Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,747 entities
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
aka Onix/Onyx
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
Axxes ransomware emerged as a rebranded version of the previously known Midas ransomware group, with roots also tracing back through Haron and Avaddon lineage. It operates via a single-extortion model, encrypting files and appending the .axxes extension. Victims receive both an “RESTORE_FILES_INFO.hta” and a “.txt” ransom note. The ransomware performs extra actions like determining the device’s geolocation, modifying the Windows Firewall, changing file extensions, and terminating processes using taskkill.exe. Its known targets span the U.S., UAE, France, and China, including at least one high-profile victim—The H Dubai hotel. This group appears financially motivated, leveraging historical branding and code of earlier groups for its operations.
Infra: 🔗 ymnbqd5gmtxc2wepkesq
RSLUpdated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →
APT GROUPfinancial
kryptina — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-10
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Every file is encrypted with a personal AES-key, and then AES-key encrypts with a RSA-1028 key. Hacking by TeleBots (Sandworm). Goes under a fake name: Update center or Microsoft Update center.
Updated: 2026-08-10
View profile →
APT GROUP
16x — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
taronis — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-10
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
A new Ransomware-as-a-Service called Jokeroo is being promoted on underground hacking sites and via Twitter that allows affiliates to allegedly gain access to a fully functional ransomware and payment server. According to a malware researcher named Damian, the Jokeroo RaaS first started promoting itself as a GandCrab Ransomware RaaS on the underground hacking forum Exploit.in.
Updated: 2026-08-10
View profile →
APT GROUPfinancial
monolock — tracked by MISP Galaxy (ransomware).
Infra: 🔗 mlock.tel
RSLUpdated: 2026-08-10
View profile →
A new infection is being distributed by porn sites that tries to blackmail a victim into paying a ransom by stating they will tell law enforcement that the victim is spreading child porn. This is done by collecting information about the user, including screen shots of their active desktop, in order to catch them in compromising situations.
Updated: 2026-08-10
View profile →
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Ransom is 3 bitcoins. Extesion depends on the config file. It seems Globe is a ransomware kit.
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware contact email safefiles32@mail.ru also as prefix in encrypted file contents
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware Based on EDA2
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware Based on EDA2
Updated: 2026-08-10
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 z3mojpjnxt5tgqvu4wgo
RSLUpdated: N/A
View profile →
APT GROUPfinancial
lockbit4 — tracked by MISP Galaxy (ransomware).
Affiliates: LockBitSupp • Wazawaka
Infra: 🔗 lockbitapyx2kr5b7ma7🔗 lockbitapyum2wks2lbc🔗 lockbitapp24bvbi43n3+2 more
RSLUpdated: 2026-08-10
View profile →
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Lolnek — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Razor was discovered by dnwls0719, it is a part of Garrantydecrypt ransomware family. Like many other programs of this type, Razor is designed to encrypt files (make them unusable/inaccessible), change their filenames, create a ransom note and change victim's desktop wallpaper. Razor renames files by appending the ".razor" extension to their filenames. For example, it renames "1.jpg" to "1.jpg.razor", and so on. It creates a ransom note which is a text file named "#RECOVERY#.txt", this file contains instructions on how to contact Razor's developers (cyber criminals) and other details. As stated in the "#RECOVERY#.txt" file, this ransomware encrypts all files and information about how to purchase a decryption tool can be received by contacting Razor's developers. Victims supposed to contact them via razor2020@protonmail.ch, Jabber client (razor2020@jxmpp.jp) or ICQ client (@razor2020) and wait for further instructions. It is very likely that they will name a price of a decryption tool and/or key and provide cryptocurrency wallet's address that should be used to make a transaction. However, it is never a good idea to trust (pay) any cyber criminals/ransomware developers. It is common that they do not provide decryption tools even after a payment. Another problem is that ransomware-type programs encrypt files with strong encryption algorithms and their developers are the only ones who have tools that can decrypt files encrypted by their ransomware. In most cases victims have the only free and safe option: to restore files from a backup. Also, it is worth mentioning that files remain encrypted even after uninstallation of ransomware, its removal only prevents it from causing further encryptions.
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →
← PreviousPage 221 / 269Next →