Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,486 entities
APT GROUPfinancialhigh
According to Nextron, Lynx ransomware is a sophisticated malware threat that has been active since mid-2024. Lynx has claimed over 20 victims across a range of industries. Once it infiltrates a system, it encrypts critical files, appending a ‘.lynx’ extension, and deletes backup files like shadow copies to hinder recovery. Uniquely, it also sends the ransom note to available printers, adding an unexpected element to its attack strategy. This malware shares similarities with previous INC ransomware, indicating that they bought INC ransomware source code.
APT GROUPfinancialhigh
Tesorion describes Lorenz as a ransomware with design and implementation flaws, leading to impossible decryption with tools provided by the attackers. A free decryptor for 2021 versions was made available via the NoMoreRansom initiative. A new version of the malware was discovered in March 2022, for which again was provided a free decryptor, while the ransomware operators are not able to provide tools to decrypt affected files.
APT GROUPfinancialhigh
LokiLocker is a .Net ransomware, which was seen first in August 2021. This malware is protected with NETGuard (modified ConfuserEX) using the additional KoiVM virtualization plugin.
The victims were observed ti be scattered around the world, with main concentation in Estern Europe and Asia (BlackBerry).
APT GROUPfinancialhigh
A ransomware that was active in 2018.
APT GROUPfinancialhigh
According to Symantec, this is a ransomware written in Golang and obfuscated with Gobfuscate. The source code for Knight (originally known as Cyclops) was offered for sale on underground forums in February 2024 after Knight’s developers decided to shut down their operation.
APT GROUPfinancialhigh
Trend Micro describes this as a Ransomware with possible ties to BlackMatter.
APT GROUPfinancialhigh
Ransomware.
T1123T1566T1125
JobCrypter
Technical ID: win.JobCrypter
MALWARE
Malware family tracked by Malpedia. ID: win.jobcrypter
APT GROUPfinancialhigh
Warsaw trojan is a new banking trojan based on the Hours Eyes RAT core engine.
APT GROUP
Malware family tracked by Malpedia. ID: win.hermes
APT GROUP
Malware family tracked by Malpedia. ID: win.globe_ransom
APT GROUPfinancialhigh
The GLOBAL GROUP is a Ransomware-as-a-Service program which emerged in June 2025. It is suspected to have ties to BlackLock and Mamona, due to code and infrastructure similarities. It's negotiation panel offers AI-driven negotiations to help the operators to engage with the victims.
APT GROUP
Malware family tracked by Malpedia. ID: win.gcman
APT GROUPfinancialhigh
According to SentinelOne, Fog Ransomware emerged in April of 2024 with operations targeting both Windows and Linux endpoints. Fog is a multi-pronged extortion operation, leveraging a TOR-based DLS to list victims and host data for those that refuse to comply with their ransom demands.
APT GROUP
Malware family tracked by Malpedia. ID: win.donex
APT GROUPfinancialhigh
DEVMAN is a ransomware which shares a large part of its codebase with DragonForce ransomware. It is highly probable that the group used a DragonForce ransomware build and simply changed the extension added to the encrypted files (from .dragonforce_encrypted to .devman). In one of the first observed samples, the ransom note still claimed to be part of the DragonForce Ransomware Cartel.
The ransomware implements common features such as the deletion of ShadowCopies, and avoid encrypting files with some extensions present in a hard-coded list. The ransomware implements multiple encryption modes:
- Full encryption
- Header-only encryption
- Custom encryption
These modes allow the operator to choose between a quick or a strong encryption depending on the scenario. The ransomware also tries to connect to SMB folders.
DEVMAN ransomware creates a temporary session under the following registry key: `HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000`. The use of the Restart Manager to bypass file locks and ensure encrypted access to active user session files. This capability seems to be a legacy of Conti ransomware, which inspired DragonForce and DEVMAN. As part of this legacy, the ransomware use a hard-coded mutex to prevent multiple instances from running in parallel.
APT GROUP
Malware family tracked by Malpedia. ID: win.darkbit
APT GROUP
According to HarfangLabs, Cyclops is a malware platform written in Go which dates back to December 2023, and that they believe has been deployed against targets in the Middle-East in 2024. Cyclops allows operators to execute arbitrary commands on the target’s file system, as well as pivot inside the infected network. Notably, Cyclops is controlled through a HTTP REST API which is exposed to operators within an SSH tunnel.
APT GROUP
Malware family tracked by Malpedia. ID: win.ctb_locker
APT GROUPfinancialhigh
According to OALabs, this ransomware has the following features:
* Files are encrypted with AES CBC using a generated 256 bit key and IV.
* The generated AES keys are encrypted using a hard coded RSA key and appended to the encrypted files.
APT GROUP
Malware family tracked by Malpedia. ID: win.crosslock
APT GROUP
Malware family tracked by Malpedia. ID: win.crazyhunter
APT GROUP
Malware family tracked by Malpedia. ID: win.cicada3301
APT GROUP
Malware family tracked by Malpedia. ID: win.catb
APT GROUP
Malware family tracked by Malpedia. ID: win.cactus
APT GROUP
Malware family tracked by Malpedia. ID: win.buhtrap
APT GROUP
Malware family tracked by Malpedia. ID: win.blacksnake
APT GROUP
Malware family tracked by Malpedia. ID: win.bert
APT GROUP
Malware family tracked by Malpedia. ID: win.beavertail
APT GROUP
According to PCrisk, AtomSilo is a type of malware that blocks access to files by encrypting them and renames every encrypted file by appending the ".ATOMSILO" to its filename. It renames "1.jpg" to "1.jpg.ATOMSILO", "2.jpg" to "2.jpg.ATOMSILO", and so on. As its ransom note, AtomSilo creates the "README-FILE-#COMPUTER-NAME#-#CREATION-TIME#.hta" file.
APT GROUP
Malware family tracked by Malpedia. ID: win.astralocker
APT GROUPespionageadvanced
A new form of ransomware named AlphaLocker that is built by cybercriminals for cybercriminals. Like all incarnations of Ransomware As A Service (RaaS), the AlphaLocker malware program can be purchased and launched by pretty much anyone who wants to get into the ransomware business. What makes AlphaLocker different from other forms of RaaS is its relatively cheap cost. The ransomware can be purchased for just $65 in bitcoin.
AlphaLocker, also known as Alpha Ransomware, is based on the EDA2 ransomware, an educational project open-sourced on GitHub last year by Turkish researcher Utku Sen. A Russian coder seems to have cloned this repository before it was taken down and used it to create his ransomware, a near-perfect clone of EDA2. The ransomware's author, is said to be paying a great deal of attention to updating the ransomware with new features, so it would always stay ahead of antivirus engines, and evade detection.
AlphaLocker's encryption process starts when the ransomware contacts its C&C server. The server generates a public and a private key via the RSA-2048 algorithm, sending the public key to the user's computer and saving the private key to its server. On the infected computer, the ransomware generates an AES-256 key for each file it encrypts, and then encrypts this key with the public RSA key, and sent to the C&C server.
To decrypt their files, users have to get ahold of the private RSA key which can decrypt the AES-encrypted files found on their computers. Users have to pay around 0.35 Bitcoin (~$450) to get this key, packaged within a nice decrypter.
APT GROUPfinancialhigh
The 8Base ransomware group has remained relatively unknown despite the massive spike in activity in Summer of 2023. The group utilizes encryption paired with “name-and-shame” techniques to compel their victims to pay their ransoms. 8Base has an opportunistic pattern of compromise with recent victims spanning across varied industries. Despite the high amount of compromises, the information regarding identities, methodology, and underlying motivation behind these incidents still remains a mystery. Samples of their ransomware show they are using customized Phobos with SmokeLoader.
APT GROUP
According to Volexity, LIGHTSPY is a multi-platform malware family with documented variants for Android, iOS, and macOS.
APT GROUP
Magecart is a malware framework intended to steal credit card information from compromised eCommerce websites. Used in criminal activities, it's a sophisticated implant built on top of relays, command and controls and anonymizers used to steal eCommerce customers' credit card information. The first stage is typically implemented in Javascript included into a compromised checkout page. It copies data from "input fields" and send them to a relay which collects credit cards coming from a subset of compromised eCommerces and forwards them to Command and Control servers.
APT GROUP
Malware family tracked by Malpedia. ID: ios.poisoncarp
APT GROUPfinancialhigh
According to 0x3oBAD, this is a 64-bit Linux ELF ransomware binary targeting VMware ESXi hypervisor environments. The sample combines a robust cryptographic scheme Curve25519 ECDHand ChaCha20 with ESXi-specific VM enumeration via the vmInventory.xml inventory file, graceful shutdown of running VMs before encryption, and a multi-threaded file encryption pipeline scaled to available CPU cores. The ransom note is delivered inside ESXi’s own web UI welcome.txt, replacing the host management interface greeting.
APT GROUP
Malware family tracked by Malpedia. ID: elf.icefire