Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters712 entities
APT GROUPfinancial
NightSpire is a ransomware group that first emerged in March 2025 and rapidly claimed over 250 victims across retail, manufacturing, healthcare, finance, and education sectors in the US, France, India, Taiwan, and Japan, using aggressive double-extortion with ransom deadlines as short as two days.
Affiliates: Phantom • Reaper • Volt • Blaze +2
Infra: 🔗 nspireyzmvapgiwgtuoz…🔗 nspireyzmvapgiwgtuoz…🔗 a2lyiiaq4n74tlgz4fk3…+5 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
sensayq — tracked by MISP Galaxy (ransomware).
Infra: 🔗 gmixcebhni6c3kcf5m7x…💬 ppzmaodrgtg7r6zcputd…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
money message — tracked by MISP Galaxy (ransomware).
Infra: 🔗 blogvl7tjyjvsfthobtt…💬 clientcuworpelkdwecu…📁 6xkylzxoxpd6bnl5ymhr…+26 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
schoolboys — tracked by MISP Galaxy (ransomware).
Infra: 💬 pnanlicgxkku2aonwsg2…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
providence — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Weyhro is a data-extortion group (relying on data theft and leak threats without file encryption) that launched a Tor leak site in March 2025, focusing on manufacturing, financial services, and real estate sectors with victims in the US, Italy, and Canada.
Infra: 🔗 xtxtpqpyaaek4p4525ks…📁 p7teg7yh2dwxg2tsbgnk…📁 p7teg7yh2dwxg2tsbgnk…+2 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
black x — tracked by MISP Galaxy (ransomware).
Infra: 🔗 blackxppq2jvqyg4slyg…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Dunghill Leak is the data extortion site operated by the Dark Angels ransomware group, active since early 2023, targeting large enterprises across healthcare, finance, industrial, and technology sectors using a highly selective non-affiliate model, and responsible for a record-breaking $75 million ransom payment in 2024.
Infra: 🔗 p66slxmtum2ox4jpayco…🔗 nsalewdnfclsowcal6kn…🔗 5kvv27efetbcqgem4tl7…+4 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
LunaLock emerged in September 2025 targeting creative and digital platforms, notably breaching an illustrator marketplace and a Mexican ISP, and is notable for threatening to submit stolen artwork to AI companies for training if the ransom is not paid.
Infra: 🔗 lunalockcccxzkpfovwz…💬 lunachataclss7bvlhk5…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
sharpboys — tracked by MISP Galaxy (ransomware).
Infra: 🔗 sharpboyz.io…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 scbrksw5fgjtujc2ah42…
RSLUpdated: N/A
View profile →APT GROUPfinancial
RunSomeWares is an emerging ransomware group that surfaced in February 2025 with initial victims across supply-chain services, financial services, accounting, and manufacturing, with unclear deployment of an encryptor vs. pure data-theft extortion.
RLUpdated: N/A
View profile →APT GROUPfinancial
Insane is a relatively obscure ransomware family first reported in late 2021, with few confirmed incidents in public threat intelligence. It encrypts victim files using symmetric encryption (AES) combined with RSA for key protection and appends the .insane extension to affected files. The ransom note, typically named INSANE_README.txt, directs victims to contact the operators via email for decryption instructions. Based on limited reporting, Insane does not appear to operate as a Ransomware-as-a-Service (RaaS) platform; instead, it seems to be deployed by the core operators in targeted attacks. Initial access methods are not well-documented, but suspected vectors include phishing attachments and exploitation of exposed RDP services. The group’s small footprint in open-source intelligence suggests limited distribution or use in highly selective campaigns.
Infra: 🔗 nv5lbsrr4rxmewzmpe25…🔗 gfksiwpsqudibondm6o2…🔗 gfksiwpsqudibondm6o2…+3 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Apos is a data-broker extortion group that surfaced in April 2024, focusing on data exfiltration and threatening to publish or sell stolen information rather than encrypting files, targeting technology, healthcare, manufacturing, telecom, and government sectors across multiple countries.
Infra: 🔗 apos.blog…🔗 yrz6bayqwhleymbevite…🔗 yrz6bayqwhleymbevite…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
blackfield — tracked by MISP Galaxy (ransomware).
Infra: 🔗 xcou7t6a4qlecsr7ipmx…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
XINOF (also known as Fonix/FonixCrypter) is a RaaS operation that began in June 2020 with no upfront affiliate cost and four methods of encryption per file; the operators shut down the service and released the master decryption key in January 2021, allowing free decryption for all victims.
Infra: 🔗 wj3b2wtj7u2bzup75tzh…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Haron appeared in July 2021 as a ransomware-as-a-service operation heavily borrowing from the defunct Avaddon ransomware (copying ransom notes and leak site structure) and built on the Thanos ransomware builder, targeting enterprise organizations with a six-day negotiation window.
Infra: 💬 ft4zr2jzlqoyob7yg4fc…🔗 midasbkic5eyfox4dhni…
RSLUpdated: N/A
View profile →APT GROUPfinancial
.crYpt
<br/>MD5: 54EFAC23D7B524D56BEDBCE887E11849
<br/>
<br/>Babuk Variant
Infra: 💬 lhwhi2kmewfas6tk47ps…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
DeathGrip is a Ransomware-as-a-Service (RaaS) that emerged around June 2024, offering malware payloads built with leaked LockBit 3.0 and Yashma/Chaos builders. Designed to lower technical barriers, it enables even low-skilled operators to deploy highly capable ransomware attacks. DeathGrip campaigns typically employ AES-256 encryption, delete shadow copies and recovery features, and modify system settings to hinder restoration. Earlier infections include low-tier ransom demands (e.g., around $100), reflecting entry-level targeting, though its flexible tooling allows a range of payload configurations.
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies including insurance firm Shirbit and hosting provider Cyberserve, leaking medical records of 290,000 patients, using extortion as a tool of geopolitical disruption rather than purely for financial gain.
Infra: 🔗 544corkfh5hwhtn4.oni…🔗 blackshadow.cc…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Dragon Ransomware, is promising rapid and customizable ransomware operations for Windows systems. Key features include a compact 50KB file size, ultra-fast encryption speed, and a builder tool that allows users to personalize ransomware configurations. The tool will be available to the public once the team reaches 1,000 subscribers on their channel, signaling a potential rise in availability to threat actors.
RLUpdated: N/A
View profile →APT GROUPfinancial
Nokoyawa is a double-extortion ransomware group that launched a RaaS program in 2022 (operated by threat actor "farnetwork"), primarily targeting businesses in South America across healthcare, financial services, government, and manufacturing, gaining significant attention in 2023 for exploiting a Windows CLFS zero-day (CVE-2023-28252).
Infra: 🔗 lirncvjfmdhv6samxvvl…🔗 6yofnrq7evqrtz3tzi3d…🔗 nokoleakb76znymx443v…+25 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
piratelock — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities in Canada, France, and Germany before expanding to telecommunications, mining, and manufacturing sectors, operating a double-extortion model with a data leak site.
Infra: 🔗 black3gnkizshuynieig…📁 4qyjonpyksc52bc3fsgf…📁 ao5oo2luy6avdfomyw7h…+6 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
dAn0n is a data-extortion actor that first appeared in April 2024. Operating primarily in a leak-focused extortion model, they publish stolen data on a Tor-hosted site rather than encrypting files. Their victims include organizations across sectors like business services, technology, healthcare, transportation, and legal—all largely based in the United States, with a few in Ireland and South Korea. Activity surged in May 2024, landing them in the top 10 most active ransomware actors that month. Despite limited branding efforts, their smaller operational footprint has allowed for swift, targeted breaches that prioritize rapid data exposure over elaborate cryptographic tactics.
Infra: 🔗 2c7nd54guzi6xhjyqrj5…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 weepangrbqjfsxd2noz4…
RSLUpdated: N/A
View profile →APT GROUPfinancial
imn crew — tracked by MISP Galaxy (ransomware).
Infra: 🔗 imncrewwfkbjkhr2oyle…🔗 ho7yirtlkkkytbzkn4bk…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
killsec3 — tracked by MISP Galaxy (ransomware).
Infra: 🔗 ks5424y3wpr5zlug5c7i…🔗 ks5424y3wpr5zlug5c7i…📁 xo4o2o2ezgydykywn6zk…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
nblock — tracked by MISP Galaxy (ransomware).
Infra: 💬 nblockn6jjp3xxh2do4c…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
mydata — tracked by MISP Galaxy (ransomware).
Infra: 🔗 mydatae2d63il5oaxxan…📁 xszpovfd3q52omk5larj…📁 ot3vo3od2pajc7ymxdk6…+2 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
QLocker was a financially motivated ransomware operation active in 2021 that exclusively targeted QNAP NAS devices exposed to the internet, exploiting a hard-coded credentials vulnerability to compress files into password-protected 7-Zip archives and demanding roughly $400 per victim, netting approximately $350,000 in a single month.
Infra: 💬 gvka2m4qt5fod2fltkjm…
RSLUpdated: N/A
View profile →APT GROUPfinancial
c3rb3r — tracked by MISP Galaxy (ransomware).
Infra: 💬 j3qxmk6g5sk3zw62i2yh…💬 c3rb3rnow2alp26exjwl…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
RebornVC is a rebrand of RansomedVC re-emerging in July 2025 under new leadership, using data auctions, direct extortion, and double extortion techniques with ransom demands ranging from $10,000 to $1,000,000, with confirmed victims in the US and Brazil.
RLUpdated: N/A
View profile →APT GROUPfinancial
This is not a ransomware group but a data broker
Infra: 🔗 e27z5kd2rjsern2gpguk…🔗 cybertube.video…🔗 e27z5kd2rjsern2gpguk…+4 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".
Infra: 🔗 griefcameifmv4hfr3au…💬 payorgz3j6hs2gj66nk6…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Qiulong is a ransomware group that emerged around April 2024 primarily targeting Brazilian organizations using double extortion and unique tactics such as publishing identity documents of victims' family members to pressure payment.
Infra: 🔗 62brsjf2w77ihz5paods…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
KittyKatKrew is a newly emerged ransomware group first identified in early 2026, using both direct and double-extortion methods against US targets including the Arkansas State Crime Laboratory, operating under the alias KKK with Telegram and X/Twitter communication channels.
Infra: 🔗 jzdonx6ak2swiitotgaj…🔗 vs6ccwled72hwmescxr2…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
offwhite — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
threatmarket — tracked by MISP Galaxy (ransomware).
Infra: 🔗 hi6bo2aihmuzkaj6gi6s…
RSLUpdated: 2026-08-04
View profile →