Malware Families page 9 of 63
6,222 malware families profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Caterpillar WebShell webshell
- Caterpillar WebShell is a self-developed Web Shell tool created by the group Volatile Cedar.
- CenterPOS trojan
- Also known as cerebrus. CenterPOS is a point-of-sale malware designed to target payment systems, primarily used in the retail and hospitality sectors.
- Central Security Treatment Organization ransomware
- Central Security Treatment Organization is a ransomware family known for targeting critical infrastructure sectors.
- Cephalo ransomware
- Cephalo is a ransomware family known for encrypting files and demanding ransom payments.
- Cephei trojanbackdoor
- Cephei is a versatile trojan with backdoor capabilities, primarily targeting the financial services and technology sectors.
- Cerber ransomware
- Also known as CRBR ENCRYPTOR. Cerber is a sophisticated ransomware family known for its as-a-service model, targeting various industries with file encryption and…
- CerberTear Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- Cerberos ransomware
- Cerberos is a sophisticated ransomware family known for encrypting victim's files and demanding cryptocurrency ransom payments for…
- Cerberus trojanbotnetcredential-stealer
- Cerberus is a banking trojan whose usage can be rented on underground forums and marketplaces.
- Cerberus RAT rat
- Cerberus RAT is an Android-based remote access tool primarily used to steal banking credentials and information.
- CetaRAT rat
- CetaRAT is a remote access trojan primarily used for cyber espionage.
- Cetus rat
- Cetus is a remote access trojan (RAT) primarily used for cyber espionage.
- ChChes trojan
- Also known as Scorpion, HAYMAKER, Ham Backdoor. ChChes is a Trojan that appears to be used exclusively by menuPass.
- ChaChi backdoorloader
- ChaChi is a Golang-based malware primarily used as a backdoor and loader.
- Chaes credential-stealerspyware
- Chaes is a multistage information stealer written in several programming languages that collects login credentials, credit card numbers…
- Chainshot exploit-kit
- Chainshot is an advanced exploit kit known for targeting vulnerabilities in technology and government sectors.
- Chalubo botnetddos
- Also known as ChaChaDDoS. Sophos describes this malware as a DDoS bot, with its name originating from ChaCha-Lua-bot due to its use of ChaCha cipher and Lua.
- Chameleon trojan
- Chameleon is an Android banking trojan that can leverage Android’s Accessibility Services to perform malicious activities.
- Chamois spywaretrojan
- Chamois is a sophisticated Android malware family primarily used for mobile ad fraud.
- Chaos backdoortrojan
- Chaos is Linux malware that compromises systems by brute force attacks against SSH services.
- Chaos (ELF) botnetddosransomware
- Multi-functional malware written in Go, targeting both Linux and Windows, evolved from elf.kaiji.
- Chaos (Windows) ransomwaretrojan
- Also known as FakeRyuk, RyukJoke, Yashma. In-development ransomware family which was released in June 2021 by an unknown threat actor.
- Chaperone backdoorkeyloggerscreen-capture
- Also known as Taj Mahal. According to Kaspersky GReAT and AMR, TajMahal is a previously unknown and technically sophisticated APT framework discovered by Kaspersky…
- Chapro
- Chapro is a type of malware with limited available information regarding its functions and targets, suggesting it may be relatively…
- Char0n rattrojan
- Char0n is a remote access trojan (RAT) often used for cyber espionage.
- ChargeWeapon ratloader
- ChargeWeapon is a remote access tool (RAT) mainly utilized for cyber espionage operations targeting technology and government sectors.
- Charger ransomwarespywaretrojan
- Charger is Android malware that steals steals contacts and SMS messages from the user's device.
- CharmPower backdoor
- CharmPower is a PowerShell-based, modular backdoor that has been used by Magic Hound since at least 2022.
- Charmant ransomware
- Charmant is a type of ransomware designed to encrypt files on an infected system, typically demanding a ransom payment for the decryption…
- Charon ransomware
- According to Secui, this ransomware was used in attacks observed against Middle Eastern government agencies and the aviation industry.
- Chartwig Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- Cheers ransomware
- Cheers is a Linux-based ransomware variant observed starting in May 2022, engineered specifically to target VMware ESXi servers.
- Cheerscrypt ransomware
- Cheerscrypt is a ransomware that was developed by Cinnamon Tempest and has been used in attacks against ESXi and Windows environments…
- Chekyshka ransomware
- Chekyshka is a type of ransomware known for encrypting user files and demanding a ransom for decryption.
- ChernoLocker ransomware
- ChernoLocker is a type of ransomware that encrypts a user's files and demands a ransom for decryption.
- Cherry Picker spywaretrojan
- Cherry Picker is a point of sale (PoS) memory scraper.
- CherryBlos credential-stealercryptominer
- CherryBlos is an Android malware that steals credentials and redirects cryptocurrency to adversary-controlled wallets.
- CherryLoader loader
- CherryLoader is a malware loader that facilitates the delivery of various payloads.
- CherryPicker POS credential-stealer
- Also known as cherry_picker, cherrypicker, cherrypickerpos. CherryPicker POS is a malware family designed to target point-of-sale systems, primarily in the retail and hospitality sectors.
- ChewBacca credential-stealerkeylogger
- ChewBacca is a point-of-sale (POS) malware that includes a memory scraper and keylogging functionality.
- Chihuahua backdoor
- Chihuahua is a backdoor malware family known for targeting financial services and government sectors.
- Chimera ransomware
- Also known as Quimera Crypter, Pashka. Chimera is a ransomware targeting mainly Germany and the USA, encrypting files and demanding ransom.
- China Chopper webshell
- China Chopper is a Web Shell hosted on Web servers to provide access back into an enterprise network that does not rely on an infected…
- ChinaJm ransomware
- ChinaJm is a type of ransomware known for encrypting files on infected systems and demanding a ransom for their decryption.
- ChinaYunLong ransomware
- ChinaYunLong is a ransomware known for targeting technology, financial services, and public sector organizations.
- Chinad
- Adware that shows advertisements using plugin techniques for popular browsers
- Chinotto (Android) spywarerat
- Chinotto is a spyware and remote access trojan (RAT) that primarily targets Android devices.
- Chinotto (Windows) rat
- Chinotto is a remote access trojan (RAT) associated with espionage activities linked to APT37, often targeting organizations in South…
- Chinoxy backdoordropper
- Chinoxy is a backdoor that has been used since at least November 2018, during the FunnyDream campaign, to gain persistence and drop…
- Chip Ransomware ransomware
- Also known as ChipLocker Ransomware. It’s directed to English speaking users, therefore is able to infect worldwide.
- Chir backdoor
- Chir is a backdoor malware primarily targeting government and technology sectors.
- Chisel (ELF) backdoor
- Chisel is an open-source project by Jaime Pillora (jpillora) that allows tunneling TCP and UDP connections via HTTP.
- Chisel (Windows) backdoor
- Chisel is an open-source project by Jaime Pillora (jpillora) that allows tunneling TCP and UDP connections via HTTP.
- ChiserClient rat
- ChiserClient is a remote access tool used for cyber espionage activities.
- Choziosi (OS X) loader
- Also known as ChromeLoader, Chropex. A loader delivering malicious Chrome and Safari extensions.
- Choziosi (Windows) spyware
- Also known as ChromeLoader. Choziosi is a browser hijacker for Chrome.
- ChrGetPdsi Stealer credential-stealer
- ChrGetPdsi is a basic infostealer written in Golang which is designed to steal browser history and logins, and targets Chrome, Edge, and…
- Christmas ransomware
- Christmas ransomware is a type of malware that encrypts files on the victim's device and demands a ransom for decryption.
- Chrome Remote Desktop
- Chrome Remote Desktop is an extension for the Google Chrome web browser that lets you setup a computer for remote access from any other…
- ChromeBack spyware
- GoSecure describes ChromeBack as a browser hijacker, redirecting traffic and serving advertisements to users.
- Chrommme backdoor
- Chrommme is a backdoor tool written using the Microsoft Foundation Class (MFC) framework that was first reported in June 2021; security…
- Chrysalis backdoorloader
- According to Rapid7, Chrysalis is a custom, feature-rich backdoor.
- Chrysaor spywarebackdoor
- Also known as JigglyPuff, Pegasus. Chrysaor, also known as Pegasus, is a sophisticated spyware developed by the NSO Group targeting iOS and Android devices.
- Chthonic trojancredential-stealer
- Also known as AndroKINS. Chthonic is a banking trojan malware that primarily targets financial institutions.
- Cinobi trojancredential-stealer
- Cinobi is a banking trojan primarily targeting financial institutions in Japan.
- Cinoshi rattrojan
- Also known as Agniane. Cinoshi, also known as Agniane, is a remote access trojan (RAT) known for targeting financial services and governmental sectors.
- Circles spyware
- Circles reportedly takes advantage of Signaling System 7 (SS7) weaknesses, the protocol suite used to route phone calls, to both track the…
- Citadel botnetcredential-stealerkeylogger
- Citadel is a banking trojan and botnet malware that primarily targets financial institutions.
- Clambling backdoor
- Clambling is a modular backdoor written in C++ that has been used by Threat Group-3390 since at least 2017.
- Clay ransomware
- Clay is a notorious ransomware family that encrypts user data and demands payment for decryption.
- ClearFake downloaderexploit-kit
- ClearFake is a malicious JavaScript framework deployed on compromised websites to deliver further malware using the drive-by download…
- Click Me Ransomware ransomware
- This is most likely to affect English speaking users, since the note is written in English.
- ClicoCrypter ransomware
- ClicoCrypter is a type of ransomware that encrypts victim's files and demands a ransom for decryption.
- ClicoCrypter-2 ransomware
- ClicoCrypter-2 is a ransomware variant that encrypts files on the infected system, demanding a ransom for data decryption.
- Client Maximus ratbackdoor
- Client Maximus is a Remote Access Trojan (RAT) used for cyber-espionage targeting sensitive sectors such as government, healthcare, and…
- ClientMesh rat
- ClientMesh is a Remote Administration Application yhich allows a user to control a number of client PCs from around the world.
- Clientor rat
- Clientor is a remote access trojan (RAT) used for espionage purposes, often targeting sectors such as government, telecommunications, and…
- ClipBanker credential-stealertrojanspyware
- The ClipBanker Trojan is known as an information stealer and spy trojan, it aims to steal and record any type of sensitive information…
- Clipog keylogger
- Clipog is a malicious program designed to record keystrokes on a compromised system, allowing attackers to capture sensitive information…
- Clipper credential-stealer
- Clipper malware is designed to intercept and redirect cryptocurrency transactions by replacing the intended wallet address with one…
- Clock ransomware
- Clock is a ransomware that, despite its classification, does not perform any file encryption.
- Clop ransomware
- Also known as Cl0p. Clop is a ransomware family that was first observed in February 2019 and has been used against retail, transportation and logistics…
- Clop (ELF) ransomware
- Also known as Cl0p. Clop (ELF) is a variant of the Clop ransomware designed to target Linux systems.
- Clop (Windows) ransomware
- Clop is a ransomware which uses the .clop extension after having encrypted the victim's files.
- Cloud Snooper backdoor
- Also known as Snoopy. Cloud Snooper is a sophisticated malware that uses a unique technique to bypass firewall restrictions and help its operators control…
- CloudAtlas spywarebackdoor
- CloudAtlas is a sophisticated cyber espionage malware used for intelligence gathering, particularly targeting government and energy…
- CloudDuke backdoorspyware
- Also known as MiniDionis, CloudLook. CloudDuke is malware that was used by APT29 in 2015.
- CloudEyE downloaderloaderdropper
- Also known as GuLoader, vbdropper. CloudEyE (initially named GuLoader) is a small VB5/6 downloader.
- CloudMensis ratspyware
- Also known as BadRAT. CloudMensis, also known as BadRAT, is a malware family targeting macOS systems.
- CloudScout spyware
- According to ESET Research, CloudScout is a toolset is capable of retrieving data from various cloud services by leveraging stolen web…
- CloudSword Ransomware ransomware
- It’s directed to English speaking users, therefore is able to infect worldwide.
- CloudWizard trojanspyware
- CloudWizard is a sophisticated Trojan designed to infiltrate cloud platforms, focusing on data exfiltration and long-term surveillance on…
- Clouded ransomware
- Clouded is a sophisticated ransomware group known for targeting various critical infrastructure sectors.
- Cmd ransomware
- Cmd is a ransomware known for encrypting files and demanding payment for decryption.
- Cmimai Stealer credential-stealer
- Cmimai Stealer is a credential-stealing malware family known for targeting sensitive information such as passwords, browser data, and…
- CoViper wiperransomware
- PCRisk notes that CoViper is yet another Coronavirus/COVID-19-themed malware infection, most likely proliferated as a file related to the…
- CoalaBot botnetdownloader
- CoalaBot is a malware family primarily used as a botnet and downloader to facilitate broader malicious campaigns.
- CobInt backdoor
- Also known as COOLPANTS. CobInt, is a self-developed backdoor of the Cobalt group.
- Cobalt Strike rat
- Also known as Agentemis, BEACON, CobaltStrike. Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute…
- CobaltMirage FRP trojan
- This Go written malware was observed during campaign of COBALT MIRAGE; it includes FRP (Fast Reverse Proxy) published by fatedier on…