Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters712 entities
APT GROUPfinancial
polyvice — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to other ransomwares, involving attacks such as Phishing, Exposed Services to the Internet, and Valid Account compromises.<br> <br> On April 19, 2023, the security company Symantec published two new tools developed by the Play group. These tools allow the malicious actor to enumerate and exfiltrate data from the internal network. The post mentions the following: 'Play threat actors use the .NET infostealer to enumerate software and services via WMI, WinRM, Remote Registry, and Remote Service. The malware checks for the existence of security and backup software, as well as remote administration tools and other programs, saving the information in .CSV files that are compressed into a .ZIP file for later manual exfiltration by threat actors.'Source: https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 mbrlkbtq5jonaqkurjwm🔗 k7kg3jqxang3wh7hnmai🔗 k7kg3jqzffsxe2z53jjx+29 more
T1560.001T1059.001T1587.001
RLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
PayloadBIN is a ransomware strain deployed in 2021 by Evil Corp as a rebranding of their WastedLocker/Hades/Phoenix lineage, specifically designed to evade US Treasury OFAC sanctions by impersonating the unrelated Babuk gang's rebrand rather than operating as an independent group.
Affiliates: Wazawaka
Infra: 🔗 vbmisqjshn4yblehk2vb
RLUpdated: N/A
View profile →
APT GROUPfinancial
Pay2Key is ransomware that has been used by the threat actor Fox Kitten. The group seems to operate since July 2020, targetting mainly Israeli companies. Pay2Key has a darknet leak site to public stolen and sensitive information of their victims. Some of their victims: Intel - Habana Labs, IAI - Israel Aerospace Industries, Portnox - Network Security Solutions.
Infra: 🔗 pay2key2zkg7arp3kv3c🔗 pay2keys7rgdzrhgzxyd
RLUpdated: N/A
View profile →
APT GROUPfinancial
paradise — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Pandora ransomware was obtained by vx-underground at 2022-03-14.
Infra: 🔗 vbfqeh5nugm6r2u2qvgh🔗 pandoraxyz.xyz
RLUpdated: N/A
View profile →
APT GROUPfinancial
Night Sky is a China-nexus ransomware group (attributed to the "Emperor Dragonfly" cluster) that emerged in late 2021, gaining notoriety in early 2022 by exploiting the Log4Shell vulnerability (CVE-2021-44228) to target corporate networks across healthcare, finance, government, and manufacturing using multi-extortion tactics.
Infra: 🔗 gg5ryfgogainisskdvh4
RLUpdated: N/A
View profile →
APT GROUPfinancial
Nevada Ransomware is a RaaS operation written in Rust that emerged on the RAMP dark web forum in late 2022, offering affiliates favorable revenue splits (85/15 or 90/10) and conducting opportunistic mass attacks against a wide range of industries worldwide.
Infra: 🔗 nevcorps5cvivjf6i2gm🔗 nevbackvzwfu5yu3gsza🔗 nevaffcwswjosddmw55q
RLUpdated: N/A
View profile →
APT GROUPfinancial
Nemty is a ransomware that was discovered in September 2019. Fortinet states that they found it being distributed through similar ways as Sodinokibi and also noted artfifacts they had seen before in Gandcrab.
Infra: 🔗 zjoxyw5mkacojk5ptn2i
RLUpdated: N/A
View profile →
APT GROUPfinancial
According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.
Infra: 🔗 hxt254aygrsziejn.oni
RLUpdated: N/A
View profile →
APT GROUPfinancial
MountLocker operated as a ransomware-as-a-service from July 2020, using a standard developer/affiliate revenue split and leveraging compromised RDP credentials for initial access, propagating laterally via Windows Active Directory APIs and targeting over 2,600 file extensions.
RLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
mortalkombat — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Morpheus emerged in late 2024 as a semi-private RaaS operation whose affiliates share identical payloads with the HellCat ransomware group, targeting pharmaceutical, manufacturing, legal, and Italian ESXi environments with ransom demands reaching up to 32 BTC (~$3M USD).
Infra: 🔗 izsp6ipui4ctgxfugbgt
RLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Money Message emerged in March 2023 targeting Windows and Linux systems across banking, transportation, and professional services sectors, demanding ransoms in the millions and publishing stolen data on their blog if unpaid, with most known victims based in the US.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Ransomware, potential rebranding of win.sfile.
Infra: 🔗 dfpc7yvle5kxmgg6sbcp
RLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
This malware written in C# is a variant of the Thanos ransomware family and emerged in October 2021 and is obfuscated using SmartAssembly. In 2022, ThreatLabz analysed a report of Midas ransomware was slowly deployed over a two month period (ZScaler). This ransomware features also its own data leak site as part of its double extortion strategy.
Infra: 🔗 midasbkic5eyfox4dhni
RLUpdated: N/A
View profile →
APT GROUPfinancial
Meow emerged in 2022 (resurfacing aggressively in 2024), initially operating as a RaaS using the Conti v2 codebase before transitioning to a data-extortion-only model — selling stolen data rather than encrypting files — with a heavy focus on US healthcare and medical research organizations.
Infra: 🔗 meow6xanhzfci2gbkn3l🔗 totos7fquprkecvcsl2j📁 ikjht3url3tvx6itf2eg+2 more
RLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.
Infra: 🔗 medusaxko7jxtrojdkxo🔗 xfv4jzckytb4g3ckwemc🔗 dlmfciajg5s4vliyo5dh+14 more
RLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Maze ransomware group is one of the most known ransomware gangs, they targeted organizations worldwide across many industries. Security researchers believed that Maze operates as an affiliated network model. MAZE was one of the first groups that made a 'Double Extortion Attack' involved Allied Universal, in November 2019, the group leaks their victim's data in the darknet. On November 1, 2020, MAZE announced an official press release that they are closing their operation. is malware targeting organizations worldwide across many industries. Security researchers claim that the threat actor behind the MAZE group is 'TA2101'.
Infra: 🔗 xfr3txoorcyy7tikjgj5💬 aoacugmutagkwctu.oni💬 mazedecrypt.top+4 more
RLUpdated: N/A
View profile →
APT GROUPfinancial
mailto — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Lynx is a ransomware-as-a-service operation that emerged in mid-2024 as a rebrand of INC Ransomware (whose source code was sold for $300,000 on the RAMP forum), claiming ~300 victims across manufacturing, business services, technology, and transportation with an 80/20 profit split for affiliates.
Infra: 🔗 lynxblog.net🔗 lynxbllrfr5262yvbgtq💬 lynxch2k5xi35j7hlbmw+34 more
RLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Tesorion describes Lorenz as a ransomware with design and implementation flaws, leading to impossible decryption with tools provided by the attackers. A free decryptor for 2021 versions was made available via the NoMoreRansom initiative. A new version of the malware was discovered in March 2022, for which again was provided a free decryptor, while the ransomware operators are not able to provide tools to decrypt affected files.
Infra: 🔗 lorenzmlwpzgxq736jzs🔗 woe2suafeg6ehxivgvvn💬 lorenzedzyzyjhzxvlcv+1 more
RLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
lokilocker — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Lilith is a C/C++-based double-extortion ransomware that emerged in July 2022, targeting 64-bit Windows systems and sharing code with the Babuk ransomware family, with its first confirmed victim being a large South American construction firm.
Infra: 🔗 yeuajcizwytgmrntijhx
RLUpdated: N/A
View profile →
APT GROUPfinancial
kuiper — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Kraken is a Russian-speaking ransomware group that emerged in February 2025, believed to have links to the HelloKitty operation, employing a RaaS model notable for a benchmarking step that measures victim machine speed to optimize encryption, and in September 2025 launched an underground criminal forum called "The Last Haven Board."
Infra: 🔗 krakenccj3wr23452a4i📁 zq3k4odlfpbzc5y4sxqg📁 t3uouzfvsaqurb2rzoe2+16 more
RLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
[Cyclops](group/cyclops) rebrand
Infra: 🔗 knight3xppu263m7g4ag💬 3r7zqtidvujbmfhx52sb📁 uzfrntnmwojla5v4w3xv+3 more
RLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Kasseika is a ransomware variant first publicly reported in January 2024, identified as a new evolution of the BlackMatter/LockBit ransomware codebase. The malware appends the .kasseika extension to encrypted files and uses a double-extortion model, combining file encryption with threats to publish stolen data on a Tor-based leak site. Early analysis revealed that Kasseika shares several traits with LockBit 3.0, including encryption routines, obfuscation methods, and ransom note structure, but with modified branding and negotiation portals. Initial access vectors have not been widely confirmed, though patterns from related ransomware suggest the use of compromised credentials, RDP exploitation, and vulnerabilities in public-facing services. Victims have been observed in North America, Europe, and Asia, spanning industries like manufacturing, logistics, and professional services.
RSLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Interlock is a ransomware group first observed in September 2024 that targets critical infrastructure sectors including healthcare, government, education, and technology across North America and Europe using double-extortion, with 57+ claimed victims including a major US dialysis provider exposing over two million patient records.
Infra: 🔗 ebhmkoohccl45qesdbvr🔗 ebhmkoohccl45qesdbvr📁 zmqolc6yrdgn24w7eaaf+180 more
RLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
icarus — tracked by MISP Galaxy (ransomware).
Infra: 🔗 e6ujsppajgb756x7x5yk
RSLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Hive is a strain of ransomware that was first discovered in June 2021. Hive was designed to be used by Ransomware-as-a-service providers, to enable novice cyber-criminals to launch ransomware attacks on healthcare providers, energy providers, charities, and retailers across the globe. In 2022 there was a switch from GoLang to Rust.
Affiliates: Wazawaka
Infra: 🔗 hiveleakdbtnp76ulyhi💬 hivecust6vhekztbqgdn🔗 hiveapi4nyabjdfz2hxd
RLUpdated: N/A
View profile →
APT GROUPfinancial
Hermes is a ransomware family first observed in the wild in February 2017, believed to have been developed by a group operating out of Asia. It originally appeared as a Ransomware-as-a-Service (RaaS) offering on underground forums but later saw deployment in targeted attacks. Hermes uses AES-256 encryption to lock victim files and appends a variety of extensions (including .hrm and campaign-specific variants). The ransom note, often named DECRYPT_INFORMATION.html or DECRYPT_INFORMATION.txt, provides payment instructions via email. The ransomware gained notoriety in 2018 when it was used as a destructive wiper in the Far Eastern International Bank (FEIB) heist in Taiwan, where attackers deployed Hermes to cover their tracks after a SWIFT fraud operation. Over time, Hermes code has been re-used and integrated into other ransomware families, including some Ryuk builds, suggesting code sharing or purchase from the original developer. Distribution vectors have included phishing campaigns, malicious attachments, and exploitation of RDP services.
RSLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Unit42 states that HelloKitty is a ransomware family that first surfaced at the end of 2020, primarily targeting Windows systems. The malware family got its name due to its use of a Mutex with the same name: HelloKittyMutex. The ransomware samples seem to evolve quickly and frequently, with different versions making use of the .crypted or .kitty file extensions for encrypted files. Some newer samples make use of a Golang packer that ensures the final ransomware code is only loaded in memory, most likely to evade detection by security solutions.
Infra: 🔗 3r6n77mpe737w4sbxxxr💬 gunyhng6pabzcurl7ipx
RLUpdated: N/A
View profile →
APT GROUPfinancial
Not a Ransomware Group
Infra: 🔗 handala.to🔗 handala-hack.to🔗 vmjfieomxhnfjba57sd6+1 more
PS
RLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
According to PCrisk, Hades Locker is an updated version of WildFire Locker ransomware that infiltrates systems and encrypts a variety of data types using AES encryption. Hades Locker appends the names of encrypted files with the .~HL[5_random_characters] (first 5 characters of encryption password) extension.
Infra: 🔗 ixltdyumdlthrtgx.oni💬 m6s6axasulxjkhzh.oni
RLUpdated: N/A
View profile →
APT GROUPfinancial
Gwisin is a targeted ransomware group first publicly reported in July 2022, believed to operate primarily within South Korea. The group’s name means “ghost” in Korean, reflecting its stealthy approach. Gwisin has been observed conducting attacks on critical sectors, including healthcare, pharmaceutical, and manufacturing industries. It uses custom-built payloads tailored for each victim, capable of encrypting both Windows and Linux/VMware ESXi environments, and often executes attacks during national holidays to maximize operational disruption. Gwisin employs a double-extortion model—exfiltrating sensitive data before encryption—and communicates with victims in Korean-language ransom notes. Initial access vectors are not fully confirmed in open-source reporting, but suspected methods include exploiting vulnerable VPN appliances and leveraging stolen administrative credentials. The group is known for extensive pre-encryption reconnaissance to identify high-value systems and backups.
Infra: 💬 gwisin4yznpdtzq424i3
RSLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
Globe is a ransomware family that first appeared in August 2016, notable for its highly customizable codebase that allows operators to configure ransom note text, encryption algorithms, and file extensions. Globe uses symmetric encryption (RC4 or AES) to lock files and typically appends custom extensions such as .GLOBE, .PURPLE, .HNY, or others set by the attacker. The malware is distributed through malicious spam emails with infected attachments, compromised websites, and exploit kits. Globe’s flexibility made it attractive to low-skilled actors, resulting in many different variants in the wild. The family has primarily targeted small to medium-sized businesses and individual users across multiple regions, with no clear geographic focus.
RSLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
GLOBAL GROUP is a ransomware-as-a-service operation that emerged in June 2025, reportedly launched by a known Russian-speaking threat actor, featuring AI-driven ransom negotiation and a mobile control panel for affiliates, targeting healthcare, oil and gas, industrial engineering, and automotive sectors.
Infra: 🔗 vg6xwkmfyirv3l6qtqus💬 panelqbinglxczi2gqkw💬 gdbkvfe6g3whrzkdlbyt+1 more
RLUpdated: 2026-08-02
View profile →
APT GROUPfinancial
FunkSec is an AI-assisted ransomware-as-a-service group that launched its data leak site in December 2024 and rapidly claimed over 85 victims across government, technology, finance, and education sectors globally, demanding unusually low ransoms and using AI tooling to lower the technical bar for affiliates.
Infra: 🔗 7ixfdvqb4eaju5lzj4gg🔗 pke2vht5jdeninupk7i2🔗 ykqjcrptcai76ru5u7jh+10 more
RLUpdated: 2026-08-02
View profile →