Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters712 entities
APT GROUPfinancial
SatanLock is a short-lived ransomware group that first appeared in April 2025 and abruptly shut down in July 2025 after claiming attacks against roughly 67 organizations — though over 65% of listed victims were duplicates from other groups — leaking all stolen data publicly upon shutdown.
RLUpdated: N/A
View profile →
APT GROUPfinancial
ms13-089 — tracked by MISP Galaxy (ransomware).
Infra: 🔗 msleakjir7pxbe6onlqe💬 chatmsuppxeoma533636
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
U-Bomb is a low-profile ransomware operation discovered in March 2023 that arrives via phishing emails and uses third-party offensive frameworks (BRC4, Sliver, Cobalt Strike) for lateral movement before deploying its encryptor, likely becoming inactive in the second half of 2023.
Infra: 🔗 contiuevxdgdhn3zl2ku
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Dread is a ransomware group that appears in tracking databases but has no publicly documented attacks or confirmed TTPs from major security vendors.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
fakersa — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Avos is the threat actor group behind AvosLocker ransomware, a RaaS operation active since June 2021 that recruited affiliates to deploy ransomware against critical infrastructure including financial services, manufacturing, and government sectors across the US and a dozen other countries.
Infra: 🔗 avos2fuj6olp6x36.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
AKA Lemon
Infra: 🔗 ioot5g6iwj26tcowu464
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
BlackShrantac is a ransomware group that emerged in late 2025, targeting organizations in manufacturing, financial services, technology, and the public sector globally, employing double-extortion combined with living-off-the-land techniques to weaponize legitimate tools and disable defenses before encrypting files.
Infra: 🔗 b2ykcy2gcug4gnccm6hn🔗 jvkpexgkuaw5toiph7fb🔗 shrantacpxim7z6m6pns
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
cylance — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 gandcrabmfe6mnef.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 g6gwcbiylnvrzj6txsyp
RSLUpdated: N/A
View profile →
APT GROUPfinancial
cryptedpay — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
key group — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
The locker is written in C/C++/ASM. <br/>It supports all systems starting from Windows 2003, has a separate binary for ESXi, and uses a unified encrypted file format across all systems. <br/>WINDOWS: <br/> • Two encryption modes: patch-based and file header. <br/> • Extensive configuration settings: from ignoring specific paths/extensions to terminating services/processes, unlocking occupied files, working with network shares, and more. <br/> • Arguments available for shutting down Hyper-V virtual machines, deleting backups, network scanning with logged-in user tokens. <br/> • Each build includes an obfuscated PowerShell script. <br/> • Execution is password-protected. <br/> • The locker itself is shellcode for x86/x64; if you have custom execution methods, we can provide the shellcode. <br/>ESXI: <br/> • Encrypts files in patches, with configurable path exclusions. <br/>The default configuration is pre-set to avoid disrupting Windows/ESXi/Linux systems. <br/> <br/>Our commission is 20% of payouts
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Likely associated with the cybercrime group BlingLibra (ShinyHunters)
RLUpdated: N/A
View profile →
APT GROUPfinancial
Chaos is a ransomware-as-a-service operation that emerged in early 2025, likely formed by former BlackSuit/Royal members, offering cross-platform ransomware for Windows, Linux, ESXi, and NAS to affiliates recruited on the RAMP dark web forum, excluding CIS/BRICS countries and hospitals from targeting.
Infra: 🔗 hptqq2o2qjva7lcaaq67📁 httj32vkww42kq3kjbsb📁 2yxf2ald2c67twt4663p+9 more
RSLUpdated: N/A
View profile →
APT GROUPfinancial
RAAS - Ransomware intégré à un fichier PDF, à faire ouvrir à vos victimes ou à insérer vous-même, Windows et Mac, ne fonctionne pas sur Linux. Tableau de vitcimes et récupération de données possible depuis votre espace abonné. Configuration de votre ransomware à votre première connexion, puis modification possible selon votre formule.
RLUpdated: N/A
View profile →
APT GROUPfinancial
miliphen — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Marketo, launched in April 2021, is a data-theft extortion marketplace that steals and sells data to third parties or back to victims without encrypting files, applying aggressive pressure by emailing victims' competitors with sample data packs.
RLUpdated: N/A
View profile →
APT GROUPfinancial
zeoticus2 — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Ranzy Locker, Former known as ThunderX. The group hosting a data leak site in the darknet where they posting sensitive information of victims who do not pay the ransom. ThunderX was launched at the end of August 2020. Soon after launching, weaknesses were found in the code, that allowed decrypting the files that the malware encrypted. The group has fixed the code and publish a new version, then released it under the name Ranzy Locker. The Tor onion URL used by the Ranzy Leak site is the same as the one used by Ako Ransomware. The use of the same URL could indicate that both groups merged, or they are cooperating similarly to the Maze cartel.
Infra: 🔗 37rckgo66iydpvgpwve7
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
oceans — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
DataF Locker is a ransomware variant first observed in 2024, closely tied to the Babuk ransomware lineage. It operates under a double-extortion model, encrypting files by appending the .dataf extension and threatening to leak exfiltrated data if the ransom isn't paid. Victims receive a ransom note named How To Restore Your Files.txt, with satisfaction of specified recovery procedures. Observations suggest use of typical intrusion vectors such as phishing, exploit tools, or leaked credential abuse, although detailed delivery methods and leak infrastructure remain under-documented in high-tier intelligence reports.
Infra: 💬 pg3n5bteiatjf6rt7oa4
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 dzkxxcsbrg7bwnlwwer5
RSLUpdated: N/A
View profile →
APT GROUPfinancial
zetarink — tracked by MISP Galaxy (ransomware).
Infra: 💬 5cxxlyurwn2usx5qwtln
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
gangbang — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
BabyLockerKZ is a variant of MedusaLocker ransomware, first observed in late 2023. It operates under a double‑extortion model, combining file encryption with data exfiltration and extortion. Technically, it reuses MedusaLocker’s AES + RSA‑2048 hybrid encryption, appends the .hazard file extension to encrypted files, and includes a unique autorun registry key (“BabyLockerKZ”) alongside dedicated public/private key data inserted into registry values. Initial access is achieved through opportunistic methods like RDP compromises, with lateral movement facilitated by compromised credentials and tools such as Mimikatz. The variant employs a custom toolkit codenamed paid_memes, which includes tools like "Checker" for scanning credentials, facilitating automation, and bridging toolsets for further exploitation. Starting late 2022, its operators have compromised over 100 organizations per month, initially targeting European victims before shifting toward Latin America in 2023.
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
tssxx25 — tracked by MISP Galaxy (ransomware).
Infra: 🔗 techscckl72ibnfg2ksj
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 restoredz4xpmuqr.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
settra — tracked by MISP Galaxy (ransomware).
Infra: 🔗 settra5ldqwgtw5q7z5a📁 26z3gms2rshr2zzedxhw📁 ttfy4zmtiaywfkkmykpx+2 more
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
D0glun is a crypto-ransomware strain first observed in January 2025, believed to be derived from Babuk via an intermediary variant known as Cheng Xilun. It uses AES-256 symmetric encryption and appends filenames with patterns such as .@D0glun@<original extension> or similar. The malware encrypts files rapidly, changes the desktop wallpaper, and drops ransom notes typically named @[email protected], Desktopcxl.txt, or help.exe. The campaign has shown signs of shared infrastructure and code reuse from Cheng Xilun, but there is no confirmed evidence of a large-scale or mature operation. Its activity so far suggests it is being tested or deployed by a small group or individual rather than a structured affiliate network.
Infra: 🔗 33333333h45xwqlf3s3e
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
aka ShinyHunters
Infra: 🔗 fjg4zi4opkxkvdz7mvwp📁 vkhztfqsjbh2in6425uv📁 c7izex5h5shupbutwzsj+9 more
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
qilin-securotrop — tracked by MISP Galaxy (ransomware).
Infra: 🔗 securo45z554mw7rgrt7
RSLUpdated: 2026-08-04
View profile →