Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,747 entities
APT GROUPfinancial
Radar (also known as Dispossessor), active since August 2023 and led by an actor called "Brain," was a RaaS group targeting small-to-mid-sized businesses across healthcare, education, finance, and transportation in over 14 countries; it was dismantled by an FBI-led international operation in August 2024 that seized 24 servers and 9 criminal domains.
Affiliates: radar • qwerty • rav3n • rin +14
Infra: 🔗 radar.ltd…🔗 3bnusfu2lgk5at43ceu7…📁 4q5tsu5o3msmv4am4dfh…+1 more
RLUpdated: 2026-08-11
View profile →APT GROUPfinancial
ValenciaLeaks is a data-extortion group that surfaced in August–September 2024, focused on exfiltrating large volumes of data and publishing it on a dedicated leak site, with documented victims including the City of Pleasanton, CA (283 GB exfiltrated) and pharmaceutical firm Duo Pharma Biotech.
RLUpdated: N/A
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 4zrjdyuq4sjogm2epwwo…🔗 4zrjdyuq4sjogm2epwwo…
RSLUpdated: N/A
View profile →APT GROUP
Spartacus Ransomware — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread by its creator in forums. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files and documents and more. The ransom is 0.1 bitcoins within 72 hours. Uses Windows Update as a decoy. Creator: Talnaci Alexandru
Updated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It SUPPOSEDLY encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc., however your files are not really encrypted, only the names are changed.
Updated: 2026-08-11
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →APT GROUPfinancial
red ransomware — tracked by MISP Galaxy (ransomware).
Infra: 🔗 33zo6hifw4usofzdnz74…📁 ybxtfftwy2iwfqjy7fvv…
Updated: 2026-08-11
View profile →APT GROUP
This crypto-extortioner encrypts user data using AES, and then requires a $ 30- $ 50- $ 80 buy- back to BTC to return the files. The name is original. Written on AutoIt.
Updated: 2026-08-11
View profile →APT GROUPfinancial
dAn0n emerged in early 2024 operating a RaaS model, rapidly claiming 13 victims in May 2024 alone, predominantly targeting US-based organizations in business services and filling the vacuum left by disruptions to LockBit and BlackCat/ALPHV.
RLUpdated: N/A
View profile →APT GROUPfinancial
Lolnek (also known as Lolkek/GlobeImposter) is a commodity ransomware strain primarily targeting small and medium-sized businesses with relatively low ransom demands, associated with the TZW ransomware family, and unsophisticated compared to major RaaS operations with no formal affiliate program.
Infra: 🔗 mmeeiix2ejdwkmseyclj…💬 obzuqvr5424kkc4unbq2…💬 nclen75pwlgebpxpsqhl…+5 more
RLUpdated: N/A
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. The ransom is 0.33 bitcoins.
Updated: 2026-08-11
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. Payments in Monero
Updated: 2026-08-11
View profile →APT GROUPfinancial
Sparta is a short-lived ransomware group first observed in September 2022 that conducted double-extortion attacks primarily targeting organizations in Spain before ceasing activity, gaining initial access via phishing and exploitation of unpatched systems.
Infra: 🔗 zj2ex44e2b2xi43m2txk…📁 z33da2c5d6t4ekkv4pxa…
RLUpdated: N/A
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 mountnewsokhwilx.oni…
RSLUpdated: N/A
View profile →APT GROUPfinancial
CoomingProject is a ransomware group that emerged around 2021 and operated a double-extortion scheme with multiple Tor-based leak sites; six members were identified by French authorities in February 2022, after which the group's infrastructure went offline.
Infra: 🔗 z6mikrtphid5fmn52nbc…🔗 teo7aj5mfgzxyeme.oni…
RLUpdated: N/A
View profile →