Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,747 entities
APT GROUPfinancial
MBC is a very obscure ransomware group with minimal public documentation and no significant threat intelligence reports available from mainstream security vendors.
Infra: 🔗 xembshruusobgbvxg4tc…
RSLUpdated: N/A
View profile →APT GROUPfinancial
blackfile — tracked by MISP Galaxy (ransomware).
Infra: 🔗 blacknbsxfdmjtx4yn53…
RSLUpdated: 2026-08-10
View profile →APT GROUP
Wants a ransom to get the victim’s files back . Originated in English. Spread worldwide.
Updated: 2026-08-10
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →APT GROUPfinancial
rapture — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-10
View profile →APT GROUPfinancial
prinz eugen — tracked by MISP Galaxy (ransomware).
Affiliates: ROOTBOY
Infra: 🔗 6cudc5cqa2bjpwdhcwm2…🔗 prinzfkbjiazbrur4mjj…🔗 prinzkpn6d3itrgcytms…
RSLUpdated: 2026-08-10
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →APT GROUPfinancial
Linkc is a ransomware group first observed in February 2025, operating a Tor-based data leak site and targeting US-based AI, cloud, aerospace, and manufacturing companies — including H2O.ai — demanding ransoms as high as $15 million using double-extortion tactics.
Infra: 🔗 iywqjjaf2zioehzzauys…💬 xs4psqhvekjle3qwyiav…
RSLUpdated: 2026-08-10
View profile →APT GROUPfinancial
Insomnia is a data-theft and extortion group that emerged in October 2025, targeting primarily US-based healthcare organizations — stealing patient files and threatening public exposure rather than encrypting files — and avoiding former Soviet states, consistent with Russian-speaking cybercrime norms.
Infra: 🔗 i62huw7ve22rpyw6lnq3…📁 r3keoxye5mki4fqcvlk4…
RSLUpdated: 2026-08-10
View profile →APT GROUP
Cisco Talos has identified a new, previously unknown threat actor of Vietnamese origin conducting a ransomware operation that began at least on June 4, 2023.
The ongoing attack utilizes a variant of the Yashma Ransomware, likely targeting multiple geographical areas and mimicking the characteristics of WannaCry.
The threat actor uses an unusual technique to deliver the ransom note, as instead of embedding the ransom note strings in the binary, the actor downloads the ransom note from a GitHub repository controlled by ,the actor by executing an embedded batch file.
Talos stated that this threat actor targets victims in English-speaking countries, Bulgaria, China, and Vietnam, as the GitHub account of the actor "nguyenvientphat" contains ransomware notes written in the languages of these countries. The presence of the ransom note may indicate that the actor intends to expand its geographical area of operation.
The company also stated that the threat actor may have Vietnamese origin because the GitHub account name and email contact in the ransom notes fake the name of a legitimate organization. The ransom note also asks victims to contact between 19:00 and 23:00 UTC +07:00, coinciding with the Vietnam time zone.
A difference was also identified in the Vietnamese language ransom note, as it begins with "Sorry, your file is encrypted!" compared to the other notes that state "Oops, your files are encrypted!". By saying "sorry," the threat actor may intend to show greater sensitivity to victims in Vietnam, indicating that the attackers themselves are Vietnamese.
Talos further mentioned that the threat actor started the campaign around June 4, 2023, as they joined GitHub and created a public repository called "Ransomware." In the repository, the threat actor added text files of ransom notes in five languages: English, Bulgarian, Vietnamese, simplified Chinese, and traditional Chinese.
The note presents the email address "nguyenvietphat[.]n@gmail[.]com," for victims to contact them. At the time of analysis, no Bitcoin was observed in the wallet, and the ransom note did not specify an amount, indicating that the ransomware operation could still be in its early stages.
The threat actor deployed a variant of the Yashma ransomware, which they compiled on June 4, 2023. It is worth noting that Yashma is a 32-bit executable written in .NET and a renamed version of the Chaos Ransomware V5, which appeared in May 2022. In the variant, most of Yashma's features remained unchanged and were described by BlackBerry security researchers, with some notable modifications.
The ransomware stores the ransom note text as strings in the binary, but this Yashma variant executes an embedded batch file, which contains the commands to download the ransom note from the actor-controlled GitHub repository. This modification avoids endpoint detection solutions and antivirus software, which typically detect embedded ransom note strings in the binary.
Previous versions of Yashma established persistence on the victim's machine in the Run registry key and by dropping a Windows shortcut file pointing to the executable path of the ransomware in the startup folder. The identified variant also established persistence in the Run registry key. However, it was modified to create a ".url" favorites file in the startup folder pointing to the executable located in "%AppData%\Roaming\svchost.exe."
Additionally, the threat actor chose to maintain Yashma's anti-recovery capability in this variant. After encrypting a file, the ransomware wipes the content of the original unencrypted files, writes a single "?" character, and then deletes the file. This technique makes it more difficult for incident responders and forensic analysts to recover deleted files from the victim's hard drive.
Updated: 2026-08-10
View profile →APT GROUPfinancial
In mid-June 2024, a new ransomware operation named Brain Cipher emerged, notably targeting Indonesia's National Data Center. This attack disrupted immigration operations at airports and various other government services.
The payload employed by this group is based on the leaked LockBit 3.0 builder. Comparative analyses have confirmed significant similarities between Brain Cipher and LockBit 3.0 samples. Notably, the attackers modified the ransomware to not only append a new extension to encrypted files but also to encrypt the filenames themselves.
Additionally, it was identified that the group appears to be in its early stages, as evidenced by their use of the leaked LockBit 3.0 builder and their recent operations. After encrypting the data, the ransomware generates ransom notes named “added_extension.README.txt.” These notes contain a description of what occurred and a link to the attackers' website hosted on the Tor network.
Infra: 🔗 mybmtbgd7aprdnw2ekxh…🔗 vkvsgl7lhipjirmz6j5u…📁 cuuhrxbg52c5agytmtjp…+36 more
RSLUpdated: 2026-08-10
View profile →APT GROUP
Today one of our volunteers, Aura, told me about a new new malspam campaign pretending to be from Craigslist that is under way and distributing the Sigma Ransomware. These spam emails contain password protected Word or RTF documents that download the Sigma Ransomware executable from a remote site and install it on a recipients computer.
Updated: 2026-08-10
View profile →APT GROUP
About: This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →APT GROUPfinancial
b0 group — tracked by MISP Galaxy (ransomware).
Infra: 🔗 bzsn5crutf7eiq5mlohn…
RSLUpdated: 2026-08-10
View profile →APT GROUPfinancial
osyolorz collective — tracked by MISP Galaxy (ransomware).
Infra: 🔗 hackerosyolorz77y7vw…
RSLUpdated: 2026-08-10
View profile →