Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,747 entities
APT GROUPfinancial
malek team — tracked by MISP Galaxy (ransomware).
Infra: 🔗 malekteam.ac…🔗 195.14.123.2.…
RSLUpdated: 2026-08-10
View profile →APT GROUPfinancial
leakeddata — tracked by MISP Galaxy (ransomware).
Infra: 🔗 business-data-leaks.…📁 ep6pheij.com…
RSLUpdated: 2026-08-10
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. This is a trollware that does not encrypt your files but makes your computer act crazy (like in the video in the link below). It is meant to be annoying and it is hard to erase from your PC, but possible.
Updated: 2026-08-10
View profile →APT GROUPfinancial
NoName (also known as CosmicBeetle) is a ransomware group active since at least 2020 targeting small and medium-sized businesses globally using its custom ScRansom tool, exploiting vulnerabilities like EternalBlue and ZeroLogon, and becoming a RansomHub affiliate to access that platform's RaaS infrastructure.
Infra: 🔗 noname2j6zkgnt7ftxsj…🔗 www.lockbitblog.info…🔗 7tkffbh3qiumpfjfq77p…+2 more
RLUpdated: 2026-08-10
View profile →APT GROUPfinancial
Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria.
Infra: 🔗 fewcriet5rhoy66k6c4c…
RLUpdated: 2026-08-10
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Original name is Mission 1996 or Mission: “Impossible” (1996) (like the movie)
Updated: 2026-08-10
View profile →APT GROUPfinancial
Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia across manufacturing, communications, and construction sectors, operating a Tor-based double-extortion leak site.
Infra: 🔗 brohoodyaifh2ptccph5…📁 fotxzhnoxtkpa6cwkimy…📁 a5wdkdd7unaacdlzcjm5…+12 more
RLUpdated: 2026-08-10
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →APT GROUP
Maui ransomware stand out because of a lack of several key features commonly seen with tooling from RaaS providers, such as an embedded ransom note to provide recovery instructions or automated means of transmitting encryption keys to attackers. Instead, it is believed that Maui is manually operated, in which operators will specify which files to encrypt when executing it and then exfiltrate the resulting runtime artifacts. There are many aspects to Maui ransomware that are unknown, including usage context.
Updated: 2026-08-10
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 flock4cvoeqm4c62gyoh…
RSLUpdated: N/A
View profile →APT GROUPfinancial
M3rx is a small ransomware group first observed in 2025, using AES-CTR/AES-GCM encryption and targeting organizations in England, the US, Australia, Germany, Italy, and Switzerland, with around eight claimed victims including a Sydney-based property firm.
Infra: 💬 pippahtohg6qgioqu3ix…🔗 4k6plf4h2cm2nco6ae3i…
RLUpdated: 2026-08-10
View profile →APT GROUP
Ransomware 7zip (a0.exe) variant cannot be decrypted Encrypts the first 2048 Bytes
Updated: 2026-08-10
View profile →