Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters712 entities
APT GROUPfinancial
Underground ransomware is deployed by the Russia-based RomCom group (Storm-0978) and has victimized companies across multiple industries since July 2023 by exploiting CVE-2023-36884, encrypting files without changing extensions and deleting Volume Shadow Copies and Windows event logs in double-extortion campaigns.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Arvin Club is a threat actor with hacktivist leanings that first appeared in May 2021, primarily publishing stolen data via a TOR site and Telegram rather than deploying file-encrypting ransomware, targeting government, education, and banking sectors globally including Iranian government entities.
Infra: 🔗 3kp6j22pz3zkv76yutct🔗 arvinc7prj6ln5wpd6yy
RSLUpdated: N/A
View profile →
APT GROUPfinancial
rabbit hole — tracked by MISP Galaxy (ransomware).
Infra: 🔗 z5jixbfejdu5wtxd2bal
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
ransom corp — tracked by MISP Galaxy (ransomware).
Infra: 🔗 sewo2yliwvgca3abz565
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 moishddxqnpdxpababec
RSLUpdated: N/A
View profile →
APT GROUPfinancial
ra group — tracked by MISP Galaxy (ransomware).
Infra: 🔗 pa32ymaeu62yo5th5mra🔗 hkpomcx622gnqp2qhenv🔗 raworldw32b2qxevn3gp+1 more
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
superblack — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Brain Cipher emerged in July 2024. Both Windows and Linux variants are available. Brain Cipher using the leaked build of LockBit Black for their operations. The group suspected to have exploited CVE-2023-28252 (Microsoft Windows CLFS Driver Privilege Escalation Vulnerability). The Ransom demand ranges from $150,000 to $1,00,0000. Demand to be paid with Monero (XMR) cryptocurrency. In 2025, they have shifted their new Negotiation portal to new server with vanity TOR Domain starting with 'brain'.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Arkana is a ransomware group that emerged in early 2025 and gained attention by claiming an attack on U.S. broadband provider WideOpenWest (WOW!), operating a three-phase ransom/sale/leak extortion model primarily focused on telecom and internet service providers.
RLUpdated: N/A
View profile →
abrahams ax
Technical ID: abrahams_ax
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 abrahamm32umasogaqoj
RSLUpdated: N/A
View profile →
APT GROUPfinancial
ironchain — tracked by MISP Galaxy (ransomware).
Infra: 💬 ironchaindecrypt7xfz
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
satancd — tracked by MISP Galaxy (ransomware).
Infra: 💬 mzg4llxp4kaf4qq5s4hl
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker avoids executable files, probably to avoid rendering the targeted system unusable for paying the ransom. It uses a combination of AES and RSA-2048, and reportedly appends extensions such as .encrypted, .bomber, .boroff, .breakingbad, .locker16, .newlock, .nlocker, and .skynet.
Infra: 🔗 kwvhrdibgmmpkhkidrby💬 kwvhrdibgmmpkhkidrby
RSLUpdated: N/A
View profile →
APT GROUPfinancial
soleenya — tracked by MISP Galaxy (ransomware).
Infra: 🔗 xzbltrroh4ocknyi7kj2
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 powerj7kmpzkdhjg4szv
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 6dtxgqam4crv6rr6.oni💬 i3ezlvkoi7fwyood.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 mrv44idagzu47oktcipn
RSLUpdated: N/A
View profile →
APT GROUPfinancial
silent ransom — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
homeland — tracked by MISP Galaxy (ransomware).
Infra: 🔗 homelandjustice.ru
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 sekhmetleaks.top🔗 rlmuybcg5h5gaatr.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Gunra is a financially motivated ransomware group that emerged in April 2025, using double-extortion tactics against real estate, pharmaceuticals, and manufacturing sectors across Japan, Egypt, Panama, Italy, and Argentina, deploying separate Windows and Linux variants with a strict five-day payment deadline.
Infra: 🔗 gunrabxbig445sjqa535💬 2bw7r32r5eshwk2h7uek💬 jzbhtsuwysslrzi2n5is+9 more
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
🚨 This is a fake group with fake victims.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Direct Extortion Double Extortion
RLUpdated: N/A
View profile →
APT GROUPfinancial
bober — tracked by MISP Galaxy (ransomware).
Infra: 💬 myosbja7hixkkjqihsjh
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
DarkLeakMarket is a dark web data leak marketplace active since at least 2019 that sells stolen data sourced from ransomware groups and hacking forums, with 39 known victim organizations; it operates more as a data resale market than a traditional ransomware operator.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Anubis is a ransomware-as-a-service group active since December 2024 that targets healthcare, engineering, construction, and professional services sectors, offering affiliates a flexible revenue split model and an optional destructive "wipe mode" alongside standard encryption.
Infra: 🔗 om6q4a6cyipxvt7ioudx🔗 anubisyfkh5rixydjpoo
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak portal and claiming victims across insurance, healthcare, aerospace, legal, and retail sectors in at least six countries.
Infra: 🔗 dcarryhaih5oldidg3tb
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
krypt — tracked by MISP Galaxy (ransomware).
Infra: 💬 decryptjhpol6zezc72x💬 decryptrrx2fojgfcof3
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
invaderx — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Darky Lock is a commodity-style ransomware strain first identified in July 2022, derived from publicly available Babuk source code. Victim systems undergo file encryption with an added “.darky” extension, and a “Restore-My-Files.txt” ransom note is placed in all impacted locations. The malware attempts to disable backup mechanisms, including shadow copies and specific applications. Its distribution leverages phishing and trojanized installers, complemented by payloads dropped via frameworks like Empire, Metasploit, and Cobalt Strike.
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
CryptBB is a ransomware group with likely Russian origins active around 2023, whose payload appends random extensions to encrypted files and whose data leak site copied 8Base's source code, listing approximately 8 victims as of September 2023.
Infra: 🔗 crypuglupv3bsqnbt5ru🔗 basemmnnqwxevlymli5b
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
turkish crypter — tracked by MISP Galaxy (ransomware).
Infra: 💬 vbzxvet5nbga7jblaksu
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
doommageddon — tracked by MISP Galaxy (ransomware).
Infra: 🔗 iacjvmxjb2ivqkxxzmde
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
wiki ransomware — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
triple x — tracked by MISP Galaxy (ransomware).
Infra: 🔗 ojcmpbdncjo5dhaxxll4📁 6qqz6m3b6htudohg2mlf
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
DarkVault is a data-exfiltration and double-extortion group first identified in late 2023, targeting medium-to-large organizations in finance, professional services, legal, and technology sectors across Europe, the UK, and North America, with a suspected connection to LockBit.
Infra: 🔗 mdhby62yvvg6sd5jmx5g📁 kkvanuf7on5uglvdhihy
RSLUpdated: 2026-08-04
View profile →