Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters712 entities
APT GROUPfinancial
AiLock is a ransomware operation that emerged in early 2025, marketing itself as AI-assisted ransomware using a hybrid ChaCha20/NTRUEncrypt encryption scheme and double-extortion tactics, actively recruiting affiliates and threatening regulatory reporting if ransoms are unpaid.
RLUpdated: N/A
View profile →
APT GROUPfinancial
BlackNevas is a ransomware group first observed in November 2024, believed to be derived from the Trigona ransomware family, targeting telecommunications, manufacturing, medical, and legal industries primarily in Asia-Pacific, the UK, Italy, and Lithuania using double-extortion with a dual AES/RSA encryption scheme.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
lyrix — tracked by MISP Galaxy (ransomware).
Infra: 💬 4hfwnas3oexnkdimschy
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
nasir security — tracked by MISP Galaxy (ransomware).
Infra: 🔗 yzcpwxuhbkyjnyn4qsf4🔗 nasir.cc
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
toxic — tracked by MISP Galaxy (ransomware).
Infra: 💬 cwybfdfhstmmoaxmnz4o
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
INC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 200 victims in 2025 alone with no sector off-limits.
RLUpdated: N/A
View profile →
APT GROUPfinancial
naga — tracked by MISP Galaxy (ransomware).
Infra: 💬 nagapay2ypwzsj7gb2hl
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
LockData Auction is a dark web marketplace that emerged around May 2021 operating an invite-only stolen data auction portal, representing a shift toward pure data-theft extortion with auctions for stolen corporate data starting from $50,000, rather than a traditional ransomware encryptor operation.
Infra: 🔗 wm6mbuzipviusuc42kcg
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Crynox (sometimes referred to as “Crynox Ransomware”) appears to be a generic file-locker threat that appends .crynox to encrypted files and drops a ransom note (read_it.txt) instructing victims to contact crynoxWARE@proton.me. It seems to use RSA-4096 and AES for encryption and may change desktop wallpaper, but there's no evidence of double-extortion or leak site operation. Distribution methods cited include phishing, pirated software, and malicious websites.
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
HellCat is a ransomware-as-a-service group that formed in Q4 2024 and quickly became notable for high-profile attacks against Schneider Electric, Telefónica, and Israel's Knesset, primarily gaining initial access via stolen Jira credentials harvested by infostealer malware, targeting critical infrastructure and government entities.
Infra: 🔗 hellcakbszllztlyqbjz📁 r7i4vprxr2vznmhnnxj3🔗 hellcat.rw+2 more
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
ZeroLockerSec is a small ransomware group with very limited public documentation that became inactive by Q2 2025 with no recorded leak posts, suggesting a brief operational period before going dormant.
Infra: 🔗 ghfuviaplse6nbeowu7g
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
EP918 is a low-activity ransomware group listed in tracking databases with no confirmed victims and no publicly documented attacks or operational details.
Infra: 🔗 dg5fyig37abmivryrxlo
RLUpdated: N/A
View profile →
APT GROUPfinancial
wiper leak — tracked by MISP Galaxy (ransomware).
Infra: 🔗 discord.com
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
a former Conti team
RLUpdated: N/A
View profile →
APT GROUPfinancial
zircon — tracked by MISP Galaxy (ransomware).
Infra: 🔗 zircon7g4qp46d3gjhej
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Dark Power emerged in January 2023 as a ransomware group written in the Nim programming language, claiming 10 victims across eight countries within its first month across agriculture, education, healthcare, IT, and manufacturing sectors, demanding $10,000 ransoms payable in Monero.
RLUpdated: N/A
View profile →
APT GROUPfinancial
The Green Blood Group is an emerging ransomware operation first identified in early 2026 whose Go-based Windows payload uses ChaCha8 encryption and aggressively destroys backup and recovery options, targeting organizations in India, Senegal, Egypt, Colombia, and Belgium.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
MadLiberator is a ransomware group that emerged in mid-2024, known for erratic behavior including randomized ransom demands and unpredictable encryption patterns, targeting government entities including the Italian Ministry of Culture and using a data leak site to post exfiltrated files.
RLUpdated: N/A
View profile →
APT GROUPfinancial
CipherForce is a newly emerged ransomware group first detected in early 2026, operating a dark web leak site and targeting technology, business services, and logistics companies across the US, China, Vietnam, India, and UAE, with at least 6 claimed victims.
Infra: 🔗 o3ydbkayttkyg4iw2nc7🔗 22evxpggnkyrxpluewqs
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
luckbit — tracked by MISP Galaxy (ransomware).
Infra: 💬 luckbit53sdne5yd5vde
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
NetRunner is a ransomware group active from at least 2025 targeting diverse sectors including healthcare, telecommunications, manufacturing, and agriculture across Japan, Italy, the US, and Jordan, notably demanding a $100M ransom from Nippon Medical School Musashi Kosugi Hospital.
Infra: 🔗 netrunrsb3bivj5gnwaj📁 netrunrs65cn2yidokrm
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
TiMc is a ransomware group that emerged in early 2026, claiming high-impact attacks against Spanish IT services leader Seidor (1 TB+ data) and oncology organization Oncologica (100 GB+), targeting Business Services, Healthcare, and IT sectors with a focus on Spanish-speaking and European targets.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 decrypt5bub45vpr.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
RRansom is a low-profile ransomware group whose dark web leak site has been listed as offline in tracking directories, with very limited public threat intelligence available about its targets, tactics, or scale of operations.
Infra: 🔗 t2tqvp4pctcr7vxhgz5y
RLUpdated: N/A
View profile →
APT GROUPfinancial
locus — tracked by MISP Galaxy (ransomware).
Infra: 🔗 ugn5khvt4kitlivv4ddf
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Orion is a ransomware operation first observed in October 2025 that listed 13 alleged victims on a dark web leak site across financial services, manufacturing, and healthcare, though analysts determined its victim list was recycled from prior LockBit and BlackCat disclosures rather than fresh compromises.
Infra: 🔗 cjfntkj5qeizxowuy3sr
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
PwndLocker is a ransomware that was observed in late 2019 and is reported to have been used to target businesses and local governments/cities. According to one source, ransom amounts demanded as part of PwndLocker activity range from $175k USD to $650k USD depending on the size of the network. PwndLocker attempts to disable a variety of Windows services so that their data can be encrypted. Various processes will also be targeted, such as web browsers and software related to security, backups, and databases. Shadow copies are cleared by the ransomware, and encryption of files occurs once the system has been prepared in this way. Executable files and those that are likely to be important for the system to continue to function appear to be skipped by the ransomware, and a large number of folders mostly related to Microsoft Windows system files are also ignored. As of March 2020, encrypted files have been observed with the added extensions of .key and .pwnd. Ransom notes are dropped in folders where encrypted files are found and also on the user's desktop.
Infra: 🔗 msaoyrayohnp32tcgwca
RLUpdated: N/A
View profile →
APT GROUPfinancial
ulose — tracked by MISP Galaxy (ransomware).
Infra: 🔗 egm34gsyx65wb6jyqds4
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial services organizations in the US, Croatia, and Indonesia by exploiting exposed perimeter services such as firewalls and VPNs, claiming at least five victims.
RLUpdated: N/A
View profile →
APT GROUPfinancial
gazprom — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 qvo5sd7p5yazwbrgioky
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Red Ransomware (Red CryptoApp) emerged in early 2024, debuting its "Wall of Shame" data leak site with 11 victims across IT, legal, hospitality, manufacturing, and education sectors predominantly in the US, using phishing and vulnerability exploitation with double-extortion tactics.
RLUpdated: N/A
View profile →
APT GROUPfinancial
lsd — tracked by MISP Galaxy (ransomware).
Infra: 🔗 t.me
RSLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Suspicious group
Infra: 🔗 dirone3rl3vvq64ckcnr
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 rktazuzi7hbln7sy.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organizations across manufacturing, healthcare, technology, and hospitality sectors using double-extortion tactics — encrypting files while exfiltrating data and threatening publication via a Tor-based leak site.
Infra: 💬 rwsu75mtgj5oiz3alkfp🔗 benzona6x5ggng3hx52h📁 cpjhb63lxycwbyus2n35+1 more
RLUpdated: 2026-08-04
View profile →