Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters712 entities
APT GROUPfinancial
<br/>
<br/>Our team members are from different countries and we are not interested in anything else, we are only interested in dollars.
<br/>
<br/>We do not allow CIS, Cuba, North Korea and China to be targeted.
<br/>
<br/>Re-attacks are not allowed for target companies that have already made payments.
<br/>
<br/>We do not allow non-profit hospitals and some non-profit organizations be targeted.
<br/>
Infra: 🔗 igziys7pres4644kbrta…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
DarkRace is a ransomware variant that surfaced in mid-2023 sharing strong code similarities with LockBit, employing double-extortion via a dark web leak site, but remained a minor player with fewer than 15 posted victims in its first half-year.
Infra: 🔗 wkrlpub5k52rjigwxfm6…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Group is connected to Qilin.
Infra: 🔗 wikileaksv2.com…🔗 31.41.244.100.…🔗 wikileaks2.site…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
<br/>
<br/>In the cyber-undergrounds, we're exploring shadowed corridors of the digital world in search of inside information. we’re a digital watchdog operating at the intersection of cybersecurity, internet freedom, and investigative journalism. We delve into the hidden corners of the web, exposing truths and uncovering stories that are often buried by mainstream media or distorted by corporate interests.
<br/>
<br/>This project isn’t just for tech experts or privacy advocates. It’s for everyone who values transparency, freedom, and integrity in a connected world. Operating independently, we’re free from corporate influence and political bias, enabling us to report with uncompromising honesty. Our work resonates with a diverse audience cybersecurity experts, digital rights activists, journalists, and anyone who values an internet free from control.
<br/>
<br/>In a world where the lines between truth and agenda grow increasingly blurred, we’re building something bold, the space where the truth of the internet can be uncovered, untamed and unfiltered. Our project is an independent voice for digital freedom, committed to shining a light on the internet’s most vital and vulnerable spaces: cybersecurity, privacy, and the right to information without compromise.
<br/>
<br/>In a landscape clouded by agendas and profit, we are here to do one thing: deliver the truth, boldly and beautifully. Join us as we push back against the systems that seek to compromise our digital freedoms and carve a path toward a more transparent, liberated internet.
<br/>
Infra: 🔗 nleakk6sejx45jxtk7x6…📁 ahic5qo3qbjgsyv7x2h5…📁 bnlluetsuf6pv7mchgue…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
LockBit is one of the most prolific ransomware groups in history, operating as a full RaaS platform that at its peak accounted for an estimated 44% of all ransomware incidents globally in 2023, targeting virtually every sector worldwide through an affiliate model where developers maintain infrastructure and affiliates conduct intrusions.
Affiliates: LockBitSupp • Wazawaka • bassterlord
Infra: 🔗 lockbitkodidilol.oni…💬 lockbitks2tvnmwk.oni…
RLUpdated: N/A
View profile →APT GROUPfinancial
Flocker (also linked to the FSociety brand) is a ransomware-as-a-service group active since 2023–2024, targeting Windows and Linux systems via phishing, compromised RDP, and exploit kits using a double extortion model, and observed collaborating with FunkSec.
RLUpdated: N/A
View profile →APT GROUPfinancial
SHAOleaks is a low-profile data leak and extortion group with minimal public documentation, operating a leak site but lacking detailed analysis by major threat intelligence firms, suggesting a very limited or short-lived operation.
RLUpdated: N/A
View profile →APT GROUPfinancial
muliaka — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Ransom Cartel is a ransomware-as-a-service operation that surfaced in December 2021, assessed by Palo Alto Unit 42 to share source code and technical overlap with the defunct REvil group, suggesting its operators had prior access to REvil's codebase, conducting double-extortion attacks against corporate networks.
Infra: 🔗 u67aylig7i6l657wxmp2…🔗 cartelraqonekult2cxb…
RLUpdated: N/A
View profile →APT GROUPfinancial
FreeCivilian is a data extortion group with suspected ties to Russian GRU military intelligence, known for targeting Ukrainian government websites — including sites offering surrender guidance to Russian troops — blending cybercrime with apparent state-aligned political objectives.
Infra: 🔗 gcbejm2rcjftouqbxuhi…
RLUpdated: N/A
View profile →APT GROUPfinancial
Sicarii is a pro-Israeli/Jewish-branded ransomware-as-a-service operation that emerged in late 2025, explicitly targeting Arab and Muslim-majority organizations while avoiding Israeli systems, exploiting exposed RDP services and Fortinet devices, with its admin later instructing operators to migrate to the BQTLock platform.
RLUpdated: N/A
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 kelvinsecteamcyber.w…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Radiant is a financially motivated ransomware group that emerged in September 2025, conducting double- and single-extortion attacks without affiliates, drawing widespread condemnation after attacking UK childcare provider Kido International and publishing photographs, names, and home addresses of over 8,000 children.
RLUpdated: N/A
View profile →APT GROUPfinancial
New possible leak site posted to a forum on November 20th, 2022, no victims at present. Unclear if its for a ransomware or extortion group
Infra: 🔗 hkk62og3s2tce2gipcdx…
RLUpdated: N/A
View profile →APT GROUPfinancial
ZeroTolerance is a low-profile ransomware group tracked on monitoring platforms with no detailed threat actor profiles, technical analysis, or named victim reports published by major threat intelligence vendors.
RLUpdated: N/A
View profile →APT GROUPfinancial
Cryp70n1c0d3 is a low-profile ransomware group with limited public documentation; specific targets, attack methodology, and operational model remain poorly documented in open sources.
Infra: 🔗 7k4yyskpz3rxq5nyokf6…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Cloak is a ransomware-as-a-service operation active since late 2022, primarily targeting small-to-medium enterprises in Europe — especially Germany — across manufacturing, healthcare, education, and government sectors, with expansion into North American and Asian targets by 2025.
Infra: 🔗 cloak7jpvcb73rtx2ff7…💬 6mw4yczxeqoiq7rgwnpi…💬 7puvv4qtcrigzbxshqib…+36 more
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 gammax6w3dkfdjfrjtht…
RSLUpdated: N/A
View profile →APT GROUPfinancial
telegram — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
white lock — tracked by MISP Galaxy (ransomware).
Infra: 💬 l3e4ct2egnlfz4ymexwn…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Launched on April 24th, 2025 RansomBay is a new project operating under the DragonForce initiative
Infra: 🔗 rrrbay3nf4c2wxmhprc6…💬 rrrbayguhgtgxrdg5myx…📁 rrrbaygxp3f2qtgvfqk6…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Nasir Security is a pro-Iranian threat actor that emerged around October 2025, primarily targeting energy sector organizations in the Middle East (UAE, Oman, Saudi Arabia, Iraq) and Israeli IT supply chain firms, using spear-phishing, BEC, and exploitation of public-facing applications.
RLUpdated: N/A
View profile →APT GROUPfinancial
Cerber Imposer is a post-2019 rebrand of the Cerber ransomware family, resurfacing in late 2021 with updated targeting of enterprise environments. Unlike its classic counterpart, Cerber Imposer utilizes the .locked file extension and includes a unique recovery note named __$$RECOVERY_README$$__.html. It does not reuse the original Cerber codebase; instead it borrows branding while operating under new cryptographic implementations and deployment tactics. Threat actors have leveraged known remote code execution vulnerabilities in Atlassian Confluence (CVE-2021-26084) and GitLab (CVE-2021-22205) to deliver this ransomware. The rebranded variant has compromised servers in the U.S., Germany, China, and Russia, indicating a broader scope of targeting than originally seen with early Cerber campaigns.
<br/>
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Mimic v.10 Ransomware-as-a-Service (RaaS). The malware is designed to target various operating systems (Windows, ESXi, NAS, FreeBSD) and features network-wide deployment, file obfuscation, backup destruction, UAC bypass, and multithreaded encryption. The service offers additional tools like NTLM password decryption and call-based extortion. They prohibit attacks on CIS countries and require active participation, with decryption tools available for a fee currently 800USD.
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Trinity ransomware was first discovered in May 2024, believed to be a rebrand of the Venus/2023Lock variants, using ChaCha20 encryption and double-extortion via a Tor leak site; the US HHS flagged it as a specific threat to the healthcare sector after confirmed attacks on healthcare organizations.
Infra: 🔗 txtggyng5euqkyzl2knb…🔗 txtggyng5euqkyzl2knb…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Elpaco is a variant of Mimic ransomware that emerged around August 2023. Designed with significant customization and stealth in mind, it targets Windows systems by abusing the Everything search utility to optimize file discovery and accelerate encryption. Operators exploit various initial access methods—most notably RDP brute-force and the Zerologon vulnerability (CVE-2020-1472)—to gain access, escalate privileges, and deliver the payload. The ransomware uses a 7z SFX dropper, deploys multi-threaded encryption, disables recovery options, and self-deletes after execution, leaving victims with encrypted files bearing Elpaco-specific extensions. It's recognized for its adaptability and advanced features compared to earlier Mimic variants.
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
lulzsec muslims — tracked by MISP Galaxy (ransomware).
Infra: 🔗 dfi7ynmrugokn4fgvpbz…🔗 dfi7ynmrugokn4fgvpbz…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
proxima — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Colossus ransomware was first observed in September 2021, when ZeroFox researchers uncovered the variant attacking a U.S.-based automotive group. It employs a double-extortion model, using Themida packing and sandbox evasion to disable defenses and deliver encrypted payloads. Victims are urged to visit a support site—hosted at a domain like colossus.support—to negotiate payment, or face large-scale data dumps and increasing ransom amounts tied to countdown timers. Operators demonstrated familiarity with RaaS playbooks, drawing architectural parallels to groups like EpsilonRed, BlackCocaine, and REvil/Sodinokibi.
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
⚠️ The group appears unreliable. Most, if not all, of its alleged victims cannot be verified. WE HAVE DECIDED TO REMOVE ENTRIES FOR THIS GROUP
RLUpdated: N/A
View profile →APT GROUPfinancial
N3tw0rm ransomware group is linked to Iran by many security researchers especially for the fact that the group targeting only Israeli companies. Like other ransomware groups, N3tw0rm has a data leak site in the darknet. Due to the low ransom price the group requested and lack of response to negotiations, some security researchers believe that the N3tw0rm group's main goal is to be used for sowing chaos for Israeli interests and not for profit.
Infra: 🔗 n3twormruynhn3oetmxv…
RLUpdated: N/A
View profile →APT GROUPfinancial
VECT is a RaaS group that launched its affiliate program in December 2025 with a five-tier revenue-sharing model and a formal partnership with BreachForums; its VECT 2.0 payload contains a critical encryption flaw that irreversibly destroys files larger than 128 KB rather than encrypting them.
Infra: 🔗 bu7zr6fotni3qxxoxlcm…🔗 158.94.210.11.…🔗 vectordntlcrlmfkcm4a…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Donut Leaks (D0nut) is a data-extortion group active since August 2022 that developed its own ransomware encryptor, linked to attacks on Greece's DESFA gas company and Continental, believed to be an affiliate of multiple RaaS operations who pivoted to running an independent extortion platform.
Infra: 🔗 sbc2zv2qnz5vubwtx3ao…📁 doq32rjiuomfghm5a4ly…🔗 sbc2zv2qnz5vubwtx3ao…+4 more
RLUpdated: N/A
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Affiliates: Wazawaka
Infra: 🔗 nq4zyac4ukl4tykmidbz…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Affiliates:
<br/>@Mr.C
<br/>@Empathy
<br/>@jayze
<br/>@Widow
<br/>@Memory
<br/>
<br/>
Infra: 🔗 late.lol…
RSLUpdated: 2026-08-04
View profile →