Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,747 entities
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 darkprn3d3udnhpuxkns📁 wjcml4mxpcvsmjxm33zh📁 7iphetz64a7iihcpwr3n+6 more
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 iw6v2p3cruy7tqfup3yl🔗 iw6v2p3cruy7tqfup3yl
RSLUpdated: N/A
View profile →
The authors of the Satan ransomware have rebranded their "product" and they now go by the name of DBGer ransomware, according to security researcher MalwareHunter, who spotted this new version earlier today. The change was not only in name but also in the ransomware's modus operandi. According to the researcher, whose discovery was later confirmed by an Intezer code similarity analysis, the new (Satan) DBGer ransomware now also incorporates Mimikatz, an open-source password-dumping utility. The purpose of DBGer incorporating Mimikatz is for lateral movement inside compromised networks. This fits a recently observed trend in Satan's modus operandi.
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. EDA2
Updated: 2026-08-10
View profile →
APT GROUPfinancial
desolated — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware Ransom note instructs to use Bitmessage to get in contact with attacker - Secretishere.key - SECRETISHIDINGHEREINSIDE.KEY - secret.key
Updated: 2026-08-10
View profile →
ransomware
Updated: 2026-08-10
View profile →
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
PayoutsKing is an active ransomware group observed through at least 2026 that has claimed attacks against a wide range of industries internationally — including Del Monte Foods and V. FRAAS — across the US, UK, Germany, and Ireland using standard double-extortion tactics.
Infra: 🔗 payoutsgn7cy6uliwevd📁 v2mw3spxqhggig5zjd6t📁 c6nrwsloenpiat7zilh2
RLUpdated: 2026-08-10
View profile →
It’s directed to English speaking users, therefore is able to infect users all over the world. It is spread using email spam, fake updates, attachments and so on. It SUPPOSEDLY encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc… Your files are not really encrypted and nothing actually happens, however the hacker does ask the victim to pay a sum of 100$, after 5 days the sum goes up to 250$ and thereafter to 500$. After the payment is received, the victim gets the following message informing him that he has been fooled and he simply needed to delete the note. https://4.bp.blogspot.com/-T8iSbbGOz84/WFGZEbuRfCI/AAAAAAAACm0/SO8Srwx2UIM3FPZcZl7W76oSDCsnq2vfgCPcB/s1600/code2.jpg
Updated: 2026-08-10
View profile →
APT GROUPfinancial
DataKeeper is a ransomware-as-a-service operation dating back to at least 2018 that promoted an affiliate model called "CrystalPartnership RaaS," offering a Windows-focused ransomware toolkit with hybrid RSA-4096 encryption, open dark web registration, and an innovative split-payment mechanism to build affiliate trust.
Infra: 🔗 dc4nwiijwiffwztwzj5f
RLUpdated: N/A
View profile →
APT GROUP
Ransomware Based on the DUMB ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land Binaries (LOLBins) to blend malicious activity with normal admin traffic, primarily targeting consumer goods, real estate, automotive, healthcare, and IT sectors.
Infra: 🔗 fuvodyoktsjdwu3mrbbr🔗 longcc4fqrfcqt5lzceu🔗 longejh5gj5igfinj36r+4 more
RLUpdated: 2026-08-10
View profile →
Looks to be in-development as it does not encrypt.
Updated: 2026-08-10
View profile →
APT GROUPfinancial
Arcane first emerged in mid-2021 under the UNC2190 cluster and later rebranded as Sabbath, continuing its operations against critical infrastructure like hospitals, schools, and educational entities. It follows a double-extortion model—encrypting data (using ROLLCOAST/Eruption malware) while also exfiltrating sensitive information and threatening to leak it. Victims have included institutions in the U.S. and Canada across sectors such as healthcare, education, and natural resources. Initial intrusion tactics involved deployment of Cobalt Strike with custom profiles, DLL-based in-memory execution, and signed TLS certificates, plus use of stealthy GET requests ending with “kitten.gif.” Specific encryption algorithms or file extensions have not been publicly confirmed. The group appears to operate in an affiliate-style model but remains under single management rather than a full RaaS platform.
RSLUpdated: 2026-08-10
View profile →
APT GROUP
Over 100,000 thousand computers in China have been infected in just a few days with poorly-written ransomware that encrypts local files and steals credentials for multiple Chinese online services. The crooks show a screen titled UNNAMED1989 and demand the victim a ransom of 110 yuan ($16) in exchange for decrypting the files, payable via Tencent's WeChat payment service by scanning a QR code.
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
A new in-development ransomware was discovered that has an interesting characteristic. Instead of the distributed executable performing the ransomware functionality, the executables compiles an embedded encrypted C# program at runtime and launches it directly into memory.
Updated: 2026-08-10
View profile →
"prepending (enc) ransomware" (Not an official name) — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-10
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 v76bdil3v7hczufr7kwk
RSLUpdated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware Based on RemindMe
Updated: 2026-08-10
View profile →
APT GROUPfinancial
shadowbyt3$ — tracked by MISP Galaxy (ransomware).
Infra: 🔗 shadowbyt3s.8bit.ca🔗 shadowsblog.cloud-ip🔗 shadoz22.io+5 more
RSLUpdated: 2026-08-10
View profile →
GrujaRS discovered a new ransomware called EnyBenyHorsuke Ransomware that appends the .Horsuke extension to encrypted files.
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware Based on EDA2
Updated: 2026-08-10
View profile →
APT GROUPfinancial
vanir group — tracked by MISP Galaxy (ransomware).
Infra: 🔗 6xdpj3sb5kekvq5ulym5🔗 6xdpj3sb5kekvq5ulym5
RSLUpdated: 2026-08-10
View profile →
APT GROUPfinancial
Nova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victims’files and uses double-extortion tactics to pressure organizations into paying for decryption and data non-disclosure.
Affiliates: Bog1337 • ploja • Hunt3rs0p3r4tion
Infra: 🔗 novavdivko2zvtrvtlln🔗 novazzitmugtbjwuttc5💬 novaeogps7purkdhxmay+20 more
RLUpdated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
← PreviousPage 215 / 269Next →