Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,747 entities
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
malek team — tracked by MISP Galaxy (ransomware).
Infra: 🔗 malekteam.ac🔗 195.14.123.2.
RSLUpdated: 2026-08-10
View profile →
APT GROUPfinancial
leakeddata — tracked by MISP Galaxy (ransomware).
Infra: 🔗 business-data-leaks.📁 ep6pheij.com
RSLUpdated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. This is a trollware that does not encrypt your files but makes your computer act crazy (like in the video in the link below). It is meant to be annoying and it is hard to erase from your PC, but possible.
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
NoName (also known as CosmicBeetle) is a ransomware group active since at least 2020 targeting small and medium-sized businesses globally using its custom ScRansom tool, exploiting vulnerabilities like EternalBlue and ZeroLogon, and becoming a RansomHub affiliate to access that platform's RaaS infrastructure.
Infra: 🔗 noname2j6zkgnt7ftxsj🔗 www.lockbitblog.info🔗 7tkffbh3qiumpfjfq77p+2 more
RLUpdated: 2026-08-10
View profile →
APT GROUP
Made with OXAR builder; decryptable
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware Targeted attacks -Jexboss -PSExec -Hyena
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUPfinancial
Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria.
Infra: 🔗 fewcriet5rhoy66k6c4c
RLUpdated: 2026-08-10
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Original name is Mission 1996 or Mission: “Impossible” (1996) (like the movie)
Updated: 2026-08-10
View profile →
APT GROUPfinancial
Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia across manufacturing, communications, and construction sectors, operating a Tor-based double-extortion leak site.
Infra: 🔗 brohoodyaifh2ptccph5📁 fotxzhnoxtkpa6cwkimy📁 a5wdkdd7unaacdlzcjm5+12 more
RLUpdated: 2026-08-10
View profile →
ransomware
Updated: 2026-08-10
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
Ransomware Variant of the Philadelphia ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
Maui ransomware stand out because of a lack of several key features commonly seen with tooling from RaaS providers, such as an embedded ransom note to provide recovery instructions or automated means of transmitting encryption keys to attackers. Instead, it is believed that Maui is manually operated, in which operators will specify which files to encrypt when executing it and then exfiltrate the resulting runtime artifacts. There are many aspects to Maui ransomware that are unknown, including usage context.
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Lockbit3 — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware File marker: "Heimdall---"
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
Locked File
Technical ID: Locked_File
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware, Infection by Phishing
Updated: 2026-08-10
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 flock4cvoeqm4c62gyoh
RSLUpdated: N/A
View profile →
APT GROUPfinancial
M3rx is a small ransomware group first observed in 2025, using AES-CTR/AES-GCM encryption and targeting organizations in England, the US, Australia, Germany, Italy, and Switzerland, with around eight claimed victims including a Sydney-based property firm.
Infra: 💬 pippahtohg6qgioqu3ix🔗 4k6plf4h2cm2nco6ae3i
RLUpdated: 2026-08-10
View profile →
APT GROUP
Ransomware 7zip (a0.exe) variant cannot be decrypted Encrypts the first 2048 Bytes
Updated: 2026-08-10
View profile →
APT GROUP
Relic — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware CrypBoss Family
Updated: 2026-08-10
View profile →
← PreviousPage 216 / 269Next →