Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,747 entities
APT GROUPfinancial
#MakeIsraelGreatAgain
Infra: 🔗 q7gmt7pbo4rrt27ydkiv…
RSLUpdated: 2026-08-10
View profile →APT GROUPfinancial
encrypthub — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-10
View profile →APT GROUPfinancial
grep — tracked by MISP Galaxy (ransomware).
Infra: 🔗 grep3ql4yhlmpq5zy3en…
RSLUpdated: 2026-08-10
View profile →APT GROUPfinancial
aka Cring / Ghost (Cring)
<br/>
<br/>Beginning early 2021, Ghost actors began attacking victims whose internet facing services ran outdated versions of software and firmware. This indiscriminate targeting of networks containing vulnerabilities has led to the compromise of organizations across more than 70 countries, including organizations in China. Ghost actors, located in China, conduct these widespread attacks for financial gain. Affected victims include critical infrastructure, schools and universities, healthcare, government networks, religious institutions, technology and manufacturing companies, and numerous small- and medium-sized businesses.
<br/>
<br/>Ghost actors rotate their ransomware executable payloads, switch file extensions for encrypted files, modify ransom note text, and use numerous ransom email addresses, which has led to variable attribution of this group over time. Names associated with this group include Ghost, Cring, Crypt3r, Phantom, Strike, Hello, Wickrme, HsHarada, and Rapture. Samples of ransomware files Ghost used during attacks are: Cring.exe, Ghost.exe, ElysiumO.exe, and Locker.exe.
<br/>
<br/>https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-050a
RSLUpdated: 2026-08-10
View profile →APT GROUPfinancial
arcus media — tracked by MISP Galaxy (ransomware).
Infra: 🔗 arcuufpr5xxbbkin4mli…
RSLUpdated: 2026-08-10
View profile →APT GROUPfinancial
OnePercent Group is a cybercriminal operation active since at least November 2020 that targeted US organizations using phishing with IcedID trojans, Cobalt Strike, and double-extortion, threatening a "one percent leak" of data before escalating to a full dump or sale to REvil; the FBI issued a formal flash advisory in August 2021.
Infra: 🔗 5mvifa3xq5m7sou3xzaa…
RLUpdated: N/A
View profile →APT GROUPfinancial
octovillan — tracked by MISP Galaxy (ransomware).
Infra: 🔗 jvdg26n32ufrgd2c.oni…
RSLUpdated: 2026-08-10
View profile →APT GROUPfinancial
Chort is a double-extortion ransomware group (whose name means "Devil" in Russian) that emerged in October 2024, primarily targeting US education and government sectors, with notable victims including the City of Sheboygan and Kuwait's Ministry of Finance.
Infra: 🔗 hgxyonufefcglpekxma5…
RLUpdated: 2026-08-10
View profile →APT GROUP
[Frankenstein](https://attack.mitre.org/groups/G0101) is a campaign carried out between January and April 2019 by unknown threat actors. The campaign name comes from the actors' ability to piece together several unrelated components.(Citation: Talos Frankenstein June 2019)
Updated: N/A
View profile →APT GROUP
About: This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-10
View profile →APT GROUPfinancial
Cheers is a Linux-based ransomware group that emerged in 2022, built on leaked Babuk source code and specializing in attacks against VMware ESXi servers, running a double-extortion leak site with four documented victims.
Affiliates: BRONZE STARLIGHT team
Infra: 🔗 rwiajgajdr4kzlnrj5zw…🔗 crkfkmrh4qzbddfrl2ax…
RLUpdated: N/A
View profile →