Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters712 entities
APT GROUPfinancial
phalcon — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
The QNAPCrypt ransomware works similarly to other ransomware, including encrypting all files and delivering a ransom note. However, there are several important differences:1. The ransom note was included solely as a text file, without any message on the screen—naturally, because it is a server and not an endpoint.2. Every victim is provided with a different, unique Bitcoin wallet—this could help the attackers avoid being traced.3. Once a victim is compromised, the malware requests a wallet address and a public RSA key from the command and control server (C&C) before file encryption.
Infra: 🔗 veqlxhq7ub5qze3qy56z…💬 7zvu7njrx7q734kvk435…
RSLUpdated: N/A
View profile →APT GROUPfinancial
BabyDuck is a ransomware group tracked on ransomware.live with approximately 180 claimed victims, appending the .babyduck extension to encrypted files, distinct from the better-known Babuk group.
Infra: 🔗 babydovegkmhbontykzi…
RSLUpdated: N/A
View profile →APT GROUPfinancial
"aGl0bGVyCg" (Base64 for "hitler") is a reference to the Hitler-Ransomware (2016), a German-origin proof-of-concept that displayed a Hitler image, did not actually encrypt files, and demanded a 25-euro Vodafone card payment; assessed as an amateur test project rather than a serious criminal operation.
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
ank — tracked by MISP Galaxy (ransomware).
Infra: 🔗 ankexpn6vk3qc5ooyyj7…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
w3crypto — tracked by MISP Galaxy (ransomware).
Infra: 💬 fdevb3qh24ak7wujqsf7…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
scattered lapsus$ hunters — tracked by MISP Galaxy (ransomware).
Infra: 🔗 shinypogk4jjniry5qi7…🔗 breachforums.hn…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
punisher — tracked by MISP Galaxy (ransomware).
Infra: 💬 jh3zjsqgqk5woyuls7dx…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
lcryptorx — tracked by MISP Galaxy (ransomware).
Infra: 🔗 lcryxdecryptor4f6xzy…🔗 lcryptordecrypt7xfzq…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
izis — tracked by MISP Galaxy (ransomware).
Infra: 📁 et3j2c6b55opkefctuie…🔗 izis6oyht2suanp5fb5t…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
BravoX is a selective ransomware-as-a-service operation that surfaced publicly in January 2026 after advertising on the RAMP underground forum, targeting primarily US-based organizations in healthcare and retail while applying strict affiliate vetting requirements including proof of access or a financial deposit.
Infra: 🔗 bravoxxtrmqeeevhl7gd…🔗 bravoxxwcfz5qk43ychg…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
RansomedVC was a short-lived extortion group active from August to November 2023 that claimed high-profile victims including Sony, innovating by threatening GDPR regulatory fines as an additional extortion lever; it briefly operated as a RaaS before shutting down in an apparent exit scam following reported arrests of six members.
Infra: 🔗 ransomed.vc…🔗 k63fo4qmdnl4cbt54sso…🔗 f6amq3izzsgtna4vw24r…+1 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Aptlock surfaced in early 2025 and is characterized by a single-extortion model combined with threats of data leakage. The ransomware encrypts files on Windows systems, appending the extension .aptlock, and then changes the victim’s desktop wallpaper. Victims receive a ransom note named read_me_to_access.txt informing them that their critical company data has been exfiltrated and will be deleted or leaked if they don’t act. They are given 72 hours to initiate contact via Tor-based chat access (using credentials provided in the note), with further warnings issued if no engagement occurs within 5 days. Specific details about intrusion vectors, encryption algorithms used, or known affiliate operators remain undisclosed in public threat intelligence. No reliable evidence links Aptlock to Ransomware-as-a-Service operations or lists any known affiliates.
Infra: 🔗 sr3b2uzrzzubagq64sav…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Launched around September 2024, ContFR is a French-speaking RaaS that uses a Tor-hosted platform to provide ransomware embedded in PDF files (targeting both Windows and macOS). The group offers a tiered subscription model—“TEST,” “BASIC,” and “ELITE”—allowing affiliates varying degrees of customization, offline capability, and support based on the package purchased. As of the latest reporting, no victims are publicly listed, though data leak publications likely require a subscription to access. The operation suggests an organized, business‑like structure, distinct from opportunistic one‑off strains.
Infra: 🔗 zprxx7sfc26rufggrean…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Fargo is a ransomware variant that surfaced in 2022, primarily targeting Microsoft SQL Server (MSSQL) systems. Believed to be a variant of the TargetCompany ransomware family, Fargo uses brute-force or credential-stuffing attacks on exposed MSSQL instances to gain access, then executes payloads via SQL Server commands. Once deployed, it encrypts files using a combination of symmetric and asymmetric algorithms, appends the .Fargo3 (or similar) extension, and drops a ransom note directing victims to contact operators via email. It also attempts to delete system backups and shadow copies to prevent recovery. Fargo has been observed targeting organizations in multiple sectors, with a concentration of victims in South Korea and other parts of Asia.
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
leak bazaar — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
SenSayQ is an emerging ransomware actor that appeared in mid-2024 using a leaked LockBit 3.0 builder for double-extortion attacks; Group-IB links it operationally to the Brain Cipher group and its siblings EstateRansomware and "Noname," suggesting a shared operator.
RLUpdated: N/A
View profile →APT GROUPfinancial
Malek Team is an Iranian-linked threat actor that emerged on October 8, 2023 (the day after the Hamas attack on Israel), believed to be tied to Iranian military intelligence, primarily targeting Israeli organizations using data exfiltration and extortion, with notable attacks on Ziv Medical Center and Ono Academic College.
RLUpdated: N/A
View profile →APT GROUPfinancial
Malas is a lesser-documented ransomware group that maintains an active dark web presence; detailed information about its targets, victims, or operational model is limited in public reporting.
Infra: 🔗 malas2urovbyyavjzaez…🔗 malas2urovbyyavjzaez…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
X001xs is a low-profile ransomware group tracked on monitoring platforms with minimal public documentation, employing standard double-extortion tactics with no detailed technical analysis published by major vendors.
RLUpdated: N/A
View profile →APT GROUPfinancial
Groove emerged in mid-2021 as a loose criminal collective linked to former Babuk gang members, known for publicly leaking Fortinet VPN credentials to attract affiliates and calling for attacks on US government and financial targets; the group later claimed its entire operation was a hoax to mislead security researchers.
Infra: 🔗 ws3dh6av66sjbxxkjpw5…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Blue Locker targets Pakistan’s vital energy sector, particularly Pakistan Petroleum
RLUpdated: N/A
View profile →APT GROUPfinancial
D1R Claims Synopsys and Bosch Breaches, but Synopsys Disputes Intrusion
RLUpdated: N/A
View profile →APT GROUPfinancial
Dataleak is a low-profile ransomware group with approximately 6 known victims including entities in Brazil; very limited public threat intelligence exists on this group's tools, TTPs, or origins.
Infra: 🔗 woqjumaahi662ka26jzx…🔗 woqjumaahi662ka26jzx…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Aware is a recently emerged ransomware group that operates a Tor-based data leak site with very limited public documentation and no publicly catalogued victims, tools, or TTPs in major threat intelligence databases.
Infra: 🔗 ui2uleaiisccbtcooyi3…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
elcometa — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
ESXiArgs is a ransomware campaign that emerged in February 2023, targeting VMware ESXi servers by exploiting the CVE-2021-21974 vulnerability. It encrypts virtual machine configuration files (.vmdk, .vmx, .vmxf, .vmsd, .vmsn, .vswp, .vmss, .nvram, .vmem) rendering VMs inaccessible. The campaign compromised thousands of unpatched servers globally, primarily affecting European organizations. A decryptor was later released by CISA and FBI.
RLUpdated: N/A
View profile →APT GROUPfinancial
mario esxi — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Pro-Palestinian Group
Infra: 🔗 toufanleaks.org…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
LeakTheAnalyst is a data-theft extortion group that operates a dark web leak site with approximately 20 claimed victims, notable for a 2017 operation targeting a Mandiant security researcher; the group focuses on stealing and publishing sensitive corporate data rather than deploying file-encrypting ransomware.
RLUpdated: N/A
View profile →APT GROUPfinancial
In September The El Dorado ransomware group have been rebrand as BlackLock
RLUpdated: N/A
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 h44jyyfomcbnnw5dha7z…
RSLUpdated: N/A
View profile →APT GROUPfinancial
This ransomware uses a combination of different crypto algorithms (ChaCha20, AES-128, Curve25519). The activity of this malware is dated to mid-June 2021. The extension of the encrypted files are set to the compromised company: .<target_company>
Infra: 🔗 wtyafjyhwqrgo4a45wdv…🔗 wtyafjyizleuw4yhepmd…💬 wtyafjyhwqrgo4a45wdv…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Cry0 is a ransomware-as-a-service operation that recruits affiliates via underground forums, using a Rust-written payload with blockchain-based (Internet Computer Protocol) negotiation infrastructure to resist law enforcement takedowns and offering affiliates a 90/10 revenue split.
Infra: 🔗 cryoblogedawivdcknyd…📁 pwn3dky35tub4ktj5bol…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
D4rk4rmy is a ransomware and data extortion group active since at least 2025, targeting financial services, hospitality, technology, and logistics sectors, operating a RaaS model with notable claimed victims including the Monte Carlo casino resort.
Infra: 🔗 d4rkd2fybtclo44hss2d…
RSLUpdated: 2026-08-04
View profile →