Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters712 entities
Abrahams Ax
Technical ID: Abrahams_Ax
APT GROUPfinancial
Abraham's Ax is an Iranian-linked hacktivist persona tied to Moses Staff that emerged in November 2022, primarily targeting Saudi Arabian government institutions for geopolitical reasons related to Saudi-Israeli normalization, using destructive wiper malware and data leak tactics rather than financial ransomware.
RLUpdated: N/A
View profile →
APT GROUPfinancial
sundawn — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Desolator is a ransomware group that emerged in May 2025, targeting construction and engineering firms in Latin America and Europe and technology companies in Asia, actively recruiting pen testers, initial access brokers, and social engineers via dark web forums to build an affiliate program.
Infra: 🔗 po4tq2brx4rgwbdx4mac
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Vice Society ransomware appends the .v-society extension when encrypting Linux machines. Running a leak site on the darkweb, Possible relations with "HelloKitty"
Infra: 🔗 4hzyuotli6maqa4u.oni🔗 vsociethok6sbprvevl4🔗 ml3mjpuhnmse4kjij7gg+5 more
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
The group appears unreliable. Most, if not all, of its alleged victims cannot be verified and appear to be randomly selected organizations. WE HAVE DECIDED TO REMOVE ENTRIES FOR THIS GROUP
Infra: 🔗 oaptxiyisljt2kv3we2w
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
RAMP (Russian Anonymous Marketplace) was a Russian-speaking dark web forum founded in 2021 that served as a central marketplace and recruitment hub for ransomware operators, affiliates, and initial access brokers — not a ransomware group itself but the backbone of the RaaS ecosystem; it was seized by the FBI in January 2026.
Affiliates: LockBitSupp • Wazawaka
Infra: 🔗 wavbeudogz6byhnardd2🔗 rampjcdlqvgkoz5oywut🔗 ramp4u5iz4xx75vmt6nk+1 more
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 k7kzrgcoxsjm7fujj5vo
RSLUpdated: N/A
View profile →
APT GROUPfinancial
darkhav0c — tracked by MISP Galaxy (ransomware).
Infra: 🔗 afiocd14efgh5hu8ijkl
RSLUpdated: 2026-08-04
View profile →
la piovra
Technical ID: la_piovra
APT GROUPfinancial
ℹ️ La Piovra Ransomware is an exercise of the company Offensive Security (also known as OffSec)
RLUpdated: N/A
View profile →
APT GROUPfinancial
Risen, which is a fully optimized and high-speed program, is the result of our years of experience in the field of malware writing. Risen is written in C language and completely using winapi. We produced many products with different features and options, but we came to the conclusion that none of the options have the benefit and efficiency they should; So, instead of spending time on useless and inefficient options, we decided to spend all our time on the strength, speed and security of our cryptography, and that's how we created Risen. Software features in version 1: <br/> <br/> <br/> -Encryption security, utilizing Chacha20 and RSA 2048 algorithms. <br/> -High encryption speed and software optimization <br/> -compatible with all versions of Windows on any hardware without any issues. <br/> -Automatic option settings, its easy to using and default configuration set to the best mode. <br/> -Utilization of Threadpool method and queue creation for encryption. <br/> -A powerful file unlocker, unlock files without closing processes. <br/> -Safe deletion of backups, shadow copies, and all windows logs. <br/> -A blog, Leak website, and management panel on TOR for leaking data of non-paying companies. <br/>
Infra: 🔗 s2wk77h653qn54csf4gp🔗 o6pi3u67zyag73ligtsu🔗 cqqzfmdd2fwshfyic6sr
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
redact — tracked by MISP Galaxy (ransomware).
Infra: 🔗 neclc36yt4yaa5lv54kh📁 ursba4dbibo27dtwtgy3
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Bluebox is a data extortion group that emerged in December 2024, employing double-extortion tactics against victims primarily in France, Sweden, and the French Caribbean, and threatening to notify data protection authorities to add regulatory pressure on victims.
Infra: 🔗 zu3wfrmrkl4ltqqnpt3o
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Connected to GD Lockersec and Babuk-Bjorka. <br/> <br/>Group is aka SalanLock (from typo on victim pages).
Infra: 🔗 212.24.99.211.🔗 5g2e.l.time4vps.clou🔗 mgeegnexyhhn5dpqewih+4 more
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 eraleignews.com🔗 wn6vonooq6fggjdgyocp🔗 basheqtvzqwz4vp6ks5l+12 more
RSLUpdated: N/A
View profile →
APT GROUPfinancial
radiant group — tracked by MISP Galaxy (ransomware).
Infra: 🔗 trfqksm6peaeyz4q6egx
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums.
Infra: 🔗 54bb47h5qu4k7l4d7v5i🔗 54bb47h.blog
RLUpdated: N/A
View profile →
lockbit3 fs
Technical ID: lockbit3_fs
APT GROUPfinancial
LockBit 3.0 ("LockBit Black"), active since June 2022, is the third iteration of the LockBit RaaS platform incorporating code from BlackMatter ransomware, featuring modular encrypted payloads that evade analysis and targeting Windows and VMware ESXi environments across all sectors globally.
RLUpdated: N/A
View profile →
APT GROUPfinancial
malphas — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
LockBit 2.0 is the second major iteration of the LockBit RaaS platform, launched in mid-2021, introducing automated domain-wide encryption via Active Directory Group Policy and claiming the fastest encryption speed among ransomware families, accounting for 46% of ransomware breach events in early 2022.
RLUpdated: N/A
View profile →
APT GROUPfinancial
bavacai — tracked by MISP Galaxy (ransomware).
Infra: 🔗 t33zoj4qwv455fog7qnb
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
pyrx — tracked by MISP Galaxy (ransomware).
Infra: 🔗 c2mdhim6btaiyae3xqth🔗 c2mdhim6btaiyae3xqth🔗 c2mdhim6btaiyae3xqth+1 more
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
CMD is a new kind of company that specializes in corporate system security and in identifying vulnerabilities across all aspects of the software used by a company. CMD operates on a global scale recognizing the critical importance of timeliness and confidentiality.
RLUpdated: N/A
View profile →
APT GROUPfinancial
BlackSuit is a type of malicious software classified as ransomware. Its operation involves multifaceted extortion, encrypting and exfiltrating victim data, and hosting public data leak sites for victims who fail to meet its demands. BlackSuit’s activities first began in early May 2023. Designed to prevent access to files by encrypting them, this ransomware appends the “.blacksuit” extension to the names of all affected files. Furthermore, it changes the desktop wallpaper and creates a ransom note file named “README.BlackSuit.txt.” This threat actor targets large corporations, small and medium-sized enterprises (SMEs), with no apparent specific discrimination regarding industry or type of victim.
Infra: 🔗 weg7sdx54bevnvulapqu🔗 c7jpc6h2ccrdwmhofuij📁 nz2ihtemh2zli2wc3bov+15 more
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
deadbydawn — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victims in Indonesia, Italy, Venezuela, and the US, with minimal public threat-intelligence coverage.
Infra: 🔗 bl4cktorpms2gybrcyt5
RLUpdated: N/A
View profile →
APT GROUPfinancial
LV ransomware group main message: "Here are companies which didn't meet consumer data protection obligations. They rejected to fix their mistakes, they rejected to protect this data in the case when they could and had to ptotect it. These companies prefered to sell their private information, their employees' and customers' personal data". Security researchers claim that the LV group is utilizing the REvil ransomware group malware. The LV group claim to have compromised the corporate network of Groupe Reorev.
Infra: 🔗 rbvuetuneohce3ouxjlb🔗 4qbxi3i2oqmyzxsjg4fw💬 l55ysq5qjpin2vq23ul3
RLUpdated: N/A
View profile →
APT GROUPfinancial
0day — tracked by MISP Galaxy (ransomware).
Infra: 🔗 odaygplp3zhyx7zl45eg
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
himalayaa — tracked by MISP Galaxy (ransomware).
Infra: 🔗 ohu6eschnuhxfg46wvco
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
farattack — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
elonmusknow — tracked by MISP Galaxy (ransomware).
Infra: 🔗 leaksbcwijsbkxcx76s2
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Abyss (also known as Abyss Locker) is a ransomware operation first identified in March 2023, derived from the Babuk source code, that targets Windows and Linux/VMware ESXi systems using double-extortion tactics across healthcare, manufacturing, finance, and technology sectors — predominantly in North America.
RLUpdated: N/A
View profile →
APT GROUPfinancial
phantom — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
BlackNevas ransomware — also referred to as “Trial Recovery” — was first observed in November 2024. It is a direct derivative of the Trigona ransomware family and continues the lineage's focus on extortion over public shaming. BlackNevas operators support a double-extortion model, encrypting files using AES-256 with RSA-4112-protected keys, and appending the .-encrypted or .ENCRYPTED file extension to affected files. Hybrid payloads are available for Windows, Linux, NAS, and VMware ESXi platforms. <br/> <br/>While BlackNevas does not host its own data leak site, it reportedly collaborates with other ransomware groups for data publication — known partners include Kill Security, Hunters International, DragonForce, Blackout, Embargo Team, and Mad Liberator. The group has predominantly targeted large enterprises in sectors such as finance, telecommunications, manufacturing, healthcare, and legal. Initial access is commonly achieved via phishing or exploitation of vulnerabilities, with lateral movement facilitated through SMB enumeration and optional LAN-wide propagation.
Infra: 🔗 ctyfftrjgtwdjzlgqh4a
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
inc ransom — tracked by MISP Galaxy (ransomware).
Infra: 🔗 incblog7vmuq7rktic73🔗 incapt.blog🔗 incapt.su+7 more
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
CiphBit is a ransomware-as-a-service group active since April 2023, targeting small-to-mid-sized businesses across the UK, Europe, and North America with 38 known victims, employing a data-broker model with selective free leaks to pressure victims alongside standard double extortion.
Infra: 🔗 ciphbitqyg26jor7eeo6💬 sonarmsng5vzwqezlvtu💬 ciphbitekvxj27jmtw5s
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Booba
RLUpdated: N/A
View profile →