Malware Families page 62 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- spy corporate
- sqlmap exploit-kit
- sqlmap is an open source penetration testing tool that can be used to automate the process of detecting and exploiting SQL injection flaws.
- stealler credential-stealer
- Stealler is a type of credential-stealing malware that captures and exfiltrates sensitive information such as passwords from infected…
- sugar backdoorrat
- Sugar is a backdoor malware known for its use in cyber espionage operations, primarily targeting government and public sector organizations.
- sundawn rat
- Sundawn is a Remote Access Trojan (RAT) primarily associated with cyber-espionage activities targeting government sectors.
- superblack ransomware
- Superblack is a sophisticated ransomware variant that primarily targets governmental and financial sectors.
- surtr ransomware
- According to PCrisk, Surtr is ransomware.
- sustes miner cryptominerdownloader
- Sustes Malware doesn’t infect victims by itself (it’s not a worm) but it is spread over exploitation and brute-force activities with…
- swen wormvirus
- Swen is a worm known for propagating via mass emailing techniques, often disguising itself as a legitimate message from Microsoft.
- synapse backdoortrojan
- Synapse is a sophisticated backdoor trojan utilized in cyber espionage operations targeting financial, government, and tech sectors.
- systemd backdoorrat
- Also known as Demsty, ReverseWindow. Systemd, also known as Demsty and ReverseWindow, is a general purpose backdoor used for cyber espionage.
- tRat rat
- tRat is a modular RAT written in Delphi and has appeared in campaigns in September and October of 2018.
- targetcompany ransomware
- Also known as Fargo, Mallox, Tohnichi. TargetCompany, also known as Fargo, Mallox, and Tohnichi, is a ransomware family primarily targeting various industries.
- taronis rat
- Taronis is a Remote Access Trojan (RAT) used primarily for cyber espionage against specific sectors.
- team underground
- Team Underground is a known group linked to various cyber threat activities, often associated with creating and distributing malware.
- teamxxx botnettrojan
- TeamXXX is a malicious botnet and trojan primarily targeting financial services and technology sectors.
- telegram
- This entry refers to malware associated with Telegram, a social messaging application.
- tengu rat
- Tengu is a remote access trojan (RAT) known for its use in targeted attacks against government and technology sectors, particularly in…
- termite trojanrat
- Termite is a remote access trojan used primarily for cyber espionage, targeting government and technology sectors.
- thanos ransomware
- Thanos is a ransomware family known for its Ransomware-as-a-Service (RaaS) offerings, allowing affiliates to customize their attacks.
- the gentlemen
- No description available for the gentlemen malware.
- the green blood group backdoorransomware
- The Green Blood Group is a sophisticated malware group known for conducting espionage and data exfiltration campaigns.
- threatmarket trojan
- Threatmarket is a malware family identified as a trojan, known for its modularity and flexible attack vectors.
- thunder x rat
- Thunder X is a remote access trojan known for its advanced capabilities used by threat actors for persistent attacks.
- tildeb rat
- Standalone implant. Potentially tied to a framework called PATROLWAGON.
- timc backdoorcredential-stealer
- Timc is a sophisticated piece of malware that has primarily been used in cyber espionage campaigns.
- tommyleaks spywarecredential-stealer
- Tommyleaks is a spyware family known for targeting financial institutions and government sectors in North America and Western Europe.
- tooda
- A malware known as 'tooda' with members suggesting a multifaceted or code-named threat structure, involving components named Eco, Ego…
- toufan ddos
- Toufan is a distributed denial-of-service (DDoS) malware that has been used to target financial and government sectors.
- toxic
- Toxic is a piece of malware with limited publicly available information.
- tridentlocker ransomware
- TridentLocker is a ransomware family known for encrypting files and demanding a ransom from victims.
- trigona ransomware
- Trigona is a ransomware family known for encrypting victim's files and demanding a ransom payment for decryption.
- trinity botnetddos
- Trinity is a notorious malware family historically associated with distributed denial of service (DDoS) attacks.
- triple x
- trisec rat
- Trisec is a remote access tool (RAT) used primarily for cyber espionage.
- troystealer credential-stealerspyware
- Troystealer is a credential-stealing malware family primarily used to harvest sensitive information such as passwords and personal data.
- tsh backdoorwebshell
- Also known as TINYSHELL. TSH, also known as TINYSHELL, is a lightweight remote access tool used to establish a backdoor connection for unauthorized access and…
- tssxx25 trojanrat
- tssxx25 is a remote access trojan used in cybercrime campaigns to gain unauthorized access to targeted systems.
- tsunami backdoorrat
- Tsunami is an open-source malware primarily used as a backdoor and remote access tool (RAT) on Linux systems.
- tuborg
- Tuborg is a malware entry with limited information available.
- turkish crypter
- The Turkish Crypter is used to obfuscate malicious payloads, making it more difficult for security tools to detect the malware it conceals.
- u-bomb wiper
- U-Bomb is a destructive wiper malware that aims to delete and overwrite files on infected systems, often rendering them inoperable.
- ulose
- unidentified_002
- unidentified_003
- This malware named unidentified_003 has no available description, making its characteristics and targets largely unknown.
- vCrypt1 ransomware
- vCrypt1 is a ransomware threat, primarily focused on encrypting victim files and demanding ransom for decryption keys.
- vGet loader
- According to Synacktiv, vGet is an in-memory stager for vShell, written in Rust.
- vSkimmer credential-stealer
- vSkimmer is a malware family designed to target point-of-sale (POS) systems, specifically focusing on ATM machines to steal credit card…
- valencia leaks
- Official twitter account: https://x.com/ValenciaLeaks72
- vamp ratspyware
- Also known as android.micropsia. Related to the micropsia windows malware and also sometimes named micropsia.
- vandev
- vandev is a known malware with limited public information available, making its capabilities and target scope unclear.
- vanhelsing ransomware
- Designed to target Windows systems, this ransomware employs advanced encryption techniques and appends a unique file extension to…
- vanillarat ratkeylogger
- Description: VanillaRat is an advanced remote administration tool coded in C#.
- vanir group trojanspyware
- Vanir Group is a sophisticated threat used primarily for espionage activities targeting government and critical infrastructure sectors.
- vasalocker ransomware
- VasaLocker is a ransomware family that encrypts files on infected systems and demands a ransom for decryption keys.
- vect ratloader
- Vect is a remote access tool (RAT) known for its stealthy loading capabilities.
- virdetdoor backdoor
- Virdetdoor is a backdoor malware designed to provide unauthorized remote access to compromised systems.
- vjw0rm 0.1 wormratddos
- Also known as Vengeance Justice Worm, VJw0rm, VJwOrm. “Vengeance Justice Worm” was first discovered in 2016 and is a highly multifunctional, modular, publicly available “commodity malware”…
- vo1d botnet
- According to Xlab, this malware is used to compromise Android TVs and set-top boxes, and its corresponding botnet had more than 1 million…
- vulcan ransomware
- Vulcan is a ransomware family known for targeting critical infrastructure sectors such as government, energy, and aerospace.
- vxLock ransomware
- vxLock is a ransomware that encrypts files on a victim's machine and demands a ransom for decryption.
- vxRat rat
- vxRat is a remote access tool used for cyber espionage, primarily targeting government and technology sectors.
- w32times trojan
- w32times is a Windows-based trojan used for unauthorized access and data exfiltration.
- w3crypto cryptominer
- W3crypto is a cryptocurrency mining malware that exploits system resources to mine cryptocurrencies, often targeting financial services…
- wAgentTea downloader
- Also known as wAgent. wAgentTea is an HTTP(S) downloader. It was deployed mostly against South Korean targets like a pharmaceutical company (Q4 2020) or…
- waissbein backdoortrojan
- Waissbein is a sophisticated backdoor trojan used in targeted attacks primarily against government, financial services, and technology…
- wallstreet
- walocker ransomware
- Walocker is a ransomware strain known for targeting logistics and supply chain companies, encrypting files and demanding ransom for…
- warlock rattrojan
- Warlock is a remote access trojan used to target financial and governmental institutions.
- weaxor rat
- Weaxor is a Remote Access Trojan (RAT) primarily used for gaining unauthorized access and control over compromised machines.
- werewolves trojanransomware
- Werewolves is a malware family known for targeting energy and financial sectors, primarily in the US and Russia.
- weyhro
- Appears to be a Data Extortion group with no encryption.
- white lock
- wiki ransomware ransomware
- Wiki ransomware is a malicious software variant designed to encrypt files on the victim's machine and demand a ransom for decryption.
- wikileaksv2 rat
- WikileaksV2 is a Remote Access Trojan (RAT) associated with the Qilin group, known for targeting government and media sectors.
- win.JobCrypter ransomware
- JobCrypter is a ransomware targeting Windows systems, known for encrypting files and demanding a ransom in cryptocurrency.
- win.beast ransomware
- Also known as blacklockbit. Beast is a Ransomware-as-a-service (RaaS) product which provides functionality such as SMB scanning, file encryption, service and process…
- win.fujinama credential-stealerkeyloggerscreen-capture
- Fujinama is a custom VB info stealer capable to execute custom commands and custom exfiltrations, keylogging and screenshot.
- win.ghostengine backdoorrat
- Win.GhostEngine is a Remote Access Trojan used primarily for cyber-espionage purposes, with capabilities to infiltrate and control target…
- win.icexloader downloaderloader
- IceXLoader is a commercial malware used to download and deploy additional malware on infected machines.
- win.innfirat backdoorcredential-stealerkeylogger
- InnifiRAT is coded in .NET and targets personal data on infected devices, with it's top priority appearing to be bitcoin and litecoin…
- win.pyfiledel wiperworm
- Py2exe built worm propagating via USB drives, having wiper features embedded in the logic (based on today's date being later than…
- win.rekoobe trojanbackdoor
- Also known as tinyshell.win, tshd.win. A Trojan for Winows with the same code structure and functionalities of elf.rekoobe, for Linux environment instead.
- win.wabot worm
- Wabot is an IRC worm that propagates through networks using the IRC protocol.
- winlog credential-stealer
- Winlog is a credential-stealing malware particularly used in targeted attacks against government and financial sectors.
- wiper leak wiper
- Wiper Leak is a malicious software variant that focuses on destroying or wiping data on compromised systems.
- witchcoven ratspyware
- Witchcoven is a remote access tool (RAT) used for cyber-espionage activities, primarily targeting financial services and government…
- woody backdoorrat
- Woody is a backdoor and remote access trojan (RAT) primarily used in cyber espionage campaigns targeting government and energy sectors in…
- worldleaks
- Worldleaks is a malware family potentially involved in data breaches.
- x4 ratspyware
- x4 is an advanced remote access trojan (RAT) that targets government and technology sectors to conduct cyber-espionage.
- xCaon backdoor
- xCaon is an HTTP variant of the BoxCaon malware family that has used by IndigoZebra since at least 2014.
- xCmd
- xCmd is an open source tool that is similar to PsExec and allows the user to execute applications on remote systems.
- xHacker Pro RAT rat
- xHacker Pro RAT is a remote access tool used for cyber espionage.
- xHelper trojandownloader
- Xhelper is a very persistent malware that can reinstall itself after factory reset, Xhelper downloads malicious apps and displays annoying…
- xPack loader
- Also known as NERAPACK. Symantec describes this as a decryptor/loader used by Chinese threat actor Antlion in campaigns targeting Taiwan.
- xXLecXx ransomware
- xXLecXx is a type of ransomware that encrypts files on the victim's computer and demands payment to restore access.
- xdr33 backdoor
- According to 360 netlab, this backdoor was derived from the leaked CIA Hive project.
- xelera trojanspyware
- Xelera is a malware trojan known for its capabilities in surveillance and data theft.
- xleaks credential-stealerspyware
- Xleaks is a malware used primarily for stealing credentials and spying on targeted systems.
- xmrig cryptominer
- According to PCrisk, XMRIG is a completely legitimate open-source application that utilizes system CPUs to mine Monero cryptocurrency.