Malware Families page 62 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

spy corporate
sqlmap exploit-kit
sqlmap is an open source penetration testing tool that can be used to automate the process of detecting and exploiting SQL injection flaws.
stealler credential-stealer
Stealler is a type of credential-stealing malware that captures and exfiltrates sensitive information such as passwords from infected…
sugar backdoorrat
Sugar is a backdoor malware known for its use in cyber espionage operations, primarily targeting government and public sector organizations.
sundawn rat
Sundawn is a Remote Access Trojan (RAT) primarily associated with cyber-espionage activities targeting government sectors.
superblack ransomware
Superblack is a sophisticated ransomware variant that primarily targets governmental and financial sectors.
surtr ransomware
According to PCrisk, Surtr is ransomware.
sustes miner cryptominerdownloader
Sustes Malware doesn’t infect victims by itself (it’s not a worm) but it is spread over exploitation and brute-force activities with…
swen wormvirus
Swen is a worm known for propagating via mass emailing techniques, often disguising itself as a legitimate message from Microsoft.
synapse backdoortrojan
Synapse is a sophisticated backdoor trojan utilized in cyber espionage operations targeting financial, government, and tech sectors.
systemd backdoorrat
Also known as Demsty, ReverseWindow. Systemd, also known as Demsty and ReverseWindow, is a general purpose backdoor used for cyber espionage.
tRat rat
tRat is a modular RAT written in Delphi and has appeared in campaigns in September and October of 2018.
targetcompany ransomware
Also known as Fargo, Mallox, Tohnichi. TargetCompany, also known as Fargo, Mallox, and Tohnichi, is a ransomware family primarily targeting various industries.
taronis rat
Taronis is a Remote Access Trojan (RAT) used primarily for cyber espionage against specific sectors.
team underground
Team Underground is a known group linked to various cyber threat activities, often associated with creating and distributing malware.
teamxxx botnettrojan
TeamXXX is a malicious botnet and trojan primarily targeting financial services and technology sectors.
telegram
This entry refers to malware associated with Telegram, a social messaging application.
tengu rat
Tengu is a remote access trojan (RAT) known for its use in targeted attacks against government and technology sectors, particularly in…
termite trojanrat
Termite is a remote access trojan used primarily for cyber espionage, targeting government and technology sectors.
thanos ransomware
Thanos is a ransomware family known for its Ransomware-as-a-Service (RaaS) offerings, allowing affiliates to customize their attacks.
the gentlemen
No description available for the gentlemen malware.
the green blood group backdoorransomware
The Green Blood Group is a sophisticated malware group known for conducting espionage and data exfiltration campaigns.
threatmarket trojan
Threatmarket is a malware family identified as a trojan, known for its modularity and flexible attack vectors.
thunder x rat
Thunder X is a remote access trojan known for its advanced capabilities used by threat actors for persistent attacks.
tildeb rat
Standalone implant. Potentially tied to a framework called PATROLWAGON.
timc backdoorcredential-stealer
Timc is a sophisticated piece of malware that has primarily been used in cyber espionage campaigns.
tommyleaks spywarecredential-stealer
Tommyleaks is a spyware family known for targeting financial institutions and government sectors in North America and Western Europe.
tooda
A malware known as 'tooda' with members suggesting a multifaceted or code-named threat structure, involving components named Eco, Ego…
toufan ddos
Toufan is a distributed denial-of-service (DDoS) malware that has been used to target financial and government sectors.
toxic
Toxic is a piece of malware with limited publicly available information.
tridentlocker ransomware
TridentLocker is a ransomware family known for encrypting files and demanding a ransom from victims.
trigona ransomware
Trigona is a ransomware family known for encrypting victim's files and demanding a ransom payment for decryption.
trinity botnetddos
Trinity is a notorious malware family historically associated with distributed denial of service (DDoS) attacks.
triple x
trisec rat
Trisec is a remote access tool (RAT) used primarily for cyber espionage.
troystealer credential-stealerspyware
Troystealer is a credential-stealing malware family primarily used to harvest sensitive information such as passwords and personal data.
tsh backdoorwebshell
Also known as TINYSHELL. TSH, also known as TINYSHELL, is a lightweight remote access tool used to establish a backdoor connection for unauthorized access and…
tssxx25 trojanrat
tssxx25 is a remote access trojan used in cybercrime campaigns to gain unauthorized access to targeted systems.
tsunami backdoorrat
Tsunami is an open-source malware primarily used as a backdoor and remote access tool (RAT) on Linux systems.
tuborg
Tuborg is a malware entry with limited information available.
turkish crypter
The Turkish Crypter is used to obfuscate malicious payloads, making it more difficult for security tools to detect the malware it conceals.
u-bomb wiper
U-Bomb is a destructive wiper malware that aims to delete and overwrite files on infected systems, often rendering them inoperable.
ulose
unidentified_002
unidentified_003
This malware named unidentified_003 has no available description, making its characteristics and targets largely unknown.
vCrypt1 ransomware
vCrypt1 is a ransomware threat, primarily focused on encrypting victim files and demanding ransom for decryption keys.
vGet loader
According to Synacktiv, vGet is an in-memory stager for vShell, written in Rust.
vSkimmer credential-stealer
vSkimmer is a malware family designed to target point-of-sale (POS) systems, specifically focusing on ATM machines to steal credit card…
valencia leaks
Official twitter account: https://x.com/ValenciaLeaks72
vamp ratspyware
Also known as android.micropsia. Related to the micropsia windows malware and also sometimes named micropsia.
vandev
vandev is a known malware with limited public information available, making its capabilities and target scope unclear.
vanhelsing ransomware
Designed to target Windows systems, this ransomware employs advanced encryption techniques and appends a unique file extension to…
vanillarat ratkeylogger
Description: VanillaRat is an advanced remote administration tool coded in C#.
vanir group trojanspyware
Vanir Group is a sophisticated threat used primarily for espionage activities targeting government and critical infrastructure sectors.
vasalocker ransomware
VasaLocker is a ransomware family that encrypts files on infected systems and demands a ransom for decryption keys.
vect ratloader
Vect is a remote access tool (RAT) known for its stealthy loading capabilities.
virdetdoor backdoor
Virdetdoor is a backdoor malware designed to provide unauthorized remote access to compromised systems.
vjw0rm 0.1 wormratddos
Also known as Vengeance Justice Worm, VJw0rm, VJwOrm. “Vengeance Justice Worm” was first discovered in 2016 and is a highly multifunctional, modular, publicly available “commodity malware”…
vo1d botnet
According to Xlab, this malware is used to compromise Android TVs and set-top boxes, and its corresponding botnet had more than 1 million…
vulcan ransomware
Vulcan is a ransomware family known for targeting critical infrastructure sectors such as government, energy, and aerospace.
vxLock ransomware
vxLock is a ransomware that encrypts files on a victim's machine and demands a ransom for decryption.
vxRat rat
vxRat is a remote access tool used for cyber espionage, primarily targeting government and technology sectors.
w32times trojan
w32times is a Windows-based trojan used for unauthorized access and data exfiltration.
w3crypto cryptominer
W3crypto is a cryptocurrency mining malware that exploits system resources to mine cryptocurrencies, often targeting financial services…
wAgentTea downloader
Also known as wAgent. wAgentTea is an HTTP(S) downloader. It was deployed mostly against South Korean targets like a pharmaceutical company (Q4 2020) or…
waissbein backdoortrojan
Waissbein is a sophisticated backdoor trojan used in targeted attacks primarily against government, financial services, and technology…
wallstreet
walocker ransomware
Walocker is a ransomware strain known for targeting logistics and supply chain companies, encrypting files and demanding ransom for…
warlock rattrojan
Warlock is a remote access trojan used to target financial and governmental institutions.
weaxor rat
Weaxor is a Remote Access Trojan (RAT) primarily used for gaining unauthorized access and control over compromised machines.
werewolves trojanransomware
Werewolves is a malware family known for targeting energy and financial sectors, primarily in the US and Russia.
weyhro
Appears to be a Data Extortion group with no encryption.
white lock
wiki ransomware ransomware
Wiki ransomware is a malicious software variant designed to encrypt files on the victim's machine and demand a ransom for decryption.
wikileaksv2 rat
WikileaksV2 is a Remote Access Trojan (RAT) associated with the Qilin group, known for targeting government and media sectors.
win.JobCrypter ransomware
JobCrypter is a ransomware targeting Windows systems, known for encrypting files and demanding a ransom in cryptocurrency.
win.beast ransomware
Also known as blacklockbit. Beast is a Ransomware-as-a-service (RaaS) product which provides functionality such as SMB scanning, file encryption, service and process…
win.fujinama credential-stealerkeyloggerscreen-capture
Fujinama is a custom VB info stealer capable to execute custom commands and custom exfiltrations, keylogging and screenshot.
win.ghostengine backdoorrat
Win.GhostEngine is a Remote Access Trojan used primarily for cyber-espionage purposes, with capabilities to infiltrate and control target…
win.icexloader downloaderloader
IceXLoader is a commercial malware used to download and deploy additional malware on infected machines.
win.innfirat backdoorcredential-stealerkeylogger
InnifiRAT is coded in .NET and targets personal data on infected devices, with it's top priority appearing to be bitcoin and litecoin…
win.pyfiledel wiperworm
Py2exe built worm propagating via USB drives, having wiper features embedded in the logic (based on today's date being later than…
win.rekoobe trojanbackdoor
Also known as tinyshell.win, tshd.win. A Trojan for Winows with the same code structure and functionalities of elf.rekoobe, for Linux environment instead.
win.wabot worm
Wabot is an IRC worm that propagates through networks using the IRC protocol.
winlog credential-stealer
Winlog is a credential-stealing malware particularly used in targeted attacks against government and financial sectors.
wiper leak wiper
Wiper Leak is a malicious software variant that focuses on destroying or wiping data on compromised systems.
witchcoven ratspyware
Witchcoven is a remote access tool (RAT) used for cyber-espionage activities, primarily targeting financial services and government…
woody backdoorrat
Woody is a backdoor and remote access trojan (RAT) primarily used in cyber espionage campaigns targeting government and energy sectors in…
worldleaks
Worldleaks is a malware family potentially involved in data breaches.
x4 ratspyware
x4 is an advanced remote access trojan (RAT) that targets government and technology sectors to conduct cyber-espionage.
xCaon backdoor
xCaon is an HTTP variant of the BoxCaon malware family that has used by IndigoZebra since at least 2014.
xCmd
xCmd is an open source tool that is similar to PsExec and allows the user to execute applications on remote systems.
xHacker Pro RAT rat
xHacker Pro RAT is a remote access tool used for cyber espionage.
xHelper trojandownloader
Xhelper is a very persistent malware that can reinstall itself after factory reset, Xhelper downloads malicious apps and displays annoying…
xPack loader
Also known as NERAPACK. Symantec describes this as a decryptor/loader used by Chinese threat actor Antlion in campaigns targeting Taiwan.
xXLecXx ransomware
xXLecXx is a type of ransomware that encrypts files on the victim's computer and demands payment to restore access.
xdr33 backdoor
According to 360 netlab, this backdoor was derived from the leaked CIA Hive project.
xelera trojanspyware
Xelera is a malware trojan known for its capabilities in surveillance and data theft.
xleaks credential-stealerspyware
Xleaks is a malware used primarily for stealing credentials and spying on targeted systems.
xmrig cryptominer
According to PCrisk, XMRIG is a completely legitimate open-source application that utilizes system CPUs to mine Monero cryptocurrency.