Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,747 entities
The Kraken Cryptor Ransomware is a newer ransomware that was released in August 2018. A new version, called Kraken Cryptor 1.5, was recently released that is masquerading as the legitimate SuperAntiSpyware anti-malware program in order to trick users into installing it.
Updated: 2026-08-10
View profile →
APT GROUPfinancial
Rebranded to Sabbath.
RSLUpdated: 2026-08-10
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 sifrecikx7s62cjv.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
audit team — tracked by MISP Galaxy (ransomware).
Infra: 🔗 6tdqqaxftvradka5d2fr📁 cjg2avmzoly7k6mw7xob
RSLUpdated: 2026-08-10
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Filemarker: "HERMES"
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
T1025T1059.005T1685
Updated: 2026-08-10
View profile →
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
root — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-10
View profile →
APT GROUPfinancial
Frag is a ransomware group that emerged in late 2024, exploiting a critical Veeam Backup & Replication vulnerability (CVE-2024-40711) to compromise targets in industrial sectors, with blockchain analysis linking it to a shared wallet cluster with the Akira group.
Infra: 💬 xhvzsaxl3vbio6dg547e🔗 34o4m3f26ucyeddzpf53🔗 34o4m3f26ucyeddzpf53+1 more
RLUpdated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
Ransomware May download additional malware after encryption
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
clearwater — tracked by MISP Galaxy (ransomware).
Infra: 💬 b6rgpykvtyqah4q5tii2
RSLUpdated: 2026-08-10
View profile →
Crypto Lab
Technical ID: Crypto_Lab
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
blackbyte-crux — tracked by MISP Galaxy (ransomware).
Infra: 🔗 dounczge5jhw4iztnnpz📁 faow6n2hkweyyalp67zv
RSLUpdated: 2026-08-10
View profile →
APT GROUP
Ransomware only encrypts .jpg files
Updated: 2026-08-10
View profile →
APT GROUP
[Andariel](https://attack.mitre.org/groups/G0138) is a North Korean state-sponsored threat group that has been active since at least 2009. [Andariel](https://attack.mitre.org/groups/G0138) has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a variety of domestic companies; they have also conducted cyber financial operations against ATMs, banks, and cryptocurrency exchanges. [Andariel](https://attack.mitre.org/groups/G0138)'s notable activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle.(Citation: FSI Andariel Campaign Rifle July 2017)(Citation: IssueMakersLab Andariel GoldenAxe May 2017)(Citation: AhnLab Andariel Subgroup of Lazarus June 2018)(Citation: TrendMicro New Andariel Tactics July 2018)(Citation: CrowdStrike Silent Chollima Adversary September 2021) [Andariel](https://attack.mitre.org/groups/G0138) is considered a sub-set of [Lazarus Group](https://attack.mitre.org/groups/G0032), and has been attributed to North Korea's Reconnaissance General Bureau.(Citation: Treasury North Korean Cyber Groups September 2019) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name [Lazarus Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or subgroups.
T1590.005T1203T1204.002
Updated: N/A
View profile →
APT GROUPfinancial
sevyware — tracked by MISP Galaxy (ransomware).
Infra: 🔗 sevykkkuzbxjpkb7gtfx
RSLUpdated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
BlackBit ransomware was first observed in August 2022 and is a .NET-based strain that closely mimics the design and functionality of LockBit 3.0, indicating either a fork of LockBit’s leaked builder or deliberate imitation. It uses a double-extortion model, encrypting victim files and threatening to leak stolen data via a Tor-based site. BlackBit employs AES symmetric encryption for file contents and RSA asymmetric encryption for key protection, appending the .BlackBit extension to affected files. The malware also includes features for terminating processes, deleting volume shadow copies, and disabling recovery mechanisms. Initial access vectors are not comprehensively documented but are consistent with phishing, exploitation of vulnerable public-facing services, and the use of compromised credentials. Victims have been identified across various sectors, including technology, manufacturing, and professional services, though its activity level has been far lower than LockBit’s.
Infra: 🔗 blackbittk6ux3mtrbh2
RSLUpdated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Affiliates: http://breachsfl6m2b52sznjg56r5wsy3jovh6vakzegbgjhwfpftwrkmsdad.onion/members/darksupp.668586/
Infra: 🔗 s42fv44x5r2ubrrydl5e🔗 rda6wisv3wkznfz5uimk🔗 2el6bpoz2ely34iqcmxs+14 more
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Babuk Locker 2.0, also known as Bjorka or SkyWave, after failing to make any profit from selling public databases on forums, decided to impersonate Babuk Ransomware group. He launched a blog where he claimed multiple public breaches from BreachForums as ransomware attacks
RLUpdated: N/A
View profile →
APT GROUPfinancial
mcafee — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. This ransomware uses the known online library as a decoy. It poses as Netflix Code generator for Netflix login, but instead encrypts your files. The ransom is 100$ in Bitcoins.
Updated: 2026-08-10
View profile →
APT GROUPfinancial
Faust is a variant of the well-known Phobos ransomware, part of a Ransomware-as-a-Service (RaaS) ecosystem active since around May 2019. Faust employs a double-extortion model, encrypting victim files and threatening to release stolen data if ransom demands are not met. It's distributed via Office document payloads using VBA scripts and known for its fileless attack delivery, enabling stealth and evasion.
RSLUpdated: 2026-08-10
View profile →
APT GROUP
Ransomware Based on EDA2
Updated: 2026-08-10
View profile →
Ransomware
Updated: 2026-08-10
View profile →
PGPSnippet Ransomware — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
← PreviousPage 225 / 269Next →