Malware Families page 8 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

BunnyLoader loader
BunnyLoader is a type of loader malware that facilitates the delivery of additional malicious payloads onto a compromised system.
Buran ransomwareexploit-kit
Buran is a new version of the Vega ransomware strain (a.k.a.
BusyGasper spyware
BusyGasper is Android spyware that has been in use since May 2016.
Buterat spywaretrojan
Also known as spyvoltar. Buterat, also known as Spyvoltar, is a malware family that functions as both spyware and a trojan.
BuyUnlockCode ransomware
BuyUnlockCode is a ransomware variant that encrypts files on an infected system and demands a ransom for decryption.
Buzus trojan
Also known as Yimfoca. Buzus, also known as Yimfoca, is a Trojan malware family that primarily targets Microsoft Windows systems.
Bvp47 backdoor
Pangu Lab discovered this backdoor during a forensic investigation in 2013.
BypassBoss trojanbackdoor
BypassBoss is a trojan that incorporates backdoor capabilities, primarily targeting government and financial services sectors.
C0hen Locker ransomware
C0hen Locker is a ransomware family that encrypts files and demands a ransom from victims, primarily targeting financial services…
CA$HOUT ransomware
CA$HOUT is a ransomware targeting primarily the financial services sector.
CACTUSTORCH trojanloader
According to the GitHub repo, CACTUSTORCH is a JavaScript and VBScript shellcode launcher.
CALENDAR backdoor
CALENDAR is malware used by APT1 that mimics legitimate Gmail Calendar traffic.
CALMTHORN rat
CALMTHORN is a remote access tool commonly used by advanced persistent threat groups.
CANONSTAGER loader
CANONSTAGER is a loader known to be leveraged by Mustang Panda and was first observed utilized in 2025.
CARROTBALL downloader
CARROTBALL is an FTP downloader utility that has been in use since at least 2019.
CARROTBAT dropper
CARROTBAT is a customized dropper that has been in use since at least 2017.
CASHY200 rat
CASHY200 is a Remote Access Trojan (RAT) used primarily to target financial services and government sectors.
CASTLELOADER loader
CastleLoader payloads are distributed as portable executables containing an embedded shellcode, which then invokes the main module of the…
CASTLETAP backdoor
CASTLETAP is an ICMP port knocking backdoor that has been installed on compromised FortiGate firewalls by UNC3886.
CCBkdr backdoor
CCBkdr is malware that was injected into a signed version of CCleaner and distributed from CCleaner's distribution website.
CCECrypt ransomware
CCECrypt is a type of ransomware that encrypts files on the victim's computer, demanding a ransom for decryption.
CCleaner Backdoor backdoortrojan
Also known as DIRTCLEANER. According to CrowdStrike, this backdoor was discovered embedded in the legitimate, signed version of CCleaner 5.33, and thus constitutes a…
CDDS backdoor
Also known as Macma. Google TAG has observed this malware being delivered via watering hole attacks using 0-day exploits, targeting visitors to Hong Kong…
CDRThief spyware
CDRThief is a malware specifically designed to target Linux-based VoIP softswitches.
CDorked backdoor
Also known as CDorked.A. This is in the same family as eBury, Calfbot, and is also likely related to DarkLeech
CEELOADER downloaderloader
Mandiant characterizes this malware as a downloader and shellcode stager.
CHAIRSMACK rat
CHAIRSMACK is a remote access trojan (RAT) associated with cyber-espionage campaigns targeting government and technology sectors primarily…
CHCH ransomware
CHCH is a Ransomware spotted in the wild in December 2019.
CHEESETRAY backdoor
Also known as CROWDEDFLOUNDER. CHEESETRAY is a sophisticated proxy-aware backdoor that can operate in both active and passive mode depending on the passed command-line…
CHEMISTGAMES backdoor
CHEMISTGAMES is a modular backdoor that has been deployed by Sandworm Team.
CHERRYSPY backdoor
According to CERT-UA, this is a PyArmor-protected backdoor capable of execution dynamically downloaded Python code.
CHIMNEYSWEEP backdoor
CHIMNEYSWEEP is a backdoor malware that was deployed during HomeLand Justice along with ROADSWEEP ransomware, and has been used to target…
CHOPSTICK backdoorrat
Also known as Backdoor.SofacyX, SPLM, Xagent. CHOPSTICK is a malware family of modular backdoors used by APT28.
CIA RAT rat
CIA RAT is a remote access trojan reportedly used for cyber espionage, capable of executing arbitrary commands and exfiltrating sensitive…
CIA Special Agent 767 Ransomware (FAKE!!!) ransomware
It’s directed to English speaking users, therefore is able to infect users all over the world.
CLAIMLOADER loader
CLAIMLOADER is a malware variant that frequently accompanies legitimate executables that are used for DLL side-loading known to be…
CLASSFON trojanbackdoor
CLASSFON is a sophisticated malware used as a backdoor and trojan primarily targeting government and financial institutions, allegedly for…
CLEANTOAD wiper
CLEANTOAD is a disruption tool that will delete file system artifacts, including those related to BLINDTOAD, and will run after a date…
CLOUDBURST downloaderloadertrojan
Also known as NickelLoader. CLOUDBURST aka NickelLoader is an HTTP(S) downloader.
CMS8000 Backdoor backdoor
According to CISA, this is an implant found in firmware for the Contec CMS8000, a patient monitor used by the Healthcare and Public Health…
CMSBrute credential-stealer
CMSBrute is a malware family targeting content management systems (CMS) with brute-force attacks.
CMSTAR trojanrat
Also known as meciv. CMSTAR, also known as meciv, is a sophisticated Trojan and RAT used primarily for cyber-espionage.
CNH ransomware
CNH is a ransomware used in cybercriminal activities, targeting critical industries like financial services, healthcare, and manufacturing.
COATHANGER rat
COATHANGER is a remote access tool (RAT) targeting FortiGate networking appliances.
COMpfun rat
Also known as Reductor RAT. COMpfun, also known as Reductor RAT, is a remote access trojan used in cyber espionage operations.
COOKBOX backdoor
According to CERT-UA, COOKBOX is a PowerShell script that implements the functionality of downloading and executing PowerShell cmdlets.
COOKIESNATCH credential-stealer
COOKIESNATCH is a malware used to steal cookies, particularly targeting web credentials.
CORALDECK spyware
CORALDECK is an exfiltration tool used by the North Korean threat actor APT37.
CORESHELL downloader
Also known as Sofacy, SOURFACE. CORESHELL is a downloader used by APT28. The older versions of this malware are known as SOURFACE and newer versions as CORESHELL.
CRAT rat
According to Cisco Talos, CRAT is a remote access trojan with plugin capabilites, used by Lazarus since at least May 2020.
CREAMSICLE trojanransomware
CREAMSICLE is a malware family associated with financial and government-targeted attacks.
CROSSWALK backdoor
Also known as Motnug, ProxIP, TOMMYGUN. According to FireEye, CROSSWALK is a skeletal, modular backdoor capable of system survey and adding modules in response to C&C replies.
CRYPTOSLAY ransomware
CRYPTOSLAY is a ransomware family that encrypts files on infected systems, demanding cryptocurrency payments for decryption keys.
CSGO Ransomware ransomware
Supposed joke ransomware, decrypt when running an exectable with the string "csgo"
CSP ransomware
CSP is a ransomware that encrypts files on infected systems, demanding a ransom for decryption keys.
CSPY Downloader downloader
CSPY Downloader is a tool designed to evade analysis and download additional payloads used by Kimsuky.
CTB Locker ransomware
CTB Locker is a form of ransomware that encrypts files on the victim's system, demanding a ransom payment in bitcoin for the decryption key.
CTB-Faker ransomware
Also known as Citroni. CTB-Faker, also known as Citroni, is a type of ransomware designed to encrypt files on a victim's computer, demanding payment for…
CTB-Locker Original ransomware
CTB-Locker Original is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption.
CTB-Locker WEB ransomware
CTB-Locker WEB is a variant of the CTB-Locker ransomware that specifically uses websites for its operations.
CTF ransomware
Ransomware
CTOS
CTOS is a malware family with no available description, indicating potential undisclosed functionalities or targets.
CVLocker ransomware
CVLocker is a type of ransomware that encrypts victims' files and demands a ransom for their decryption.
CYR-Locker Ransomware (FAKE) ransomware
This is most likely to affect English speaking users, since the note is written in English.
CabArt rat
CabArt is a remote access trojan (RAT) primarily used for cyber-espionage, targeting government and defense sectors.
Cachedump credential-stealer
Cachedump is a publicly-available tool that program extracts cached password hashes from a system’s registry.
CaddyWiper wiper
Also known as KillDisk.NCX. CaddyWiper is a destructive data wiper that has been used in attacks against organizations in Ukraine since at least March 2022.
Cadelspy backdoor
Also known as Cadelle. Cadelspy is a backdoor that has been used by APT39.
Caesar RAT rat
Caesar is an HTTP-based RAT that allows you to remotely control devices directly from your browser.
CageyChameleon backdoorrat
Also known as Cabbage RAT. CageyChameleon Malware is a VBS-based backdoor which has the capability to enumerate the list of running processes and check for the…
CainXPii ransomware
CainXPii is a ransomware variant that encrypts files and demands a ransom for decryption.
Caja botnettrojan
Linux malware cross-compiled for x86, MIPS, ARM.
Caligula botnetddos
According to Avast Decoded, Caligula is an IRC multiplatform bot that allows to perform DDoS attacks.
Calisto trojanbackdoor
Calisto is a macOS Trojan that opens a backdoor on the compromised machine.
CallMe trojan
CallMe is a Trojan designed to run on Apple OSX.
Cameleon backdoorrat
Also known as StormKitty. PWC describes this malware as a backdoor, capable of file management, upload and download of files, and execution of commands.
Caminho downloaderloader
Also known as VMDetectLoader, Katz Stealer Loader. Caminho is a downloader that has been used by threat actors since at least 2025 to deliver various strains of malware such as XWorm.
CamuBot trojan
There is no lot of IOCs in this article so we take one sample and try to extract some interesting IOCs, our findings below : CamuBot…
Cancer Ransomware FAKE
It’s directed to English speaking users, therefore is able to infect worldwide.
CanisterWorm
CanisterWorm is a self-propagating malware that has been used by TeamPCP in credential harvesting and software supply chain campaigns…
Cannibal Rat rat
Cannibal Rat is a python written remote access trojan with 4 versions as of March 2018.
Cannon trojan
Cannon is a Trojan with variants written in C# and Delphi.
Capoae cryptominer
Capoae is a XMRig-based mining malware developed in the Go programming language, designed to exploit system resources for cryptocurrency…
CapraRAT rat
According to PCrisk, CapraRAT is the name of an Android remote access trojan (RAT), possibly a modified version of another (open-source)…
Carbanak ratbackdoor
Also known as Anunak, Sekur RAT. Carbanak is a full-featured, remote backdoor used by a group of the same name (Carbanak).
Carberp trojancredential-stealer
Carberp is a credential and information stealing malware that has been active since at least 2009.
Carbon backdoor
Carbon is a sophisticated, second-stage backdoor and framework that can be used to steal sensitive information from victims.
CarbonSteal spyware
CarbonSteal is one of a family of four surveillanceware tools that share a common C2 infrastructure.
Cardinal rat
Cardinal is a remote access trojan (RAT) discovered by Palo Alto Networks in 2017 and has been active for over two years.
Cardinal RAT rat
Cardinal RAT is a potentially low volume remote access trojan (RAT) observed since December 2015.
Careto (OS X) spywarerat
Also known as Appetite, Mask. Careto, also known as the Mask and Appetite, is an advanced spyware known to target high-profile victims including government…
Careto (Windows) spywareratbackdoor
Also known as TheMask. Careto, also known as TheMask, is a sophisticated malware family used for cyber-espionage operations primarily targeting government…
CargoBay trojandownloader
CargoBay is a newer malware family which was first observed in 2022 and is notable for being written in the Rust language.
Casa RAT rat
Casa RAT is a remote access trojan known to target government and public sector organizations as well as educational institutions.
CashRansomware ransomware
CashRansomware is a type of ransomware known for encrypting files and demanding a ransom payment in exchange for the decryption key.
Casper spyware
ESET describes Casper as a well-developed reconnaissance tool, making extensive efforts to remain unseen on targeted machines.
Cassetto Ransomware ransomware
Michael Gillespie saw an encrypted file uploaded to ID Ransomware that appends the .cassetto extension and drops a ransom note named…
Casso ransomware
Casso is known as a ransomware family used by cybercriminals to encrypt victims' files and demand a ransom for decryption keys.
Catchamas trojancredential-stealer
Catchamas is a Windows Trojan that steals information from compromised systems.
Catelites botnettrojancredential-stealer
Catelites Bot (identified by Avast and SfyLabs in December 2017) is an Android trojan, with ties to CronBot.