Malware

50 named threats: which were viruses and which were not?

A careful A–Z directory of 50 named computer viruses and malware families, with aliases, classifications, historical context and safe response guidance.

Original conceptual illustration showing named malware directory and virus classification without embedded text or logos

The clearest file-infecting viruses in this directory are Neshta, Parite, Sality and Virut. Melissa is a Word macro virus, while ILOVEYOU was described by the U.S. Government Accountability Office as both a virus and a worm. Most of the other names are worms, Trojans, ransomware, infostealers, loaders, botnets, rootkits or wipers—not file-infecting viruses.

What is the difference between a virus and malware?

Malware is the umbrella term for malicious software. A virus is one subtype: it normally inserts code into a host file, document or boot area and depends on that carrier being executed or opened. A worm is designed to replicate or propagate across networks or removable media; it may not need a host file. A Trojan pretends to be useful or benign, or arrives through a deceptive delivery chain. These categories can overlap in one incident, but they answer different questions about how a threat works.

A name can also describe a campaign, family, variant or vendor detection label rather than one immutable program. “LockBit 3.0,” for example, is a version name associated with the LockBit family; “QakBot,” “QBot” and “Pinkslipbot” are associated names in public reporting. Treating every alias as a separate virus exaggerates the count and makes a directory harder to use.

How should you use this A–Z malware directory?

Start with the type column if you are learning terminology. Use the reader context column to understand what the name is useful for: a historic email lesson, an enterprise detection investigation, a file-infection question or a family-name lookup. The directory does not provide malware samples, execution instructions, exploit steps or guaranteed removal advice.

A detection name alone does not prove that a device is infected. Confirm the product, file path, alert time, affected account and surrounding telemetry with the security tool that raised the alert. For an organization, preserve relevant logs and follow the incident-response process. For a home device, disconnect it from sensitive accounts where appropriate, update trusted security software and seek qualified support before deleting evidence or resetting the system.

Which names in this list are genuine file-infecting viruses?

Four entries are especially clear examples of file-infecting viruses in the cited Microsoft threat records: Neshta prepends itself to Windows executable files; Parite is a polymorphic file-infecting family targeting executable files; Sality is a Windows file-infecting virus family; and Virut is described as a polymorphic, memory-resident file-infecting virus. These are not interchangeable with ransomware or a remote-access Trojan simply because an antivirus product may use the word “virus” in a detection label.

Melissa is a different kind of virus: the FBI describes the 1999 incident as a Word macro virus that used Outlook to send messages. ILOVEYOU sits at a boundary: the 2000 GAO testimony calls it both a virus and a worm because it combined file manipulation with self-propagation through email. MyDoom is often casually called a virus, but Microsoft’s family entry describes it as a mass-mailing worm. These distinctions are useful when explaining spread, evidence and response.

Are these names current threats or historical examples?

They are a mixture. Some names are primarily historical records; others remain family names used in public intelligence or security detections. The evidence used for this article establishes identity, broad type, aliases or documented historical behavior—not a current prevalence ranking, active campaign, monthly search volume or 2026 outbreak claim. A MITRE ATT&CK software page is evidence that a named software family is tracked in open reporting; it is not, by itself, proof that the family is active everywhere now.

The four CYBERoinfo historical records already live for Stuxnet, Mirai, WannaCry and NotPetya are linked only as historical context. They should not be read as a claim that those incidents are recurring. The directory intentionally avoids reproducing their incident timelines.

50 computer virus and malware names, A–Z

The entries below are the complete 50-name set from the private page plan. “Virus” in a search query is treated as reader language; the type field is the editorial classification. Aliases are consolidated rather than counted as extra families.

  • 1. AcidRain — Modem/router wiper. A destructive Linux/ELF malware name associated with wiping modem and router devices. It belongs in a device-disruption discussion, not a file-virus list; the underlying evidence does not establish current prevalence.
  • 2. Agent Tesla — Spyware Trojan. A Windows information-stealing and remote-access family often discussed in connection with credential and data collection. “Trojan” describes its delivery and role; it is not a self-replicating file virus.
  • 3. Akira — Ransomware. A ransomware family name used in incident-response and extortion reporting. Readers researching it should focus on containment, identity protection and recovery rather than assume that every alert represents an active intrusion.
  • 4. Astaroth — Banking Trojan. A banking-malware name associated with credential theft and execution through a delivery chain. It illustrates why a Trojan can be financially focused without being a virus that infects other files.
  • 5. Azorult — Information-stealing Trojan. An infostealing Trojan associated with collecting browser, credential and other system information. The name is useful in alert triage; a product label does not by itself show what data, if any, left a device.
  • 6. Bad Rabbit — Self-propagating ransomware. A ransomware name associated with propagation behavior, often used as a historical example of how file-locking and worm-like spread can appear together. The combination does not make it a classic file-infecting virus.
  • 7. BlackCat — Ransomware. A family name used for ransomware operations and variants. It is an extortion and availability concern; readers should use verified incident guidance and backups, not rely on old “decryptor” promises.
  • 8. Bumblebee — Malware loader. A loader name: its significance is the delivery of additional payloads, not self-replication. In an investigation, the loader may be one stage in a larger chain, so endpoint and identity evidence matter.
  • 9. Clop — Ransomware. A ransomware family associated in public reporting with file-access disruption and data-extortion cases. It is not a file virus, and a historical name should not be turned into an unsupported current-activity claim.
  • 10. Conficker — Windows worm. A named Windows worm and a useful example of network propagation through a historically exploited Windows vulnerability. This directory establishes the classification and reader context without claiming an active outbreak.
  • 11. Conti — Ransomware. A ransomware family name that appears in historical incident and leak reporting. Treat it as a family identifier, not as a promise that every “Conti” reference describes the same build, operator or current campaign.
  • 12. Dridex — Banking Trojan. A banking Trojan associated with credential theft and malicious delivery chains. The name helps readers interpret older intelligence reports; it does not mean a detected file is necessarily Dridex without corroborating evidence.
  • 13. Dyre — Banking Trojan. A historically tracked banking-Trojan family. Its value here is as an example of malware built around financial-account theft, not as evidence of a present-day outbreak or a file-infecting virus.
  • 14. Emotet — Modular loader and banking malware. A modular malware family whose roles and components have changed across reporting. It is best understood as a delivery and access concern; the family name should not be treated as one identical sample over time.
  • 15. Gootloader — JavaScript-based malware loader. A loader associated with malicious JavaScript delivery and follow-on payloads. The entry is relevant to defenders reviewing script execution and initial access, not to readers looking for a classic virus that modifies executable files.
  • 16. Grandoreiro — Banking Trojan. A banking-Trojan family name used in public threat intelligence. It is a financial-theft example and should be separated from generic “virus” wording when explaining how a detection may affect a user.
  • 17. HermeticWiper — Destructive wiper. A wiper name associated with destructive data or system impact. Wipers aim to damage availability or integrity rather than encrypt files for a normal ransom workflow, and they are not file-infecting viruses.
  • 18. IcedID — Banking malware and loader. A family associated with banking theft and later delivery roles in public reporting. The dual description is intentional: malware families can be used in more than one stage, while a reader still needs to know it is not a virus by default.
  • 19. ILOVEYOU — Email worm/virus hybrid. The 2000 historical case combined email self-propagation with file manipulation. GAO explicitly described it as both a virus and a worm. That hybrid label is more accurate than presenting it as a generic modern “virus attack.”
  • 20. LockBit 3.0 — Ransomware family variant. A version name within the LockBit family, not automatically a separate family or separate page. Aliases and variant labels should be consolidated so that readers do not mistake one operating line for several unrelated viruses.
  • 21. LoJax — UEFI rootkit. A rootkit name associated with persistence below or alongside the operating system boot chain. It is a firmware-level security concern and a clear example of why “malware” includes much more than file infection.
  • 22. Lumma Stealer — Infostealer. An information-stealing family name associated with credential and browser-data theft. If an alert names it, prioritize account protection, session review and qualified forensic advice; do not infer successful exfiltration from the label alone.
  • 23. Maze — Ransomware. A ransomware family name associated with data-access disruption and extortion reporting. It belongs under ransomware rather than virus taxonomy, and historical descriptions should not be used as a current incident diagnosis.
  • 24. Melissa — Word macro virus and email-spreading malware. The FBI records the 1999 Melissa incident as a Word macro virus that used Outlook to send messages. It is a genuine virus example, but its macro and email behavior should not be generalized to every modern attachment alert.
  • 25. Mirai — IoT botnet malware. Mirai is an IoT botnet malware name, not a file-infecting computer virus. See CYBERoinfo’s existing historical record for context on the 2016 DDoS episode; this directory does not repeat that timeline.
  • 26. MyDoom — Mass-mailing worm. Microsoft’s family record classifies MyDoom as a worm. Older public language sometimes called variants viruses, which is why the name is useful for teaching that everyday usage and technical classification can differ.
  • 27. Neshta — File-infecting virus. Microsoft describes Neshta.C as a prepending file virus that infects Windows executable files. This is one of the clearest genuine virus entries here; aliases in vendor naming should not be counted as separate threats.
  • 28. njRAT — Remote-access malware. A remote-access family name associated with unauthorized control and surveillance capabilities. It is a RAT-style malware example, not a self-replicating file virus; a detection calls for account, endpoint and network review.
  • 29. NotPetya — Destructive wiper presented as ransomware. A destructive malware name that looked like ransomware but is commonly discussed for its wiping impact. See CYBERoinfo’s live historical record for incident context; do not infer that every ransomware alert is NotPetya.
  • 30. P2P ZeuS — Banking Trojan and botnet variant. A peer-to-peer variant associated with the ZeuS banking-malware lineage. “Variant” matters: families can share code or naming history without being identical samples, and neither label makes it a classic virus.
  • 31. Parite — File-infecting virus. Microsoft describes Win32/Parite as a polymorphic family that infects Windows executable files and writable network shares. It is a genuine file-infector, unlike the many ransomware and Trojan names in this directory.
  • 32. PlugX — Remote-access Trojan. A remote-access Trojan family name widely used in defensive reporting. It illustrates how a named malware family can be associated with a particular access capability without being a worm or host-file virus.
  • 33. QakBot — Banking Trojan and loader. QakBot is also known as QBot and Pinkslipbot in public reporting. Keep those aliases under one canonical family; the name describes a banking and delivery concern, not three separate viruses.
  • 34. Raccoon Stealer — Infostealer. An infostealer name associated with credential and browser-data theft. The practical reader question is what accounts and sessions need protection after an alert, not whether it “spread like a virus.”
  • 35. RansomHub — Ransomware-as-a-service family. A ransomware family discussed in an affiliate or service model context. “As-a-service” describes an operating model, not a technical replication method; it should not be confused with a file-infecting virus.
  • 36. Raspberry Robin — Initial-access malware with USB-linked spread. A malware name associated with initial access and removable-media or USB-linked spread in public reporting. Spread through a device or user workflow is not the same as infecting every executable file.
  • 37. RedLine Stealer — Infostealer. An information-stealing family name tied to credential and browser-data theft discussions. It is a useful search label for alert triage and account-protection guidance, but the record here does not establish current prevalence.
  • 38. REvil — Ransomware. A ransomware family name found in historical reporting on extortion operations. Readers should distinguish the family label from later copycats, aliases or unrelated detections that use similar language.
  • 39. Royal — Ransomware. A ransomware family name used in public incident-response reporting. Its category is about data and system availability plus extortion—not the replication behavior that defines a traditional virus.
  • 40. Ryuk — Ransomware. A ransomware family name associated with enterprise-targeted extortion reporting. It is included as a named example, not as a ranking of “worst” malware or proof of a current campaign.
  • 41. Sality — File-infecting virus. Microsoft’s threat naming identifies Sality as a Windows virus family. It belongs in the genuine file-infection group and should be investigated differently from a cloud-only account alert or a ransomware note.
  • 42. SamSam — Operator-driven ransomware. A ransomware name associated with hands-on operator activity rather than an autonomous file virus. The distinction helps organizations focus on access controls, segmentation, logging and recovery readiness.
  • 43. Shamoon — Destructive wiper. A wiper family name associated with destructive operations. It is relevant to integrity and availability planning, and it should not be described as ransomware merely because both can make systems unavailable.
  • 44. Stuxnet — Industrial-control-system worm. Stuxnet is a complex ICS-targeting malware name with worm-like propagation. See CYBERoinfo’s existing historical record for discovery context; this entry does not repeat its incident history or make a current-outbreak claim.
  • 45. TrickBot — Banking Trojan and modular malware. A modular banking-malware family name associated with credential theft and additional components. “Modular” warns readers that capabilities can vary by build; it remains a malware-family label, not a virus definition.
  • 46. Ursnif — Banking Trojan, including Gozi lineage. A banking-Trojan name associated with the Gozi lineage in public tracking. Names and family boundaries vary among sources, so investigators should preserve the exact detection and supporting indicators.
  • 47. Virut — File-infecting virus. Microsoft describes Virut.E as a polymorphic, memory-resident file-infecting virus. It is another genuine virus example and should not be conflated with a Trojan that only masquerades as a legitimate program.
  • 48. WannaCry — Worm-like ransomware. A ransomware family with worm-like propagation. The names WanaCry, WanaCrypt, WanaCrypt0r and WCry are aliases, not four separate viruses. See CYBERoinfo’s existing historical record for the 2017 incident context.
  • 49. WhisperGate — Wiper disguised as ransomware. A destructive malware name often discussed as ransomware-like because of its presentation. The important reader distinction is destructive intent versus ordinary file encryption and extortion; it is not a classic virus.
  • 50. XLoader — Infostealer, including FormBook lineage. An infostealer name associated with the FormBook lineage in public tracking. Family naming can shift across vendors, so use the exact alert, file and telemetry rather than assuming every XLoader reference is one build.

What should you do if a security product names one of these families?

For broader first-party guidance, see CYBERoinfo’s Malware knowledge hub, Trojan malware explainer, Botnet explainer, Spyware explainer, infostealer guide, ransomware attack-paths guide and first-hour incident checklist. These links are existing public CYBERoinfo destinations, not proposed new pages.

  • Record the exact alert. Save the family name, alias, detection time, device, account, file path and product version. Do not replace a precise alert with the generic word “virus.”
  • Contain proportionately. For a work device, follow the organization’s incident process and ask the security team whether to isolate it. For a personal device, disconnect it from sensitive networks or accounts when safe; do not destroy evidence in a panic.
  • Protect accounts from a clean device. Change important passwords, revoke suspicious sessions and enable multifactor authentication where available. Prioritize email, financial, administrator and password-manager accounts.
  • Use trusted recovery paths. Update the operating system and security software, scan with a reputable tool and restore only from known-good backups. A detection record cannot prove that a scan found every related component.
  • Escalate high-impact cases. Ransomware, suspected data theft, a wiper, firmware/rootkit concern, or a compromised business account warrants qualified incident-response or IT support. Preserve logs and relevant evidence before wiping or rebuilding when an organization may need investigation.

What can this directory prove—and what can it not prove?

It can provide a consistent reader-facing classification, consolidate common aliases and identify whether a name is documented as a file-infecting virus, worm, Trojan, ransomware family, loader, infostealer, botnet, rootkit or wiper. It can also point readers toward the right kind of follow-up question.

It cannot prove that a family is active in a particular country, that a named alert is genuine, that a person or group is responsible, that a device has been fully cleaned, or that a family caused a particular loss. The source record is open reporting and vendor or government documentation; taxonomy differs between publishers. Historical pages can contain old estimates or incident framing that should not be reused as current measurements.

Frequently asked questions

Question: Are all 50 names computer viruses?

No. Only a subset are genuine file-infecting viruses. The list deliberately includes other malware because readers use “computer virus” as a broad search term. The type column is the corrective classification.

Question: What is the difference between a malware family and an alias?

A family is a tracked grouping of related malicious software. An alias is another name used for the same or overlapping software. QakBot/QBot/Pinkslipbot and WannaCry/WanaCrypt/WCry are consolidated here so aliases do not inflate the number of threats.

Question: Which entries are safest to call viruses?

Neshta, Parite, Sality and Virut are the clearest file-infecting virus examples in the source set. Melissa is a Word macro virus. ILOVEYOU is best described with its historical hybrid label: virus and worm.

Question: Does a name in an antivirus alert prove infection?

No. It is a detection signal that needs context. False positives, remnants, blocked downloads, renamed files and vendor-specific labels are possible. Check the product’s evidence and follow a qualified response process.

Question: Is a historical malware name still a current threat?

Not necessarily. A family may be retired, renamed, reused, detected in old files or still appear in open reporting. This page makes no current-prevalence or outbreak claim without separate, dated evidence.

Question: Why are Stuxnet, Mirai, WannaCry and NotPetya linked differently?

CYBERoinfo already has verified live historical records for those four names. The links provide historical context without creating duplicate incident pages. The directory entry remains the classification and lookup point.

Decision checklist

  • Record the exact alert. Save the family name, alias, detection time, device, account, file path and product version. Do not replace a precise alert with the generic word “virus.”
  • Contain proportionately. For a work device, follow the organization’s incident process and ask the security team whether to isolate it. For a personal device, disconnect it from sensitive networks or accounts when safe; do not destroy evidence in a panic.
  • Protect accounts from a clean device. Change important passwords, revoke suspicious sessions and enable multifactor authentication where available. Prioritize email, financial, administrator and password-manager accounts.
  • Use trusted recovery paths. Update the operating system and security software, scan with a reputable tool and restore only from known-good backups. A detection record cannot prove that a scan found every related component.
  • Escalate high-impact cases. Ransomware, suspected data theft, a wiper, firmware/rootkit concern, or a compromised business account warrants qualified incident-response or IT support. Preserve logs and relevant evidence before wiping or rebuilding when an organization may need investigation.

Limitations

  • An alert or family name alone does not confirm an infection or data theft on a particular device.
  • Historical activity and vendor capability descriptions are not proof of a present-day outbreak or specific sample behavior.
  • A scan or infrastructure disruption cannot guarantee that every related threat was removed.
  • This educational article is not personalized incident-response or a device-specific diagnosis.

Evidence sources

  1. MITRE ATT&CK — MITRE ATT&CK software catalog
  2. MITRE ATT&CK — MITRE S1125 AcidRain
  3. MITRE ATT&CK — MITRE S0331 Agent Tesla
  4. MITRE ATT&CK — MITRE S1129 Akira
  5. MITRE ATT&CK — MITRE S0373 Astaroth
  6. MITRE ATT&CK — MITRE S0344 Azorult
  7. MITRE ATT&CK — MITRE S0606 Bad Rabbit
  8. MITRE ATT&CK — MITRE S1068 BlackCat
  9. MITRE ATT&CK — MITRE S1039 Bumblebee
  10. MITRE ATT&CK — MITRE S0611 Clop
  11. MITRE ATT&CK — MITRE S0608 Conficker
  12. MITRE ATT&CK — MITRE S0575 Conti
  13. MITRE ATT&CK — MITRE S0384 Dridex
  14. MITRE ATT&CK — MITRE S0024 Dyre
  15. MITRE ATT&CK — MITRE S0367 Emotet
  16. MITRE ATT&CK — MITRE S1138 Gootloader
  17. MITRE ATT&CK — MITRE S0531 Grandoreiro
  18. MITRE ATT&CK — MITRE S0697 HermeticWiper
  19. MITRE ATT&CK — MITRE S0483 IcedID
  20. U.S. Government Accountability Office — GAO ILOVEYOU testimony
  21. MITRE ATT&CK — MITRE S1202 LockBit 3.0
  22. MITRE ATT&CK — MITRE S0397 LoJax
  23. MITRE ATT&CK — MITRE S1213 Lumma Stealer
  24. MITRE ATT&CK — MITRE S0449 Maze
  25. FBI — FBI Melissa Virus case
  26. CISA — CISA Mirai alert
  27. Microsoft — Microsoft MyDoom
  28. Microsoft — Microsoft Neshta.C
  29. MITRE ATT&CK — MITRE S0385 njRAT
  30. MITRE ATT&CK — MITRE S0368 NotPetya
  31. MITRE ATT&CK — MITRE S0016 P2P ZeuS
  32. Microsoft — Microsoft Parite
  33. MITRE ATT&CK — MITRE S0013 PlugX
  34. MITRE ATT&CK — MITRE S0650 QakBot
  35. MITRE ATT&CK — MITRE S1148 Raccoon Stealer
  36. MITRE ATT&CK — MITRE S1212 RansomHub
  37. MITRE ATT&CK — MITRE S1130 Raspberry Robin
  38. MITRE ATT&CK — MITRE S1240 RedLine Stealer
  39. MITRE ATT&CK — MITRE S0496 REvil
  40. MITRE ATT&CK — MITRE S1073 Royal
  41. MITRE ATT&CK — MITRE S0446 Ryuk
  42. Microsoft — Microsoft Sality
  43. MITRE ATT&CK — MITRE S0370 SamSam
  44. MITRE ATT&CK — MITRE S0140 Shamoon
  45. MITRE ATT&CK — MITRE S0603 Stuxnet
  46. MITRE ATT&CK — MITRE S0266 TrickBot
  47. MITRE ATT&CK — MITRE S0386 Ursnif
  48. Microsoft — Microsoft Virut.E
  49. MITRE ATT&CK — MITRE S0366 WannaCry
  50. MITRE ATT&CK — MITRE S0689 WhisperGate
  51. MITRE ATT&CK — MITRE S1207 XLoader