Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,747 entities
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware Variant of CryPy
Updated: 2026-08-10
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
HelloGookie is a rebrand of the HelloKitty ransomware group announced in April 2024, releasing previously stolen data from CD Projekt Red and Cisco; HelloKitty/HelloGookie has been active since 2020 with its highest-profile attack being the 2021 breach of CD Projekt Red.
Infra: 🔗 gookie256cvccntvenyx
RSLUpdated: 2026-08-10
View profile →
APT GROUP
Unknown — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-10
View profile →
APT GROUPfinancial
VanirGroup is an Eastern European ransomware group composed of former affiliates from Karakurt, LockBit, and Knight ransomware that emerged in mid-2024, before German law enforcement (Karlsruhe Public Prosecutor's Office) seized its leak site.
RLUpdated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
Kryptos is a small ransomware group first observed in October 2025, conducting simultaneous attacks across North America and Oceania on its debut day with a focus on professional, technical, and legal service sectors, with only 3 known documented victims.
Infra: 🔗 kryptospnjzz7vfkr663
RSLUpdated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
MintEye is a ransomware group with concentrated activity in North America, targeting professional services, construction, engineering, architecture, and logistics sectors, with victims documented in the US and Chile; limited public technical analysis is available.
Infra: 🔗 85.121.48.68📁 i6575ykikb3yvut4btuc
RSLUpdated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
Dablio Ransomware — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUP
Ransomware Variant of Kirk
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
Designed to target Windows systems, this ransomware employs advanced encryption techniques and appends a unique file extension to compromised files. Its stealthy evasion tactics and persistence mechanisms make detection and removal challenging. This highlights the need for proactive cybersecurity measures and a robust incident response strategy to safeguard data integrity and minimize breach risks.
Infra: 💬 vanhelqmjstkvlhrjwzg🔗 vanhelvuuo4k3xsiq626🔗 vanhelxjo52qr2ixcmtj+7 more
RSLUpdated: 2026-08-10
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 exfil5gqmbxrg6yky5ae
RSLUpdated: N/A
View profile →
APT GROUPfinancial
ChileLocker (also known as ARCrypter) first appeared in August 2022 after attacking a Chilean government agency and quickly expanded globally, appending a ".crypt" extension to encrypted files and recruiting affiliates under a RaaS model on criminal forums.
Infra: 🔗 z6vidveub2ypo3d3x7om💬 ebljej7okwfnx5hdfikq💬 7wa2bi6grhbu4opt5bgu
RSLUpdated: 2026-08-10
View profile →
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →
APT GROUPfinancial
weaxor — tracked by MISP Galaxy (ransomware).
Infra: 💬 weaxorpemwzoxg5cdvvf
RSLUpdated: 2026-08-10
View profile →
APT GROUPfinancial
Zeon was the precursor identity used by the group that rebranded as Royal in September 2022, composed primarily of former Conti "Team One" members, deliberately avoiding the RaaS model and keeping its code and infrastructure private.
Infra: 🔗 zeonrefpbompx6rwdqa5
RSLUpdated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomhouse — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-10
View profile →
APT GROUPfinancial
wallstreet — tracked by MISP Galaxy (ransomware).
RLUpdated: N/A
View profile →
APT GROUPfinancial
crpx0 — tracked by MISP Galaxy (ransomware).
Infra: 🔗 tlxoddx4odmc2qvsmtsb🔗 crpx0.su
RSLUpdated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
the gentlemen — tracked by MISP Galaxy (ransomware).
Infra: 🔗 tezwsse5czllksjb7cwp💬 i2ohjeeqe37jre4f2u7p
RSLUpdated: 2026-08-10
View profile →
APT GROUPfinancial
A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked.<BR> > <BR> > The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
RLUpdated: N/A
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
Direct Extortion Double Extortion
RLUpdated: N/A
View profile →
APT GROUPfinancial
Group is also currently known as MADDLL32 and Metatron.
Infra: 🔗 k67ivvik3dikqi4gy4ua
RSLUpdated: 2026-08-10
View profile →
← PreviousPage 223 / 269Next →