Malware Families page 7 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Blackrota webshell
Blackrota is a webshell malware primarily targeting Linux-based cloud environments.
Blackruby ransomwarecryptominer
Blackruby is a ransomware that encrypts files and demands payment for decryption.
Blackshadow ransomware
BlackShadow is a state-aligned cybercrime group reportedly linked to Iran’s cyber operations, first identified in late 2020.
Blacktor ransomwaretrojan
Blacktor is a malware family known for deploying ransomware and trojan capabilities.
Blackworm RAT rat
Blackworm RAT is a remote access trojan used for unauthorized access and control of compromised systems.
Blank ransomware
Blank is a type of ransomware that encrypts files on infected systems, demanding a ransom for the decryption key.
BlankBot botnet
BlankBot is a botnet malware with limited available information.
BlankGrabber credential-stealer
Stealer written in Python 3, typically distributed bundled via PyInstaller.
BleachGap wiper
BleachGap is a wiper malware known for being used in targeted operations to erase data on infected systems.
BleedGreen Ransomware ransomware
Also known as FireCrypt Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
Blind ransomware
Blind is a ransomware that encrypts files on the victim's system, demanding a ransom payment for decryption.
BlindEDR rootkit
According to Cyderes, this is a tool to clear kernel callbacks registered by a range of security solutions.
Blister loader
Also known as COLORFAKE. Elastic observed this loader coming with valid code signatures, being used to deploy secondary payloads in-memory.
Blitzkrieg ransomware
Blitzkrieg is a ransomware family known for encrypting victim files and demanding a ransom for decryption.
Blizzard ransomware
Blizzard is a ransomware with no affiliations to existing families, known for encrypting crucial files and demanding ransom payments to…
Blocatto ransomware
Blocatto is a ransomware variant based on the HiddenTear codebase.
BlockFile12 ransomware
BlockFile12 is a sophisticated ransomware known for encrypting files and demanding ransom payments in cryptocurrencies.
Blocky ransomware
Blocky is a ransomware family known for encrypting victims' files and demanding payment in cryptocurrency for the decryption key.
BloodAlchemy rattrojan
This malware family is the suspected successor to ShadowPad and Deed rat.
BloodHound credential-stealer
BloodHound is an Active Directory (AD) reconnaissance tool that can reveal hidden relationships and identify attack paths within an AD…
BloodJaws ransomware
BloodJaws is a type of ransomware that encrypts victim files and demands payment to release them.
BloodyStealer credential-stealertrojan
BloodyStealer is a credential-stealing malware that primarily targets gaming platforms and services.
Blooper ransomware
Blooper is a type of ransomware that encrypts files on victim systems and demands a ransom for decryption.
BluStealer credential-stealerkeyloggertrojan
Also known as a310logger. Avast describe this malware as a recombination of other malware including SpyEx, ThunderFox, ChromeRecovery, StormKitty, and firepwd.
Blue Banana rat
Blue Banana is a RAT (Remote Administration Tool) created purely in Java
Blue Banana RAT rat
Blue Banana RAT is a remote access tool used primarily in cyber-espionage campaigns targeting government and financial sectors.
BlueCheeser ransomware
BlueCheeser is a ransomware family that encrypts victims' data and demands a ransom payment.
BlueEagle ransomware
BlueEagle is a ransomware variant that targets various industries, encrypting files and demanding payment in cryptocurrency.
BlueFox credential-stealerloader
BlueFox is a .NET infostealer sold on forums as a Maware-as-a-Service.
BlueNoroff trojan
This family contains the BlueNoroff toolkit used for SWIFT manipulation, as used by the Lazarus activity cluster also referred to as…
BlueShell backdoor
According to AhnLab, BlueShell is a backdoor malware developed in Go language, published on Github, and it supports Windows, Linux, and…
Bluerose ransomware
Bluerose is a type of ransomware that encrypts files on an infected system and demands payment for the decryption key.
Bluesky ransomware
Bluesky is a ransomware known for encrypting files on infected systems and demanding ransom payments typically in cryptocurrency.
Boaxxe botnet
Boaxxe is a malware family known for its involvement in botnet activities, primarily targeting financial data and launching distributed…
Bobik ratddos
This malware offers remote access capabilities but also has a DDoS module that was used against supporters of Ukraine.
BockLit ransomware
According to Trend Micro, this is a ransomware written in Go, targeting Windows and MacOS environments that tries to disguise as LockBit…
Bofamet credential-stealerspyware
Bofamet Stealer is an infostealer managed through a web-based Command and Control (C2) panel, allowing attackers to configure operations…
Bohmini trojanbackdoor
Bohmini is a remote access trojan known for providing backdoor access to compromised systems.
Bolek botnettrojan
Also known as KBOT. Bolek, also known as KBOT, is a banking trojan that primarily targets financial institutions in Eastern Europe, particularly in Russia and…
Bonacigroup trojanbotnet
Bonacigroup is a cybercrime group known for deploying various trojans that target financial services and technology sectors, primarily in…
Bonadan backdoorcryptominercredential-stealer
Bonadan is a malicious version of OpenSSH which acts as a custom backdoor.
BoneSpy spyware
According to Lookout, BoneSpy is based on the Russian-developed, open-source DroidWatcher surveillanceware, featuring nearly identical…
Bonsoir ransomware
Bonsoir is a ransomware that encrypts files on the infected system and demands a ransom payment for decryption.
BooM ransomware
BooM is a ransomware threat known for encrypting victim files and demanding a ransom payment for decryption.
Book of Eli credential-stealerkeyloggerscreen-capture
This in .Net written malware is a classic information stealer.
BookCodes RAT rat
Also known as BookCodesTea. BookCodesRAT is a remote access trojan that uses HTTP(S) for communication.
BoomBox downloader
BoomBox is a downloader responsible for executing next stage components that has been used by APT29 since at least 2021.
BoooamCrypt ransomware
BoooamCrypt is a type of ransomware that encrypts files on infected systems, demanding a ransom from victims to restore access.
Bootkitty wiper
Bootkitty is a bootkit malware that has been employed in attacks against critical infrastructure sectors and leverages advanced techniques…
Booyah ransomware
Also known as Salami. Booyah, also known as Salami, is a ransomware family known for encrypting files and demanding a ransom to restore access.
Borat RAT ratspywareransomware
The Borat RAT comes bundled with its components (e.g.
Boris HT ransomware
Boris HT is a ransomware that encrypts user data and demands a ransom for decryption.
Borr trojan
Borr is a banking trojan primarily targeting financial institutions and government entities.
BotenaGo wormexploit-kit
According to Alien Labs, this malware targets embedded devices including routers with more than 30 exploits.
BottomLoader downloaderloader
BottomLoader is a malware family known primarily for its functionality as a downloader and loader.
Bouncer rat
Bouncer is a Remote Access Trojan (RAT) used for gaining unauthorized control over targeted systems.
BoxCaon backdoor
BoxCaon is a Windows backdoor that was used by IndigoZebra in a 2021 spearphishing campaign against Afghan government officials.
Bozok rat
Bozok is a Remote Access Trojan (RAT) that allows attackers to remotely control infected machines, enabling data theft and espionage…
BrLock ransomware
BrLock is a ransomware family known for encrypting files and demanding ransom payments for decryption keys.
BrainCrypt Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
BrainLag ransomware
BrainLag is a ransomware strain that targets various industries by encrypting files and demanding cryptocurrency for decryption keys.
BrainTest trojanspyware
BrainTest is a family of Android malware known for its ability to persist on infected devices by exploiting system vulnerabilities.
Brambul wormcredential-stealer
Also known as SORRYBRUTE. Brambul is a worm that spreads by using a list of hard-coded login credentials to launch a brute-force password attack against an SMB…
Braodo credential-stealerspyware
According to K7 Security Labs, Braodo Stealer is written in Python and collects all cookies and saved credentials from the browsers and…
BrasDex trojancredential-stealer
According to PCrisk, BraDex is a banking malware targeting Android operating systems.
Brat rat
Brat is a remote access trojan (RAT) known for providing attackers with access to infected systems.
Brave Prince ratspyware
Brave Prince is a Korean-language implant that was first observed in the wild in December 2017.
BravoNC rat
BravoNC is a sophisticated remote access tool (RAT) used primarily for cyber-espionage.
Brazilian ransomware
Brazilian is a ransomware strain based on the EDA2 project.
Brazilian Globe ransomware
Brazilian Globe is a ransomware strain known for targeting organizations within Brazil.
BrbBot botnetcredential-stealer
BrbBot is a botnet malware family primarily targeting financial services and technology sectors.
BreachRAT ratbackdoor
This is a backdoor which FireEye call the Breach Remote Administration Tool (BreachRAT), written in C++.
Bread trojan
Also known as Joker. Bread was a large-scale billing fraud malware family known for employing many different cloaking and obfuscation techniques in an attempt…
Break out the Box cryptominer
Also known as BOtB. This is a pentesting tool and according to the author, "BOtB is a container analysis and exploitation tool designed to be used by…
Breakthrough loader
There is no reference available for this family and all known samples have version 1.0.0.
Bredolab botnetcredential-stealerdownloader
Bredolab is a malware family primarily known for its use as a downloader.
Briba trojanbackdoordownloader
Briba is a trojan used by Elderwood to open a backdoor and download files on to compromised hosts.
Brick ransomware
Brick is a type of ransomware used by cybercriminals to encrypt victims' data and demand a ransom payment for recovery.
BrickR ransomware
BrickR is a ransomware that encrypts victim files and demands a ransom for their release.
BrickerBot ddoswiper
BrickerBot is malware that targets IoT devices, rendering them unusable by corrupting their storage and disrupting their network…
BrittleBush trojanwiper
BrittleBush is a sophisticated malware family targeting government and energy sectors.
Broomstick backdoorransomware
Also known as CLEANBOOST, CleanUp, CleanUpLoader. Oyster is a backdoor malware written in C++ that first appeared in July 2023.
Browlock ransomware
Browlock is a browser locker ransomware that doesn't encrypt files locally but locks the victim's browser instead, displaying a ransom…
Bruh Wiper wiper
Bruh Wiper is a destructive malware designed to delete data and render systems inoperable.
Brunhilda dropper
PRODAFT describes Brunhilda as a "Dropper as a Service" for Google Play, delivering e.g.
BrushaLoader loader
BrushaLoader is a malware loader known for delivering additional malicious payloads.
BrutPOS credential-stealer
BrutPOS is a type of malware designed to target point-of-sale systems by using brute-force attacks to steal credentials.
Brute Ratel C4 rat
Also known as BRc4, BOLDBADGER, BruteRatel. Brute Ratel C4 is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020.
BtcKING ransomware
BtcKING is a ransomware family that encrypts files on infected systems and demands payment in cryptocurrency.
Bucbi ransomware
Bucbi is a type of ransomware that encrypts files on the target system without changing file names or extensions.
Bud ransomware
Bud ransomware encrypts files on the victim's system, often demanding payment in cryptocurrency to provide the decryption key.
Buer downloaderloader
Also known as Buerloader, RustyBuer. Buer is a downloader sold on underground forums and used by threat actors to deliver payload malware onto target machines.
BugWare ransomware
BugWare is a type of ransomware malware designed to encrypt files on infected systems and demand payment for decryption keys.
Buhtrap trojancredential-stealerbackdoor
Also known as Ratopak. Buhtrap is a sophisticated malware family primarily targeting financial institutions and government organizations in Russia and Ukraine.
BulbaCrypt HT ransomware
BulbaCrypt HT is a form of ransomware designed to encrypt files on a victim's system, demanding a ransom for decryption.
Bumblebee loaderdropper
Also known as COLDTRAIN, SHELLSTING, Shindig. Bumblebee is a custom loader written in C++ that has been used by multiple threat actors, including possible initial access brokers, to…
Bundestrojaner spywaretrojan
Also known as 0zapftis, R2D2. Bundestrojaner, also known as 0zapftis or R2D2, is a government-developed spyware program used by German law enforcement for surveillance…
BundleBot credential-stealerscreen-capturetrojan
Bundlebot is an info stealer that abuses the single-file dotnet bundle which operates as a self-contained executable that does not require…
Bundlore backdoor
Also known as OSX.Bundlore, SurfBuyer. Bundlore is adware written for macOS that has been in use since at least 2015.
Bunitu trojan
Bunitu is a trojan that exposes infected computers to be used as a proxy for remote clients.