited public knowledge about its functionality…
- rustylocker ransomware
- RustyLocker is a ransomware family that encrypts files on compromised systems, often targeting government, financial services, and…
- s1ngularity Stealer credential-stealer
- According to StepSecurity, this is a stealer deployed through a compromised Nx package, targeting system environment properties…
- sLoad downloaderscreen-capture
- Also known as Starslord. sLoad is a PowerShell downloader that most frequently delivers Ramnit banker and includes noteworthy reconnaissance features.
- sRDI loader
- Also known as DAVESHELL. sRDI allows for the conversion of DLL files to position independent shellcode.
- safepay ransomware
- SafePay ransomware started in October 2024 as a new ransomware service, using some of the leaked LockBit source code.
- sarcoma ransomware
- Also known as Sarcoma Ransomware Group. Sarcoma is a ransomware group that emerged in October 2024 and has been actively targeting various organizations.
- satancd ransomware
- Satancd is a ransomware family known for encrypting files on victims' systems to extort payments.
- satanlock ransomware
- Connected to GD Lockersec and Babuk-Bjorka.
- scanbox exploit-kit
- ScanBox is a reconnaissance and exploitation framework used in watering hole attacks, often targeting media and government sectors.
- scattered lapsus$ hunters ransomwarecredential-stealer
- Scattered LAPSUS$ is a ransomware and credential-stealer campaign that has targeted a diverse range of industries, primarily focusing on…
- schoolboys trojan
- Schoolboys is a relatively obscure malware often associated with low-level cyberattacks targeting the education sector.
- schtasks
- Also known as schtasks.exe. schtasks is used to schedule execution of programs or scripts on a Windows system to run at a specific date and time.
- secp0 ransomware
- Secp0 is a ransomware that encrypts files on infected systems, demanding a ransom payment for decryption.
- securotrop trojanbackdoor
- Securotrop is an advanced malware family known for targeting government and financial sectors.
- sedexp backdoorspyware
- sedexp is a sophisticated backdoor and spyware tool used primarily in cyber-espionage campaigns.
- seinup trojan
- Seinup is a financial trojan known to target banking institutions.
- sensayq trojan
- Sensayq is a type of trojan malware that has been observed in various cybercrime activities.
- settra
- sevyware
- shadow trojan
- Shadow is a stealthy malware that operates primarily as a trojan.
- shadowbyt3$ trojanspyware
- Shadowbyt3$ is a sophisticated malware family often used in cyber espionage.
- shadowhammer backdoor
- Also known as DAYJOB. ShadowHammer is a targeted attack campaign that compromised a popular software update mechanism to distribute malware.
- shareip ratbackdoor
- Also known as remotecmd. Shareip, also known as remotecmd, is a remote access tool used by threat actors to gain unauthorized access to systems.
- sharpboys
- This malware is known as sharpboys. Further details about its behavior, targets, and capabilities are currently unavailable.
- shinyhunters credential-stealer
- ShinyHunters is a cybercriminal group known for breaching and selling databases from various industries including technology, retail, and…
- sicari ratbackdoor
- Sicari is a remote access trojan (RAT) known to target government and financial sectors, primarily in the United States and the United…
- siegedsec ransomware
- SiegedSec is a ransomware group known for targeting educational institutions and government sectors.
- sihost trojan
- sihost is a Trojan malware that has been identified as part of a larger malware family.
- silent
- Silent is a malware with limited public information.
- silent ransom ransomware
- Silent Ransom is a ransomware family known for encrypting victims' files and demanding payment for decryption keys.
- sinobi backdoorrat
- Sinobi is a remote access trojan primarily targeting governmental and military organizations in Japan.
- skip-2.0 backdoor
- Skip-2.0 is a backdoor specifically designed to target Microsoft SQL Server, allowing attackers to bypass standard security measures and…
- skira team ratbackdoor
- Skira Team is a threat actor group known for using Remote Access Trojans to target government, financial, and tech sectors.
- skyrat rat
- Skyrat is a remote access trojan often associated with advanced persistent threat (APT) groups.
- slam ransomware
- Slam is a ransomware family known for encrypting files on compromised systems and demanding a ransom for decryption.
- slnrat rat
- SLNRat is a remote access tool (RAT) used by cybercriminals to gain unauthorized access to infected systems.
- slug rat
- Slug is a remote access trojan (RAT) known for targeting specific sectors such as government and financial services.
- smac ratbackdoor
- Also known as speccom. SMAC, also known as Speccom, is a remote access Trojan (RAT) used primarily for cyber espionage.
- solarmarker backdoorcredential-stealertrojan
- Also known as Jupyter, Polazert, Yellow Cockatoo. Unit 42 notes that they identified a new version of SolarMarker, a malware family known for its infostealing and backdoor capabilities…
- soleenya ratspyware
- Soleenya is a remote access tool (RAT) often leveraged for cyber espionage.
- soraya credential-stealer
- Soraya is a malware designed to scrape memory for payment card data on point-of-sale systems.
- space bears ratspyware
- Space Bears is an advanced persistent threat (APT) malware family known for espionage operations targeting critical infrastructure sectors.
- spirigatito
- Spirigatito is a malware entity with unidentified characteristics due to limited available information.
- splitloader downloaderloader
- Splitloader is a malware family used primarily as a downloader and loader for other malicious payloads.
- spring
- No description available.
- spwebmember spyware
- spwebmember is a Microsoft SharePoint enumeration and data dumping tool written in .NET.