Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,747 entities
APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam (for example: “you have a criminal case against you”), fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →APT GROUPfinancial
sicari — tracked by MISP Galaxy (ransomware).
Infra: 🔗 sicariifoucvhyqg54sm…🔗 sicarilxx2br6esqnhad…🔗 sicari7m63wlggfxajiu…+3 more
Updated: 2026-08-11
View profile →APT GROUPfinancial
hyflock — tracked by MISP Galaxy (ransomware).
Infra: 🔗 e5hdifgit6ua7k4ggmlt…
Updated: 2026-08-11
View profile →APT GROUP
It’s directed to English and Chinese speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Python Ransomware
Updated: 2026-08-11
View profile →APT GROUP
new destrucrtive ransomware called Pedcont that claims to encrypt files because the victim has accessed illegal content on the deep web. The screen then goes blank and becomes unresponsive.
Updated: 2026-08-11
View profile →APT GROUP
BianLian used subtle techniques to exploit, enumerate, and move laterally in victim networks to remain undetected and aggressively worked to counter Endpoint Detection & Response (EDR) protections during the encryption phase of their operations. The group has displayed signs of being new to the practical business aspects of ransomware and associated logistics. Generally they seemed to be experiencing the growing pains of a group of talented hackers new to this aspect of criminal extortion.
Infrastructure associated with the BianLian group first appeared online in December 2021 and their toolset appears to have been under active development since then. Finally, we have observed the BianLian threat actor tripling their known command and control (C2) infrastructure in the month of August, suggesting a possible increase in the actor’s operational tempo.
Updated: 2026-08-11
View profile →APT GROUPfinancial
Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomware payload via DLL sideloading, targeting law firms, healthcare, financial services, and IT firms across the US and Japan with 19 known victims.
Infra: 🔗 cephalus6oiypuwumqlw…
RLUpdated: 2026-08-11
View profile →APT GROUPfinancial
KillSec originated as a hacktivist group aligned with the Anonymous movement before pivoting to ransomware operations in October 2023, officially launching a RaaS platform in June 2024 with an affiliate-friendly 88% revenue split, primarily targeting healthcare, financial services, and government sectors with over 250 documented victims as of late 2025.
Infra: 🔗 kill432ltnkqvaqntbal…
RLUpdated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →APT GROUP
Gerber Ransomware 1.0 — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →Justice Blade
Technical ID: Justice_Blade
APT GROUP
Justice_Blade — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →APT GROUP
Since this is the first detection of this malware in the wild, it’s not surprising that Babuk is not obsfuscated at all. Overall, it’s a pretty standard ransomware that utilizes some of the new techniques we see such as multi-threading encryption as well as abusing the Windows Restart Manager similar to Conti and REvil. For encrypting scheme, Babuk uses its own implementation of SHA256 hashing, ChaCha8 encryption, and Elliptic-curve Diffie–Hellman (ECDH) key generation and exchange algorithm to protect its keys and encrypt files. Like many ransomware that came before, it also has the ability to spread its encryption through enumerating the available network resources.
Updated: 2026-08-11
View profile →APT GROUPfinancial
Trisec is a Tunisian-origin ransomware group that emerged in February 2024, claiming affiliation with the Tunisian government and operating as both a financially motivated and state-sponsored mercenary group, exclusively recruiting Tunisian members and reporting nine victims in the first half of 2024.
Infra: 🔗 orfc3joknhrzscdbuxaj…🔗 orfc3joknhrzscdbuxaj…🔗 pkk4gbz7lsbgeja6s6iw…+3 more
RLUpdated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. The ransom is in the amount is 0.3 bitcoins. The ransomware is disguises themselves as Adobe Systems, Incorporated. RaaS
Updated: 2026-08-11
View profile →APT GROUPfinancial
booba team — tracked by MISP Galaxy (ransomware).
Infra: 💬 eazk7las3xsvsyxgww3j…🔗 7t3zi3e7ki6iseun77of…🔗 7t3zi3e7ki6iseun77of…+1 more
Updated: 2026-08-11
View profile →APT GROUPfinancial
MadCat is a suspected fraudulent ransomware operation that surfaced briefly in late 2023, apparently linked to scammers targeting other criminals on the dark web with fake stolen passport offers; its leak site appeared dead shortly after announcement, casting doubt on whether it ever operated as a genuine ransomware group.
RLUpdated: N/A
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 apvc24autvavxuc6.oni…
RSLUpdated: N/A
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →