Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,747 entities
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware Files might be partially encrypted
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware via remote attacker. tuyuljahat@hotmail.com contact address
Updated: 2026-08-10
View profile →
APT GROUPfinancial
The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
RLUpdated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
S!Ri found a new Thanatos Ransomware variant called PICO Ransomware. This ransomware will append the .PICO extension to encrypted files and drop a ransom note named README.txt.
Updated: 2026-08-10
View profile →
APT GROUPfinancial
Genesis is an emerging ransomware group first observed in late 2025, targeting small to mid-sized US organizations across healthcare, retail, financial services, legal, and manufacturing using double-extortion tactics, focusing heavily on data exfiltration and public leaking.
Infra: 🔗 genesis6ixpb5mcy4kud
RLUpdated: 2026-08-10
View profile →
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
NetWalker ransomware group operates by the threat actor known as "CIRCUS SPIDER". The NetWalker ransomware was discovered in 2019. The group mainly targeting the Asia Pacific region but can attack globally. The group uses common attacking tools like Mimikatz and other legitimate tools (LOLBINS) like PSTools, AnyDesk, TeamViewer, NLBrute, and more. The group knowing by targeting the healthcare sector. Finally, in January 2021, Netwalker was takedown by the authorities, the police have confiscated hundreds of thousands of dollars in ransom payments collected by the Netwalker group, and they seized servers and disrupted the infrastructure and the darknet websites of the Netwalker ransomware group.
Infra: 🔗 rnfdsgm6wb6j6su5txke🔗 pb36hu4spl6cyjdfhing
RLUpdated: N/A
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. This is a fake ransomware. Your files are not really encrypted, however the attacker does ask for a ransom of .03 bitcoins. It is still dangerous even though it is fake, he still go through to your computer.
Updated: 2026-08-10
View profile →
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
wallstreet — tracked by MISP Galaxy (ransomware).
Infra: 🔗 4dwiv37h7hhuhjpvtn72
RSLUpdated: 2026-08-10
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →
APT GROUP
A new ransomware variant has been identified, named DORRA. It is worth mentioning in advance that this variant is derived from the Makop ransomware family. This variant encrypts data by adding the “.DORRA” extension to files, as well as a unique ID and the ransomware developer's email address. After encrypting the data, the payload creates a ransom note as a text file named “README-WANING.txt,” through which victims are instructed to contact the threat actor via the provided email to decrypt the data. Interestingly, this variant uses a simple email address hosted on Microsoft's Outlook service as the contact method.
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
AES KEY GEN ASSIST Ransomware
Technical ID: AES_KEY_GEN_ASSIST Ransomware
APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc…
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
RANSOMED.VC aka Raznatovic
Infra: 🔗 f6amq3izzsgtna4vw24r🔗 f6amq3izzsgtna4vw24r🔗 ransomed.vc+1 more
RLUpdated: 2026-08-10
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 petya37h5tbhyvki.oni🔗 petya5koahtsf7sv.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
RansomedVC2 aka RebornVC aka RansomedVC (rebrand) under new leadership.
Infra: 🔗 ransomed.biz🔗 ransomed.vc
RSLUpdated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUP
Ransomware Uses https://diskcryptor.net for full disk encryption
Updated: 2026-08-10
View profile →
APT GROUPfinancial
Aurora is a ransomware group associated with a multi-purpose Go-based malware distributed by multiple criminal teams from mid-2022, also sold as an infostealer/botnet under the same name on underground forums.
Infra: 💬 ijexszhscln27nl263lm📁 pavregldzg2ypbd3gxbi📁 exposedrecords.io
RLUpdated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware Prepends files Demands 48.48 BTC
Updated: 2026-08-10
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 wemo2ysyeq6km2nqhcrz
RSLUpdated: N/A
View profile →
APT GROUP
RSAUtil is distributed by the developer hacking into remote desktop services and uploading a package of files. This package contains a variety of tools, a config file that determines how the ransomware executes, and the ransomware itself.
Updated: 2026-08-10
View profile →
Funfact uses an open code for GNU Privacy Guard (GnuPG), then asks to email them to find out the amout of bitcoin to send (to receive a decrypt code). Written in English, can attach all over the world. The ransom is 1.22038 BTC, which is 1100USD.
Updated: 2026-08-10
View profile →
APT GROUP
TOX: D3404141459BC7206CC4AFEC16A3403F262C0937A732C12644E7CA97F0615201A519F7EAB2E2
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →
APT GROUPfinancial
Beast is a Ransomware-as-a-service (RaaS) product which provides functionality such as SMB scanning, file encryption, service and process starting and stopping, and geographic identification to avoid encryption in CIS countries.
Infra: 🔗 beast6azu4f7fxjakiay📁 ooie6tet7ggcmlgvtmyv📁 xzxvf4x2hxivr3q2ffzu+7 more
RLUpdated: 2026-08-10
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
← PreviousPage 219 / 269Next →