Malware Families page 9 of 63

6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Caterpillar WebShell webshell
Caterpillar WebShell is a self-developed Web Shell tool created by the group Volatile Cedar.
CenterPOS trojan
Also known as cerebrus. CenterPOS is a point-of-sale malware designed to target payment systems, primarily used in the retail and hospitality sectors.
Central Security Treatment Organization ransomware
Central Security Treatment Organization is a ransomware family known for targeting critical infrastructure sectors.
Cephalo ransomware
Cephalo is a ransomware family known for encrypting files and demanding ransom payments.
Cephei trojanbackdoor
Cephei is a versatile trojan with backdoor capabilities, primarily targeting the financial services and technology sectors.
Cerber ransomware
Also known as CRBR ENCRYPTOR. Cerber is a sophisticated ransomware family known for its as-a-service model, targeting various industries with file encryption and…
CerberTear Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
Cerberos ransomware
Cerberos is a sophisticated ransomware family known for encrypting victim's files and demanding cryptocurrency ransom payments for…
Cerberus trojanbotnetcredential-stealer
Cerberus is a banking trojan whose usage can be rented on underground forums and marketplaces.
Cerberus RAT rat
Cerberus RAT is an Android-based remote access tool primarily used to steal banking credentials and information.
CetaRAT rat
CetaRAT is a remote access trojan primarily used for cyber espionage.
Cetus rat
Cetus is a remote access trojan (RAT) primarily used for cyber espionage.
ChChes trojan
Also known as Scorpion, HAYMAKER, Ham Backdoor. ChChes is a Trojan that appears to be used exclusively by menuPass.
ChaChi backdoorloader
ChaChi is a Golang-based malware primarily used as a backdoor and loader.
Chaes credential-stealerspyware
Chaes is a multistage information stealer written in several programming languages that collects login credentials, credit card numbers…
Chainshot exploit-kit
Chainshot is an advanced exploit kit known for targeting vulnerabilities in technology and government sectors.
Chalubo botnetddos
Also known as ChaChaDDoS. Sophos describes this malware as a DDoS bot, with its name originating from ChaCha-Lua-bot due to its use of ChaCha cipher and Lua.
Chameleon trojan
Chameleon is an Android banking trojan that can leverage Android’s Accessibility Services to perform malicious activities.
Chamois spywaretrojan
Chamois is a sophisticated Android malware family primarily used for mobile ad fraud.
Chaos backdoortrojan
Chaos is Linux malware that compromises systems by brute force attacks against SSH services.
Chaos (ELF) botnetddosransomware
Multi-functional malware written in Go, targeting both Linux and Windows, evolved from elf.kaiji.
Chaos (Windows) ransomwaretrojan
Also known as FakeRyuk, RyukJoke, Yashma. In-development ransomware family which was released in June 2021 by an unknown threat actor.
Chaperone backdoorkeyloggerscreen-capture
Also known as Taj Mahal. According to Kaspersky GReAT and AMR, TajMahal is a previously unknown and technically sophisticated APT framework discovered by Kaspersky…
Chapro
Chapro is a type of malware with limited available information regarding its functions and targets, suggesting it may be relatively…
Char0n rattrojan
Char0n is a remote access trojan (RAT) often used for cyber espionage.
ChargeWeapon ratloader
ChargeWeapon is a remote access tool (RAT) mainly utilized for cyber espionage operations targeting technology and government sectors.
Charger ransomwarespywaretrojan
Charger is Android malware that steals steals contacts and SMS messages from the user's device.
CharmPower backdoor
CharmPower is a PowerShell-based, modular backdoor that has been used by Magic Hound since at least 2022.
Charmant ransomware
Charmant is a type of ransomware designed to encrypt files on an infected system, typically demanding a ransom payment for the decryption…
Charon ransomware
According to Secui, this ransomware was used in attacks observed against Middle Eastern government agencies and the aviation industry.
Chartwig Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
Cheers ransomware
Cheers is a Linux-based ransomware variant observed starting in May 2022, engineered specifically to target VMware ESXi servers.
Cheerscrypt ransomware
Cheerscrypt is a ransomware that was developed by Cinnamon Tempest and has been used in attacks against ESXi and Windows environments…
Chekyshka ransomware
Chekyshka is a type of ransomware known for encrypting user files and demanding a ransom for decryption.
ChernoLocker ransomware
ChernoLocker is a type of ransomware that encrypts a user's files and demands a ransom for decryption.
Cherry Picker spywaretrojan
Cherry Picker is a point of sale (PoS) memory scraper.
CherryBlos credential-stealercryptominer
CherryBlos is an Android malware that steals credentials and redirects cryptocurrency to adversary-controlled wallets.
CherryLoader loader
CherryLoader is a malware loader that facilitates the delivery of various payloads.
CherryPicker POS credential-stealer
Also known as cherry_picker, cherrypicker, cherrypickerpos. CherryPicker POS is a malware family designed to target point-of-sale systems, primarily in the retail and hospitality sectors.
ChewBacca credential-stealerkeylogger
ChewBacca is a point-of-sale (POS) malware that includes a memory scraper and keylogging functionality.
Chihuahua backdoor
Chihuahua is a backdoor malware family known for targeting financial services and government sectors.
Chimera ransomware
Also known as Quimera Crypter, Pashka. Chimera is a ransomware targeting mainly Germany and the USA, encrypting files and demanding ransom.
China Chopper webshell
China Chopper is a Web Shell hosted on Web servers to provide access back into an enterprise network that does not rely on an infected…
ChinaJm ransomware
ChinaJm is a type of ransomware known for encrypting files on infected systems and demanding a ransom for their decryption.
ChinaYunLong ransomware
ChinaYunLong is a ransomware known for targeting technology, financial services, and public sector organizations.
Chinad
Adware that shows advertisements using plugin techniques for popular browsers
Chinotto (Android) spywarerat
Chinotto is a spyware and remote access trojan (RAT) that primarily targets Android devices.
Chinotto (Windows) rat
Chinotto is a remote access trojan (RAT) associated with espionage activities linked to APT37, often targeting organizations in South…
Chinoxy backdoordropper
Chinoxy is a backdoor that has been used since at least November 2018, during the FunnyDream campaign, to gain persistence and drop…
Chip Ransomware ransomware
Also known as ChipLocker Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
Chir backdoor
Chir is a backdoor malware primarily targeting government and technology sectors.
Chisel (ELF) backdoor
Chisel is an open-source project by Jaime Pillora (jpillora) that allows tunneling TCP and UDP connections via HTTP.
Chisel (Windows) backdoor
Chisel is an open-source project by Jaime Pillora (jpillora) that allows tunneling TCP and UDP connections via HTTP.
ChiserClient rat
ChiserClient is a remote access tool used for cyber espionage activities.
Choziosi (OS X) loader
Also known as ChromeLoader, Chropex. A loader delivering malicious Chrome and Safari extensions.
Choziosi (Windows) spyware
Also known as ChromeLoader. Choziosi is a browser hijacker for Chrome.
ChrGetPdsi Stealer credential-stealer
ChrGetPdsi is a basic infostealer written in Golang which is designed to steal browser history and logins, and targets Chrome, Edge, and…
Christmas ransomware
Christmas ransomware is a type of malware that encrypts files on the victim's device and demands a ransom for decryption.
Chrome Remote Desktop
Chrome Remote Desktop is an extension for the Google Chrome web browser that lets you setup a computer for remote access from any other…
ChromeBack spyware
GoSecure describes ChromeBack as a browser hijacker, redirecting traffic and serving advertisements to users.
Chrommme backdoor
Chrommme is a backdoor tool written using the Microsoft Foundation Class (MFC) framework that was first reported in June 2021; security…
Chrysalis backdoorloader
According to Rapid7, Chrysalis is a custom, feature-rich backdoor.
Chrysaor spywarebackdoor
Also known as JigglyPuff, Pegasus. Chrysaor, also known as Pegasus, is a sophisticated spyware developed by the NSO Group targeting iOS and Android devices.
Chthonic trojancredential-stealer
Also known as AndroKINS. Chthonic is a banking trojan malware that primarily targets financial institutions.
Cinobi trojancredential-stealer
Cinobi is a banking trojan primarily targeting financial institutions in Japan.
Cinoshi rattrojan
Also known as Agniane. Cinoshi, also known as Agniane, is a remote access trojan (RAT) known for targeting financial services and governmental sectors.
Circles spyware
Circles reportedly takes advantage of Signaling System 7 (SS7) weaknesses, the protocol suite used to route phone calls, to both track the…
Citadel botnetcredential-stealerkeylogger
Citadel is a banking trojan and botnet malware that primarily targets financial institutions.
Clambling backdoor
Clambling is a modular backdoor written in C++ that has been used by Threat Group-3390 since at least 2017.
Clay ransomware
Clay is a notorious ransomware family that encrypts user data and demands payment for decryption.
ClearFake downloaderexploit-kit
ClearFake is a malicious JavaScript framework deployed on compromised websites to deliver further malware using the drive-by download…
Click Me Ransomware ransomware
This is most likely to affect English speaking users, since the note is written in English.
ClicoCrypter ransomware
ClicoCrypter is a type of ransomware that encrypts victim's files and demands a ransom for decryption.
ClicoCrypter-2 ransomware
ClicoCrypter-2 is a ransomware variant that encrypts files on the infected system, demanding a ransom for data decryption.
Client Maximus ratbackdoor
Client Maximus is a Remote Access Trojan (RAT) used for cyber-espionage targeting sensitive sectors such as government, healthcare, and…
ClientMesh rat
ClientMesh is a Remote Administration Application yhich allows a user to control a number of client PCs from around the world.
Clientor rat
Clientor is a remote access trojan (RAT) used for espionage purposes, often targeting sectors such as government, telecommunications, and…
ClipBanker credential-stealertrojanspyware
The ClipBanker Trojan is known as an information stealer and spy trojan, it aims to steal and record any type of sensitive information…
Clipog keylogger
Clipog is a malicious program designed to record keystrokes on a compromised system, allowing attackers to capture sensitive information…
Clipper credential-stealer
Clipper malware is designed to intercept and redirect cryptocurrency transactions by replacing the intended wallet address with one…
Clock ransomware
Clock is a ransomware that, despite its classification, does not perform any file encryption.
Clop ransomware
Also known as Cl0p. Clop is a ransomware family that was first observed in February 2019 and has been used against retail, transportation and logistics…
Clop (ELF) ransomware
Also known as Cl0p. Clop (ELF) is a variant of the Clop ransomware designed to target Linux systems.
Clop (Windows) ransomware
Clop is a ransomware which uses the .clop extension after having encrypted the victim's files.
Cloud Snooper backdoor
Also known as Snoopy. Cloud Snooper is a sophisticated malware that uses a unique technique to bypass firewall restrictions and help its operators control…
CloudAtlas spywarebackdoor
CloudAtlas is a sophisticated cyber espionage malware used for intelligence gathering, particularly targeting government and energy…
CloudDuke backdoorspyware
Also known as MiniDionis, CloudLook. CloudDuke is malware that was used by APT29 in 2015.
CloudEyE downloaderloaderdropper
Also known as GuLoader, vbdropper. CloudEyE (initially named GuLoader) is a small VB5/6 downloader.
CloudMensis ratspyware
Also known as BadRAT. CloudMensis, also known as BadRAT, is a malware family targeting macOS systems.
CloudScout spyware
According to ESET Research, CloudScout is a toolset is capable of retrieving data from various cloud services by leveraging stolen web…
CloudSword Ransomware ransomware
It’s directed to English speaking users, therefore is able to infect worldwide.
CloudWizard trojanspyware
CloudWizard is a sophisticated Trojan designed to infiltrate cloud platforms, focusing on data exfiltration and long-term surveillance on…
Clouded ransomware
Clouded is a sophisticated ransomware group known for targeting various critical infrastructure sectors.
Cmd ransomware
Cmd is a ransomware known for encrypting files and demanding payment for decryption.
Cmimai Stealer credential-stealer
Cmimai Stealer is a credential-stealing malware family known for targeting sensitive information such as passwords, browser data, and…
CoViper wiperransomware
PCRisk notes that CoViper is yet another Coronavirus/COVID-19-themed malware infection, most likely proliferated as a file related to the…
CoalaBot botnetdownloader
CoalaBot is a malware family primarily used as a botnet and downloader to facilitate broader malicious campaigns.
CobInt backdoor
Also known as COOLPANTS. CobInt, is a self-developed backdoor of the Cobalt group.
Cobalt Strike rat
Also known as Agentemis, BEACON, CobaltStrike. Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute…
CobaltMirage FRP trojan
This Go written malware was observed during campaign of COBALT MIRAGE; it includes FRP (Fast Reverse Proxy) published by fatedier on…