Malware Families page 8 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- BunnyLoader loader
- BunnyLoader is a type of loader malware that facilitates the delivery of additional malicious payloads onto a compromised system.
- Buran ransomwareexploit-kit
- Buran is a new version of the Vega ransomware strain (a.k.a.
- BusyGasper spyware
- BusyGasper is Android spyware that has been in use since May 2016.
- Buterat spywaretrojan
- Also known as spyvoltar. Buterat, also known as Spyvoltar, is a malware family that functions as both spyware and a trojan.
- BuyUnlockCode ransomware
- BuyUnlockCode is a ransomware variant that encrypts files on an infected system and demands a ransom for decryption.
- Buzus trojan
- Also known as Yimfoca. Buzus, also known as Yimfoca, is a Trojan malware family that primarily targets Microsoft Windows systems.
- Bvp47 backdoor
- Pangu Lab discovered this backdoor during a forensic investigation in 2013.
- BypassBoss trojanbackdoor
- BypassBoss is a trojan that incorporates backdoor capabilities, primarily targeting government and financial services sectors.
- C0hen Locker ransomware
- C0hen Locker is a ransomware family that encrypts files and demands a ransom from victims, primarily targeting financial services…
- CA$HOUT ransomware
- CA$HOUT is a ransomware targeting primarily the financial services sector.
- CACTUSTORCH trojanloader
- According to the GitHub repo, CACTUSTORCH is a JavaScript and VBScript shellcode launcher.
- CALENDAR backdoor
- CALENDAR is malware used by APT1 that mimics legitimate Gmail Calendar traffic.
- CALMTHORN rat
- CALMTHORN is a remote access tool commonly used by advanced persistent threat groups.
- CANONSTAGER loader
- CANONSTAGER is a loader known to be leveraged by Mustang Panda and was first observed utilized in 2025.
- CARROTBALL downloader
- CARROTBALL is an FTP downloader utility that has been in use since at least 2019.
- CARROTBAT dropper
- CARROTBAT is a customized dropper that has been in use since at least 2017.
- CASHY200 rat
- CASHY200 is a Remote Access Trojan (RAT) used primarily to target financial services and government sectors.
- CASTLELOADER loader
- CastleLoader payloads are distributed as portable executables containing an embedded shellcode, which then invokes the main module of the…
- CASTLETAP backdoor
- CASTLETAP is an ICMP port knocking backdoor that has been installed on compromised FortiGate firewalls by UNC3886.
- CCBkdr backdoor
- CCBkdr is malware that was injected into a signed version of CCleaner and distributed from CCleaner's distribution website.
- CCECrypt ransomware
- CCECrypt is a type of ransomware that encrypts files on the victim's computer, demanding a ransom for decryption.
- CCleaner Backdoor backdoortrojan
- Also known as DIRTCLEANER. According to CrowdStrike, this backdoor was discovered embedded in the legitimate, signed version of CCleaner 5.33, and thus constitutes a…
- CDDS backdoor
- Also known as Macma. Google TAG has observed this malware being delivered via watering hole attacks using 0-day exploits, targeting visitors to Hong Kong…
- CDRThief spyware
- CDRThief is a malware specifically designed to target Linux-based VoIP softswitches.
- CDorked backdoor
- Also known as CDorked.A. This is in the same family as eBury, Calfbot, and is also likely related to DarkLeech
- CEELOADER downloaderloader
- Mandiant characterizes this malware as a downloader and shellcode stager.
- CHAIRSMACK rat
- CHAIRSMACK is a remote access trojan (RAT) associated with cyber-espionage campaigns targeting government and technology sectors primarily…
- CHCH ransomware
- CHCH is a Ransomware spotted in the wild in December 2019.
- CHEESETRAY backdoor
- Also known as CROWDEDFLOUNDER. CHEESETRAY is a sophisticated proxy-aware backdoor that can operate in both active and passive mode depending on the passed command-line…
- CHEMISTGAMES backdoor
- CHEMISTGAMES is a modular backdoor that has been deployed by Sandworm Team.
- CHERRYSPY backdoor
- According to CERT-UA, this is a PyArmor-protected backdoor capable of execution dynamically downloaded Python code.
- CHIMNEYSWEEP backdoor
- CHIMNEYSWEEP is a backdoor malware that was deployed during HomeLand Justice along with ROADSWEEP ransomware, and has been used to target…
- CHOPSTICK backdoorrat
- Also known as Backdoor.SofacyX, SPLM, Xagent. CHOPSTICK is a malware family of modular backdoors used by APT28.
- CIA RAT rat
- CIA RAT is a remote access trojan reportedly used for cyber espionage, capable of executing arbitrary commands and exfiltrating sensitive…
- CIA Special Agent 767 Ransomware (FAKE!!!) ransomware
- It’s directed to English speaking users, therefore is able to infect users all over the world.
- CLAIMLOADER loader
- CLAIMLOADER is a malware variant that frequently accompanies legitimate executables that are used for DLL side-loading known to be…
- CLASSFON trojanbackdoor
- CLASSFON is a sophisticated malware used as a backdoor and trojan primarily targeting government and financial institutions, allegedly for…
- CLEANTOAD wiper
- CLEANTOAD is a disruption tool that will delete file system artifacts, including those related to BLINDTOAD, and will run after a date…
- CLOUDBURST downloaderloadertrojan
- Also known as NickelLoader. CLOUDBURST aka NickelLoader is an HTTP(S) downloader.
- CMS8000 Backdoor backdoor
- According to CISA, this is an implant found in firmware for the Contec CMS8000, a patient monitor used by the Healthcare and Public Health…
- CMSBrute credential-stealer
- CMSBrute is a malware family targeting content management systems (CMS) with brute-force attacks.
- CMSTAR trojanrat
- Also known as meciv. CMSTAR, also known as meciv, is a sophisticated Trojan and RAT used primarily for cyber-espionage.
- CNH ransomware
- CNH is a ransomware used in cybercriminal activities, targeting critical industries like financial services, healthcare, and manufacturing.
- COATHANGER rat
- COATHANGER is a remote access tool (RAT) targeting FortiGate networking appliances.
- COMpfun rat
- Also known as Reductor RAT. COMpfun, also known as Reductor RAT, is a remote access trojan used in cyber espionage operations.
- COOKBOX backdoor
- According to CERT-UA, COOKBOX is a PowerShell script that implements the functionality of downloading and executing PowerShell cmdlets.
- COOKIESNATCH credential-stealer
- COOKIESNATCH is a malware used to steal cookies, particularly targeting web credentials.
- CORALDECK spyware
- CORALDECK is an exfiltration tool used by the North Korean threat actor APT37.
- CORESHELL downloader
- Also known as Sofacy, SOURFACE. CORESHELL is a downloader used by APT28. The older versions of this malware are known as SOURFACE and newer versions as CORESHELL.
- CRAT rat
- According to Cisco Talos, CRAT is a remote access trojan with plugin capabilites, used by Lazarus since at least May 2020.
- CREAMSICLE trojanransomware
- CREAMSICLE is a malware family associated with financial and government-targeted attacks.
- CROSSWALK backdoor
- Also known as Motnug, ProxIP, TOMMYGUN. According to FireEye, CROSSWALK is a skeletal, modular backdoor capable of system survey and adding modules in response to C&C replies.
- CRYPTOSLAY ransomware
- CRYPTOSLAY is a ransomware family that encrypts files on infected systems, demanding cryptocurrency payments for decryption keys.
- CSGO Ransomware ransomware
- Supposed joke ransomware, decrypt when running an exectable with the string "csgo"
- CSP ransomware
- CSP is a ransomware that encrypts files on infected systems, demanding a ransom for decryption keys.
- CSPY Downloader downloader
- CSPY Downloader is a tool designed to evade analysis and download additional payloads used by Kimsuky.
- CTB Locker ransomware
- CTB Locker is a form of ransomware that encrypts files on the victim's system, demanding a ransom payment in bitcoin for the decryption key.
- CTB-Faker ransomware
- Also known as Citroni. CTB-Faker, also known as Citroni, is a type of ransomware designed to encrypt files on a victim's computer, demanding payment for…
- CTB-Locker Original ransomware
- CTB-Locker Original is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
- CTB-Locker WEB ransomware
- CTB-Locker WEB is a variant of the CTB-Locker ransomware that specifically uses websites for its operations.
- CTF ransomware
- Ransomware
- CTOS
- CTOS is a malware family with no available description, indicating potential undisclosed functionalities or targets.
- CVLocker ransomware
- CVLocker is a type of ransomware that encrypts victims' files and demands a ransom for their decryption.
- CYR-Locker Ransomware (FAKE) ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- CabArt rat
- CabArt is a remote access trojan (RAT) primarily used for cyber-espionage, targeting government and defense sectors.
- Cachedump credential-stealer
- Cachedump is a publicly-available tool that program extracts cached password hashes from a system’s registry.
- CaddyWiper wiper
- Also known as KillDisk.NCX. CaddyWiper is a destructive data wiper that has been used in attacks against organizations in Ukraine since at least March 2022.
- Cadelspy backdoor
- Also known as Cadelle. Cadelspy is a backdoor that has been used by APT39.
- Caesar RAT rat
- Caesar is an HTTP-based RAT that allows you to remotely control devices directly from your browser.
- CageyChameleon backdoorrat
- Also known as Cabbage RAT. CageyChameleon Malware is a VBS-based backdoor which has the capability to enumerate the list of running processes and check for the…
- CainXPii ransomware
- CainXPii is a ransomware variant that encrypts files and demands a ransom for decryption.
- Caja botnettrojan
- Linux malware cross-compiled for x86, MIPS, ARM.
- Caligula botnetddos
- According to Avast Decoded, Caligula is an IRC multiplatform bot that allows to perform DDoS attacks.
- Calisto trojanbackdoor
- Calisto is a macOS Trojan that opens a backdoor on the compromised machine.
- CallMe trojan
- CallMe is a Trojan designed to run on Apple OSX.
- Cameleon backdoorrat
- Also known as StormKitty. PWC describes this malware as a backdoor, capable of file management, upload and download of files, and execution of commands.
- Caminho downloaderloader
- Also known as VMDetectLoader, Katz Stealer Loader. Caminho is a downloader that has been used by threat actors since at least 2025 to deliver various strains of malware such as XWorm.
- CamuBot trojan
- There is no lot of IOCs in this article so we take one sample and try to extract some interesting IOCs, our findings below : CamuBot…
- Cancer Ransomware FAKE
- It’s directed to English speaking users, therefore is able to infect worldwide.
- CanisterWorm
- CanisterWorm is a self-propagating malware that has been used by TeamPCP in credential harvesting and software supply chain campaigns…
- Cannibal Rat rat
- Cannibal Rat is a python written remote access trojan with 4 versions as of March 2018.
- Cannon trojan
- Cannon is a Trojan with variants written in C# and Delphi.
- Capoae cryptominer
- Capoae is a XMRig-based mining malware developed in the Go programming language, designed to exploit system resources for cryptocurrency…
- CapraRAT rat
- According to PCrisk, CapraRAT is the name of an Android remote access trojan (RAT), possibly a modified version of another (open-source)…
- Carbanak ratbackdoor
- Also known as Anunak, Sekur RAT. Carbanak is a full-featured, remote backdoor used by a group of the same name (Carbanak).
- Carberp trojancredential-stealer
- Carberp is a credential and information stealing malware that has been active since at least 2009.
- Carbon backdoor
- Carbon is a sophisticated, second-stage backdoor and framework that can be used to steal sensitive information from victims.
- CarbonSteal spyware
- CarbonSteal is one of a family of four surveillanceware tools that share a common C2 infrastructure.
- Cardinal rat
- Cardinal is a remote access trojan (RAT) discovered by Palo Alto Networks in 2017 and has been active for over two years.
- Cardinal RAT rat
- Cardinal RAT is a potentially low volume remote access trojan (RAT) observed since December 2015.
- Careto (OS X) spywarerat
- Also known as Appetite, Mask. Careto, also known as the Mask and Appetite, is an advanced spyware known to target high-profile victims including government…
- Careto (Windows) spywareratbackdoor
- Also known as TheMask. Careto, also known as TheMask, is a sophisticated malware family used for cyber-espionage operations primarily targeting government…
- CargoBay trojandownloader
- CargoBay is a newer malware family which was first observed in 2022 and is notable for being written in the Rust language.
- Casa RAT rat
- Casa RAT is a remote access trojan known to target government and public sector organizations as well as educational institutions.
- CashRansomware ransomware
- CashRansomware is a type of ransomware known for encrypting files and demanding a ransom payment in exchange for the decryption key.
- Casper spyware
- ESET describes Casper as a well-developed reconnaissance tool, making extensive efforts to remain unseen on targeted machines.
- Cassetto Ransomware ransomware
- Michael Gillespie saw an encrypted file uploaded to ID Ransomware that appends the .cassetto extension and drops a ransom note named…
- Casso ransomware
- Casso is known as a ransomware family used by cybercriminals to encrypt victims' files and demand a ransom for decryption keys.
- Catchamas trojancredential-stealer
- Catchamas is a Windows Trojan that steals information from compromised systems.
- Catelites botnettrojancredential-stealer
- Catelites Bot (identified by Avast and SfyLabs in December 2017) is an Android trojan, with ties to CronBot.