Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters712 entities
APT GROUPfinancial
LostTrust is a double-extortion ransomware operation that emerged in March 2023 and publicized over 50 victims within days of launching its leak site in September 2023, believed to be a rebrand of the MetaEncryptor gang, primarily targeting manufacturing, professional services, construction, and education sectors with 71% of known victims in the US.
Infra: 🔗 hscr6cjzhgoybibuzn2x…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
MyDecryptor is a low-profile ransomware group with minimal public documentation, appearing on ransomware tracking platforms but not the subject of major threat intelligence reporting, suggesting it is a small or relatively inactive operation.
Infra: 🔗 5s4ixqul2enwxrqv.oni…
RLUpdated: N/A
View profile →APT GROUPfinancial
Crypto24 is a double-extortion ransomware-as-a-service group that surfaced on the RAMP forum in mid-2024, targeting large organizations in financial services, healthcare, manufacturing, and technology across Asia, Europe, and North America, with notable victims including CMC Group, Vietnam's second-largest ICT conglomerate.
Infra: 🔗 j5o5y2feotmhvr7cbcp2…🔗 j5o5y2feotmhvr7cbcp2…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
CryLock (originally known as Cryakl/Fantomas since 2014) is a ransomware operation run by a Russian couple who targeted roughly 400,000 victims over eight years and earned over €64 million in Bitcoin; the operators were arrested in Spain in June 2023 and extradited to Belgium.
Infra: 🔗 d57uremugxjrafyg.oni…
RLUpdated: N/A
View profile →APT GROUPfinancial
timc — tracked by MISP Galaxy (ransomware).
Infra: 🔗 rzzfiwoop67jrxadngcy…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 zhuobnfsddn2myfxxdqt…
RSLUpdated: N/A
View profile →APT GROUPfinancial
skira team — tracked by MISP Galaxy (ransomware).
Infra: 🔗 mtgc3qvyedjnfu7cen2z…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Shadow is a low-profile ransomware group tracked on ransomware monitoring platforms with limited public documentation; specific attribution details regarding its targets, origin, or scale remain sparse in published threat intelligence reports.
Infra: 🔗 lc65fb3wrvox6xlyn4hk…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
spy corporate — tracked by MISP Galaxy (ransomware).
Infra: 🔗 spycorp.pro…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 yboa7nidpv5jdtumgfm4…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Arcus Media is a ransomware-as-a-service group that emerged in May 2024, employing double extortion with ChaCha20 + RSA-2048 encryption and recruiting affiliates via a referral-based vetting process, claiming 50+ victims across manufacturing, healthcare, retail, and business services globally.
RLUpdated: N/A
View profile →APT GROUPfinancial
Argonauts is a ransomware group that emerged in September 2024, operating a double-extortion model targeting logistics, healthcare, energy, and telecom sectors, with approximately 13 claimed victims tracked via a TOR-based leak site.
RLUpdated: N/A
View profile →APT GROUPfinancial
Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support for Windows, Linux, ESXi, and NAS device encryption, and became notable for a public feud with rival group 0APT in which each breached and leaked the other's operator data.
Infra: 🔗 krybitxdpxohsmjooeb3…🔗 krybitx3fh5krdnhegyp…🔗 krybitqsdzwmhnitvwuh…+1 more
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
j group — tracked by MISP Galaxy (ransomware).
Infra: 🔗 twniiyed6mydtbe64i5m…💬 w4d5aqmdxkcsc2xwcz7w…📁 share.jtor.xyz…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
VFOKX is a low-profile ransomware group tracked on ransomware monitoring platforms with very limited public documentation and no detailed analysis or named victims published by major threat intelligence vendors.
Infra: 🔗 vfokxcdzjbpehgit223v…🔗 746pbrxl7acvrlhzshos…
RLUpdated: N/A
View profile →APT GROUPfinancial
RA Group, also known as RA World, first surfaced in April 2023, utilizing a custom variant of the Babuk ransomware.
RLUpdated: N/A
View profile →APT GROUPfinancial
3am — tracked by MISP Galaxy (ransomware).
Infra: 🔗 threeamkelxicjsaf2cz…📁 ulkvlj5sirgrbnvb4hvb…💬 threeam7fj33rv5twe5l…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Cs‑137 is a newly observed ransomware strain that first appeared in January 2025. It employs the ChaCha20 cipher for encryption and appends obfuscated filenames with a random 10-character alphanumeric identifier while preserving the original file extension. In its current testing phase, it drops a ransom note with a randomized filename (e.g. ABCDEF-README.txt) and sets a randomly named image file as the desktop wallpaper. The note references a Tor-based extortion portal—though access is not yet active, indicating the operation’s early development stage. The strategy suggests single-extortion behavior, focused on disrupting access rather than data theft or leak threats.
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather than a broad affiliate program.
Infra: 🔗 direwolfcdkv5whaz2sp…📁 direwolfgpyqohwxwoet…💬 direwolf66s5zealav7a…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Orca is a ransomware group that emerged in September 2024, identified as a variant of the Zeppelin malware family, targeting organizations in manufacturing and logistics across Taiwan, Tunisia, Austria, and France, claiming to avoid hospitals, government institutions, and non-profits.
Infra: 🔗 orca66hwnpciepupe562…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
AgainstTheWest (ATW) is a hacktivist group active since October 2021 that targets governments and corporations perceived as authoritarian, breaching organizations like Alibaba, Sberbank, and Gazprom using custom ransomware and wiper malware for ideological disruption rather than financial profit.
RLUpdated: N/A
View profile →APT GROUPfinancial
deadlock — tracked by MISP Galaxy (ransomware).
Infra: 🔗 deadlock.liveblog365…🔗 deadblogdbdu5wprek7w…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 monteoamwxlutyovf7ox…🔗 monteoamwxlutyovf7ox…
RSLUpdated: N/A
View profile →APT GROUPfinancial
WALocker is an emerging ransomware group that came to attention in 2025, targeting organizations in Southeast Asia and government entities, with a notable attack breaching Myanmar's Union Civil Service Board and exposing data on approximately 200,000 government officials.
Infra: 🔗 weepangrbqjfsxd2noz4…📁 am7hswbi46e3ozxec3ms…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
WereWolves is a Russian-speaking ransomware group that emerged in May 2023, using a modified LockBit 3 (Black) encryptor, operating an unusual public website that actively recruits new members and offers a bug-bounty program with rewards up to $1 million, with at least 26 victims across Russia, the US, and Europe.
Infra: 🔗 werewolves.pro…🔗 weerwolven.biz.…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
waissbein — tracked by MISP Galaxy (ransomware).
Infra: 📁 samu747og2fgxujardbh…📁 syympi25sxgm55kyk5wk…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
World Leaks emerged in January 2025 as a rebrand of the Hunters International ransomware operation, shifting its focus from file encryption to solely stealing sensitive data and threatening to leak it unless a ransom is paid
Infra: 🔗 worldleaksartrjm3c6v…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Unlike many other groups, Silent claims to operate with a high level of anonymity and discretion. According to their own statement, they avoid public negotiations and encrypt minimal data. Instead, their focus is on stealing valuable confidential corporate information — and either selling it to competitors, on the dark web, or publishing it selectively.
Infra: 🔗 silentbgdghp3zeldwpu…📁 jf2zjpxfh3sob5xr6uc5…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Ranstreet is a low-profile ransomware group with very limited public documentation, appearing in ransomware tracking lists but without major vendor research reports or significant attributed attacks.
RLUpdated: N/A
View profile →APT GROUPfinancial
xleaks — tracked by MISP Galaxy (ransomware).
Infra: 💬 fqb6joilbbd26d574bfa…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
spirigatito — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Hellcome Bjorkanism
Infra: 🔗 netleaks.net…📁 wki2kiikvycnowcygyz7…📁 3lce6cov7sj7vovrr3cb…+3 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
abyss-data — tracked by MISP Galaxy (ransomware).
Infra: 🔗 3ev4metjirohtdpshsql…📁 ufvi7hpcawesdklmomme…📁 t7ogwvu74a6flssns55y…+44 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
ArcRypt (also known as ARCrypter or ChileLocker) was first identified in August 2022, originally targeting government entities in Latin America and subsequently expanding globally. The group employs a single-extortion model—there is no evidence of a data-leak threat or RaaS ecosystem. The malware encrypts files using extensions such as .crypt, .crYpt, and .crYptA3, and uniquely drops the ransom note before commencing encryption. It has variants for both Windows and Linux, including a Go-based Linux version. Communication with victims occurs via Tor-based portals, evolving over time from a single shared site to individualized mirror sites for each victim. In some cases, threat actors have instructed victims to contact them using Tox, creating a Tox profile for communication. Targets have included Chile’s government infrastructure, Colombia’s Invima agency, and organizations in China and Canada.
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
run some wares — tracked by MISP Galaxy (ransomware).
Infra: 🔗 rnsmwareartse3m4hjsu…📁 nidzkoszg57upoq7wcal…🔗 oow7rehrxlzpy6vh3hez…+3 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
2023Lock is a ransomware strain first observed in January 2024, believed to be an evolution of the Venus and Zeoticus families and a direct precursor to the later TrinityLock variant. It employs a hybrid encryption method combining XChaCha20 and curve25519xsalsa20poly1305, appending the “.2023lock” extension to encrypted files. Upon infection, it delivers ransom notes in HTML, TXT, and HTA formats containing decryption instructions. Unlike many modern ransomware groups, there is no evidence that 2023Lock engages in double extortion or data exfiltration, operating purely through file encryption to pressure victims into payment. Its codebase and operational patterns strongly align with TrinityLock, which emerged a few months later with more sophisticated extortion tactics.
RSLUpdated: 2026-08-04
View profile →