Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,747 entities
APT GROUPfinancial
PlayBoy Locker is a ransomware-as-a-service operation that emerged in September 2024, targeting Windows, NAS, and ESXi systems across multiple sectors on an 85/15 affiliate revenue split; its source code was reportedly sold underground by late 2024.
Infra: 🔗 vlofmq2u3f5amxmnblvx…💬 ovcbyl77wplz67mdcilq…
RSLUpdated: 2026-08-10
View profile →APT GROUP
A new distribution campaign is underway for a STOP Ransomware variant called KeyPass based on the amount of victims that have been seen. Unfortunately, how the ransomware is being distributed is unknown at this time.
Updated: 2026-08-10
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. This ransomware poses at MSOffice to fool users into opening the infected file. GO Ransomware
Updated: 2026-08-10
View profile →APT GROUP
Freezing crypto ransomware encrypts user data using AES, and then requires a ransom in # BTC to return the files. Original title: not indicated in the note. The file says: FreeMe.exe
Updated: 2026-08-10
View profile →APT GROUP
BlackShadow is a state-aligned cybercrime group reportedly linked to Iran’s cyber operations, first identified in late 2020. Their operations blend data exfiltration with ransom threats, notably targeting Israeli organizations such as Cyberserve—a web hosting provider—and leaking data to inflict reputational damage. Victims included entities like Atraf (an LGBTQ dating app), tour booking services, and museums, reflecting political or ideological motivations over financial gain. Despite carrying out extortion, there is no evidence that BlackShadow employs typical encryption-based ransomware mechanics; instead, they leverage stolen data and the threat of public exposure.
Updated: 2026-08-10
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 egregoranrmzapcv.oni…🔗 egregornews.com…
RSLUpdated: N/A
View profile →APT GROUPfinancial
A group which seems to recycle leak from other ransomware groups
Infra: 🔗 unsafeipw6wbkzzmj7yq…
RSLUpdated: N/A
View profile →APT GROUPfinancial
crazyhunter team — tracked by MISP Galaxy (ransomware).
Infra: 🔗 7i6sfmfvmqfaabjksckw…
RSLUpdated: 2026-08-10
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 6i42qq2xdu244a3xp2c3…
RSLUpdated: N/A
View profile →APT GROUPfinancial
paradise2 — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-10
View profile →APT GROUPfinancial
cipherwolf — tracked by MISP Galaxy (ransomware).
Infra: 🔗 b63zgpxrwqttrr6ti3jv…
RSLUpdated: 2026-08-10
View profile →APT GROUPfinancial
Quantum ransomware, active from mid-2021 through 2022, was a rebrand of the MountLocker/AstroLocker/XingLocker lineage that operated as RaaS, known for extremely fast attack timelines (under four hours from initial access to encryption) and ransom demands ranging from $150,000 to multi-million dollars.
Infra: 🔗 quantum445bh3gzuyilx…🔗 quantum445bh3gzuyilx…📁 26gzvue4vlgxuiaaotxl…+33 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
This group is believed to be connected to Lost Trust. El Dorado rebranded to BlackLock in September 2024.
Infra: 🔗 dataleakypypu7uwblm5…🔗 panelqbinglxczi2gqkw…🔗 panelqbinglxczi2gqkw…+4 more
RSLUpdated: 2026-08-10
View profile →