Malware Families page 7 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Blackrota webshell
- Blackrota is a webshell malware primarily targeting Linux-based cloud environments.
- Blackruby ransomwarecryptominer
- Blackruby is a ransomware that encrypts files and demands payment for decryption.
- Blackshadow ransomware
- BlackShadow is a state-aligned cybercrime group reportedly linked to Iran’s cyber operations, first identified in late 2020.
- Blacktor ransomwaretrojan
- Blacktor is a malware family known for deploying ransomware and trojan capabilities.
- Blackworm RAT rat
- Blackworm RAT is a remote access trojan used for unauthorized access and control of compromised systems.
- Blank ransomware
- Blank is a type of ransomware that encrypts files on infected systems, demanding a ransom for the decryption key.
- BlankBot botnet
- BlankBot is a botnet malware with limited available information.
- BlankGrabber credential-stealer
- Stealer written in Python 3, typically distributed bundled via PyInstaller.
- BleachGap wiper
- BleachGap is a wiper malware known for being used in targeted operations to erase data on infected systems.
- BleedGreen Ransomware ransomware
- Also known as FireCrypt Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- Blind ransomware
- Blind is a ransomware that encrypts files on the victim's system, demanding a ransom payment for decryption.
- BlindEDR rootkit
- According to Cyderes, this is a tool to clear kernel callbacks registered by a range of security solutions.
- Blister loader
- Also known as COLORFAKE. Elastic observed this loader coming with valid code signatures, being used to deploy secondary payloads in-memory.
- Blitzkrieg ransomware
- Blitzkrieg is a ransomware family known for encrypting victim files and demanding a ransom for decryption.
- Blizzard ransomware
- Blizzard is a ransomware with no affiliations to existing families, known for encrypting crucial files and demanding ransom payments to…
- Blocatto ransomware
- Blocatto is a ransomware variant based on the HiddenTear codebase.
- BlockFile12 ransomware
- BlockFile12 is a sophisticated ransomware known for encrypting files and demanding ransom payments in cryptocurrencies.
- Blocky ransomware
- Blocky is a ransomware family known for encrypting victims' files and demanding payment in cryptocurrency for the decryption key.
- BloodAlchemy rattrojan
- This malware family is the suspected successor to ShadowPad and Deed rat.
- BloodHound credential-stealer
- BloodHound is an Active Directory (AD) reconnaissance tool that can reveal hidden relationships and identify attack paths within an AD…
- BloodJaws ransomware
- BloodJaws is a type of ransomware that encrypts victim files and demands payment to release them.
- BloodyStealer credential-stealertrojan
- BloodyStealer is a credential-stealing malware that primarily targets gaming platforms and services.
- Blooper ransomware
- Blooper is a type of ransomware that encrypts files on victim systems and demands a ransom for decryption.
- BluStealer credential-stealerkeyloggertrojan
- Also known as a310logger. Avast describe this malware as a recombination of other malware including SpyEx, ThunderFox, ChromeRecovery, StormKitty, and firepwd.
- Blue Banana rat
- Blue Banana is a RAT (Remote Administration Tool) created purely in Java
- Blue Banana RAT rat
- Blue Banana RAT is a remote access tool used primarily in cyber-espionage campaigns targeting government and financial sectors.
- BlueCheeser ransomware
- BlueCheeser is a ransomware family that encrypts victims' data and demands a ransom payment.
- BlueEagle ransomware
- BlueEagle is a ransomware variant that targets various industries, encrypting files and demanding payment in cryptocurrency.
- BlueFox credential-stealerloader
- BlueFox is a .NET infostealer sold on forums as a Maware-as-a-Service.
- BlueNoroff trojan
- This family contains the BlueNoroff toolkit used for SWIFT manipulation, as used by the Lazarus activity cluster also referred to as…
- BlueShell backdoor
- According to AhnLab, BlueShell is a backdoor malware developed in Go language, published on Github, and it supports Windows, Linux, and…
- Bluerose ransomware
- Bluerose is a type of ransomware that encrypts files on an infected system and demands payment for the decryption key.
- Bluesky ransomware
- Bluesky is a ransomware known for encrypting files on infected systems and demanding ransom payments typically in cryptocurrency.
- Boaxxe botnet
- Boaxxe is a malware family known for its involvement in botnet activities, primarily targeting financial data and launching distributed…
- Bobik ratddos
- This malware offers remote access capabilities but also has a DDoS module that was used against supporters of Ukraine.
- BockLit ransomware
- According to Trend Micro, this is a ransomware written in Go, targeting Windows and MacOS environments that tries to disguise as LockBit…
- Bofamet credential-stealerspyware
- Bofamet Stealer is an infostealer managed through a web-based Command and Control (C2) panel, allowing attackers to configure operations…
- Bohmini trojanbackdoor
- Bohmini is a remote access trojan known for providing backdoor access to compromised systems.
- Bolek botnettrojan
- Also known as KBOT. Bolek, also known as KBOT, is a banking trojan that primarily targets financial institutions in Eastern Europe, particularly in Russia and…
- Bonacigroup trojanbotnet
- Bonacigroup is a cybercrime group known for deploying various trojans that target financial services and technology sectors, primarily in…
- Bonadan backdoorcryptominercredential-stealer
- Bonadan is a malicious version of OpenSSH which acts as a custom backdoor.
- BoneSpy spyware
- According to Lookout, BoneSpy is based on the Russian-developed, open-source DroidWatcher surveillanceware, featuring nearly identical…
- Bonsoir ransomware
- Bonsoir is a ransomware that encrypts files on the infected system and demands a ransom payment for decryption.
- BooM ransomware
- BooM is a ransomware threat known for encrypting victim files and demanding a ransom payment for decryption.
- Book of Eli credential-stealerkeyloggerscreen-capture
- This in .Net written malware is a classic information stealer.
- BookCodes RAT rat
- Also known as BookCodesTea. BookCodesRAT is a remote access trojan that uses HTTP(S) for communication.
- BoomBox downloader
- BoomBox is a downloader responsible for executing next stage components that has been used by APT29 since at least 2021.
- BoooamCrypt ransomware
- BoooamCrypt is a type of ransomware that encrypts files on infected systems, demanding a ransom from victims to restore access.
- Bootkitty wiper
- Bootkitty is a bootkit malware that has been employed in attacks against critical infrastructure sectors and leverages advanced techniques…
- Booyah ransomware
- Also known as Salami. Booyah, also known as Salami, is a ransomware family known for encrypting files and demanding a ransom to restore access.
- Borat RAT ratspywareransomware
- The Borat RAT comes bundled with its components (e.g.
- Boris HT ransomware
- Boris HT is a ransomware that encrypts user data and demands a ransom for decryption.
- Borr trojan
- Borr is a banking trojan primarily targeting financial institutions and government entities.
- BotenaGo wormexploit-kit
- According to Alien Labs, this malware targets embedded devices including routers with more than 30 exploits.
- BottomLoader downloaderloader
- BottomLoader is a malware family known primarily for its functionality as a downloader and loader.
- Bouncer rat
- Bouncer is a Remote Access Trojan (RAT) used for gaining unauthorized control over targeted systems.
- BoxCaon backdoor
- BoxCaon is a Windows backdoor that was used by IndigoZebra in a 2021 spearphishing campaign against Afghan government officials.
- Bozok rat
- Bozok is a Remote Access Trojan (RAT) that allows attackers to remotely control infected machines, enabling data theft and espionage…
- BrLock ransomware
- BrLock is a ransomware family known for encrypting files and demanding ransom payments for decryption keys.
- BrainCrypt Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- BrainLag ransomware
- BrainLag is a ransomware strain that targets various industries by encrypting files and demanding cryptocurrency for decryption keys.
- BrainTest trojanspyware
- BrainTest is a family of Android malware known for its ability to persist on infected devices by exploiting system vulnerabilities.
- Brambul wormcredential-stealer
- Also known as SORRYBRUTE. Brambul is a worm that spreads by using a list of hard-coded login credentials to launch a brute-force password attack against an SMB…
- Braodo credential-stealerspyware
- According to K7 Security Labs, Braodo Stealer is written in Python and collects all cookies and saved credentials from the browsers and…
- BrasDex trojancredential-stealer
- According to PCrisk, BraDex is a banking malware targeting Android operating systems.
- Brat rat
- Brat is a remote access trojan (RAT) known for providing attackers with access to infected systems.
- Brave Prince ratspyware
- Brave Prince is a Korean-language implant that was first observed in the wild in December 2017.
- BravoNC rat
- BravoNC is a sophisticated remote access tool (RAT) used primarily for cyber-espionage.
- Brazilian ransomware
- Brazilian is a ransomware strain based on the EDA2 project.
- Brazilian Globe ransomware
- Brazilian Globe is a ransomware strain known for targeting organizations within Brazil.
- BrbBot botnetcredential-stealer
- BrbBot is a botnet malware family primarily targeting financial services and technology sectors.
- BreachRAT ratbackdoor
- This is a backdoor which FireEye call the Breach Remote Administration Tool (BreachRAT), written in C++.
- Bread trojan
- Also known as Joker. Bread was a large-scale billing fraud malware family known for employing many different cloaking and obfuscation techniques in an attempt…
- Break out the Box cryptominer
- Also known as BOtB. This is a pentesting tool and according to the author, "BOtB is a container analysis and exploitation tool designed to be used by…
- Breakthrough loader
- There is no reference available for this family and all known samples have version 1.0.0.
- Bredolab botnetcredential-stealerdownloader
- Bredolab is a malware family primarily known for its use as a downloader.
- Briba trojanbackdoordownloader
- Briba is a trojan used by Elderwood to open a backdoor and download files on to compromised hosts.
- Brick ransomware
- Brick is a type of ransomware used by cybercriminals to encrypt victims' data and demand a ransom payment for recovery.
- BrickR ransomware
- BrickR is a ransomware that encrypts victim files and demands a ransom for their release.
- BrickerBot ddoswiper
- BrickerBot is malware that targets IoT devices, rendering them unusable by corrupting their storage and disrupting their network…
- BrittleBush trojanwiper
- BrittleBush is a sophisticated malware family targeting government and energy sectors.
- Broomstick backdoorransomware
- Also known as CLEANBOOST, CleanUp, CleanUpLoader. Oyster is a backdoor malware written in C++ that first appeared in July 2023.
- Browlock ransomware
- Browlock is a browser locker ransomware that doesn't encrypt files locally but locks the victim's browser instead, displaying a ransom…
- Bruh Wiper wiper
- Bruh Wiper is a destructive malware designed to delete data and render systems inoperable.
- Brunhilda dropper
- PRODAFT describes Brunhilda as a "Dropper as a Service" for Google Play, delivering e.g.
- BrushaLoader loader
- BrushaLoader is a malware loader known for delivering additional malicious payloads.
- BrutPOS credential-stealer
- BrutPOS is a type of malware designed to target point-of-sale systems by using brute-force attacks to steal credentials.
- Brute Ratel C4 rat
- Also known as BRc4, BOLDBADGER, BruteRatel. Brute Ratel C4 is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020.
- BtcKING ransomware
- BtcKING is a ransomware family that encrypts files on infected systems and demands payment in cryptocurrency.
- Bucbi ransomware
- Bucbi is a type of ransomware that encrypts files on the target system without changing file names or extensions.
- Bud ransomware
- Bud ransomware encrypts files on the victim's system, often demanding payment in cryptocurrency to provide the decryption key.
- Buer downloaderloader
- Also known as Buerloader, RustyBuer. Buer is a downloader sold on underground forums and used by threat actors to deliver payload malware onto target machines.
- BugWare ransomware
- BugWare is a type of ransomware malware designed to encrypt files on infected systems and demand payment for decryption keys.
- Buhtrap trojancredential-stealerbackdoor
- Also known as Ratopak. Buhtrap is a sophisticated malware family primarily targeting financial institutions and government organizations in Russia and Ukraine.
- BulbaCrypt HT ransomware
- BulbaCrypt HT is a form of ransomware designed to encrypt files on a victim's system, demanding a ransom for decryption.
- Bumblebee loaderdropper
- Also known as COLDTRAIN, SHELLSTING, Shindig. Bumblebee is a custom loader written in C++ that has been used by multiple threat actors, including possible initial access brokers, to…
- Bundestrojaner spywaretrojan
- Also known as 0zapftis, R2D2. Bundestrojaner, also known as 0zapftis or R2D2, is a government-developed spyware program used by German law enforcement for surveillance…
- BundleBot credential-stealerscreen-capturetrojan
- Bundlebot is an info stealer that abuses the single-file dotnet bundle which operates as a self-contained executable that does not require…
- Bundlore backdoor
- Also known as OSX.Bundlore, SurfBuyer. Bundlore is adware written for macOS that has been in use since at least 2015.
- Bunitu trojan
- Bunitu is a trojan that exposes infected computers to be used as a proxy for remote clients.