Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters712 entities
APT GROUPfinancial
Black Berserk is a relatively unsophisticated ransomware strain analyzed in late 2023. It operates under a single‑extortion model—encrypting files and demanding payment, with no documented abilities or threats for data exfiltration or public leaks. In observed cases, the malware appends the .Black extension to encrypted files (e.g., 1.jpg.Black) and leaves a ransom note titled Black_Recover.txt, which urges victims to make contact to negotiate payment or test decryption with benign files. The infection method appears opportunistic, delivered via isolated incidents or broad malware distribution—not linked to targeted campaigns or infrastructure. There is no evidence of it functioning as a RaaS operation or targeting any specific victim profiles or sectors.
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
blackhunt — tracked by MISP Galaxy (ransomware).
Infra: 🔗 sdjf982lkjsdvcjlksaf…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Obscura is a ransomware strain observed in 2025, written in Go and specifically targeting Windows domain controllers via the SYSVOL/NETLOGON share, using Curve25519 + XChaCha20 encryption with double-extortion tactics and a 10-day payment deadline.
Infra: 🔗 obscurad3aphckihv7wp…📁 obscurad3aphckihv7wp…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
team underground — tracked by MISP Galaxy (ransomware).
Infra: 💬 undgrddapc4reaunnrdr…💬 ehehqyhw3iev2vfso4vq…🔗 47glxkuxyayqrvugfumg…+1 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Official twitter account: https://x.com/ValenciaLeaks72
Infra: 🔗 6doyqxqqj36vnedtt2zw…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
robbing hood — tracked by MISP Galaxy (ransomware).
Infra: 💬 fonektibq4fbgergrorw…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
dark shinigami — tracked by MISP Galaxy (ransomware).
Infra: 🔗 darkshiz4d5ayumjvgbd…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Kyber is a recently identified ransomware group using sophisticated hybrid encryption (AES-256-CTR with X25519 and Kyber1024), operating Tor-based communication channels and employing double-extortion with free partial decryption offered to build negotiation trust, discovered through underground forum monitoring in 2025.
Infra: 🔗 kyblogtz6k3jtxnjjvlu…💬 mlnmlnnrdhcaddwll4zq…📁 tp7e2ekeoqqozyq2t3oy…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
quicklock — tracked by MISP Galaxy (ransomware).
Infra: 💬 dmkhn64rhzqtys7rns6z…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 cloak.su…
RSLUpdated: N/A
View profile →APT GROUPfinancial
buddyransome — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 mrdxtxy6vqeqbmb4rvbv…
RSLUpdated: N/A
View profile →APT GROUPfinancial
rustylocker — tracked by MISP Galaxy (ransomware).
Infra: 🔗 rustydl5ak6p6ajqnja6…🔗 rustyb2uj3aceqsouwei…🔗 rustye6pskjsu5vo2wlx…+10 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 hitleransomware.cf…
RSLUpdated: N/A
View profile →APT GROUPfinancial
MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.
RLUpdated: N/A
View profile →APT GROUPfinancial
0mega is a double-extortion ransomware group that emerged in May 2022, targeting businesses across multiple sectors worldwide by encrypting files and threatening to leak stolen data; it also pivoted to cloud-based extortion by compromising Microsoft 365 admin accounts.
Infra: 🔗 omegalock5zxwbhswbis…🔗 0mega.cc…🔗 0mega.ws…+1 more
RLUpdated: N/A
View profile →APT GROUPfinancial
Members:
<br/>Eco
<br/>Ego
<br/>emo
<br/>elo
<br/>user
<br/>Dante
<br/>Sevy
Infra: 🔗 tooda.sh…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
Rancoz is a Windows-targeting ransomware strain first observed in November 2022 that appends the ".rec_rans" extension to encrypted files, considered a Vice Society copycat, deployed against a small number of organizations using double extortion and linked to the same developer as the "Buddy" ransomware.
Infra: 🔗 ze677xuzard4lx4iul2y…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
CRPxO is actively recruiting affiliates, offering:
🔹 70% revenue share
🔹 XMR/BTC payouts
🔹 Claimed payouts within 24 hours
🔹 $333 one-time affiliate access
RLUpdated: N/A
View profile →APT GROUPfinancial
arachna leak — tracked by MISP Galaxy (ransomware).
Infra: 🔗 ptyctpveqfevlukjw4hp…
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
BackMyData is a variant of the Phobos ransomware family, first observed in early 2024. It follows a double‑extortion model: encrypting files and threatening data exposure. The ransomware primarily targets organizations via weak or misconfigured RDP access (e.g., remote desktop services), though phishing and initial-stage payloads like SmokeLoader have also been noted. Technical behavior includes AES‑256 file encryption, with keys secured via a public RSA‑2048 key embedded in the binary. Post-infection actions involve disabling firewalls, deleting volume shadow copies, inhibiting recovery functionality, and establishing persistence through registry Run keys and startup folder entries. Encrypted files receive the extension .BACKMYDATA, and victims are left with ransom notes (info.txt, info.hta, or .backmydata) that instruct them to contact attackers via email or Session Messenger. A significant incident involved a coordinated attack on Romania’s Hipocrate Information System (HIS), impacting 26 hospitals and causing widespread system outages across nearly 100 facilities, with ransom demands of approximately 3.5 BTC (~$175,000).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
argonauts group — tracked by MISP Galaxy (ransomware).
Infra: 🔗 jbmk7h6xlkedn2gg5yi7…💬 4xi5jklauqmjfkwxhs2a…
RSLUpdated: 2026-08-04
View profile →justice blade
Technical ID: justice_blade
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 justice-blade.io…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Hotarus Corp is a ransomware group that came to attention in early 2021 after attacking Ecuador's Ministry of Finance and Banco Pichincha — the country's largest private bank — deploying PHP-based ransomware and claiming to have stolen tens of millions of customer records.
Infra: 🔗 r6d636w47ncnaukrpvlh…
RLUpdated: N/A
View profile →APT GROUPfinancial
Mamona was a short-lived ransomware rebrand attempted by the operator behind BlackLock RaaS in March 2025 that failed before reverting; as a standalone strain it operates entirely offline with no C2 communication, uses custom encryption, and targets Windows systems.
Infra: 🔗 owt3kwkxod2pvxlv3ulj…🔗 185.158.113.114.…🔗 185.158.113.114.…+1 more
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
"Unknown" is a catch-all tracking label used on ransomware monitoring platforms for attacks where the responsible threat actor has not been positively attributed to a known named group, serving as a placeholder for unattributed incidents.
Infra: 🔗 tdoe2fiiamwkiadhx2a4…🔗 darktorhvabc652txfc5…
RLUpdated: N/A
View profile →APT GROUPfinancial
Slug is a very obscure ransomware or extortion group with only a single documented victim (AerCap, the aircraft leasing company) recorded on ransomware tracking platforms; no detailed threat intelligence reports exist for this group.
Infra: 🔗 3ytm3d25hfzvbylkxiwy…
RLUpdated: 2026-08-04
View profile →APT GROUPfinancial
obsidian orb — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 ransomyktqx2m3xg.oni…
RSLUpdated: N/A
View profile →