Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,747 entities
APT GROUPfinancial
Skira is a small ransomware group that emerged around late 2024, claiming responsibility for the breach of Carruth Compliance Consulting that exposed SSNs, W-2s, and financial records of employees across 36 US school districts, with five total claimed victims across the US, Turkey, and India.
RLUpdated: N/A
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. CrySiS > Dharma Note: ATTENTION! At the moment, your system is not protected. We can fix it and restore files. To restore the system write to this address: bitcoin143@india.com. CrySiS variant
Updated: 2026-08-11
View profile →APT GROUPfinancial
Spook ransomware operated briefly in September–October 2021 as a rebrand of the Prometheus ransomware group (built on the Thanos builder), conducting double-extortion attacks against global targets with a concentration in manufacturing and unusually publishing all victim names regardless of ransom payment.
Infra: 🔗 spookuhvfyxzph54ikjf…
RLUpdated: N/A
View profile →help restoremydata
Technical ID: help_restoremydata
APT GROUPfinancial
.help_restoremydata
<br/>ext : .help_restoremydata
<br/>note : HOW_TO_RECOVERY_FILES.html
<br/>mail : help@restoremydata.pw
<br/>md5 : b1e8b6c2b65d51893bbe61d46cbdb4af
Infra: 💬 gzdn6yjvmrujiqzz4wwu…
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
phalcon — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →APT GROUP
A new ransomware group is said to have emerged in mid-April 2024, under the name "APT73." It's worth noting that the group reportedly self-proclaimed as an APT, which stands for "Advanced Persistent Threat" in the cybersecurity field.
According to research, much of the available information about the aforementioned group came from another ransomware group known as LockBit. This is evident as the group, on its Data Leak Site (DLS) website, added pages such as "Contact Us," "How to buy Bitcoin," "Web Security Bug Bounty," and "Mirrors."
Another relevant fact is that this group is also known as Ransomware Eraleig. This is because the group allegedly used a domain in the past to disclose information about victims. There is no information available about any Tactics, Techniques, and Procedures associated with this ransomware group, nor about the latest artifacts used for encryption purposes.
Updated: 2026-08-11
View profile →APT GROUPfinancial
The QNAPCrypt ransomware works similarly to other ransomware, including encrypting all files and delivering a ransom note. However, there are several important differences:1. The ransom note was included solely as a text file, without any message on the screen—naturally, because it is a server and not an endpoint.2. Every victim is provided with a different, unique Bitcoin wallet—this could help the attackers avoid being traced.3. Once a victim is compromised, the malware requests a wallet address and a public RSA key from the command and control server (C&C) before file encryption.
Infra: 🔗 veqlxhq7ub5qze3qy56z…💬 7zvu7njrx7q734kvk435…
RLUpdated: N/A
View profile →APT GROUPfinancial
BabyDuck is a ransomware group tracked on ransomware.live with approximately 180 claimed victims, appending the .babyduck extension to encrypted files, distinct from the better-known Babuk group.
Infra: 🔗 babydovegkmhbontykzi…
RLUpdated: N/A
View profile →APT GROUP
A new ransomware called HC7 is infecting victims by hacking into Windows computers that are running publicly accessible Remote Desktop services. Once the developers gain access to the hacked computer, the HC7 ransomware is then installed on all accessible computers on the network.
Originally released as HC6, victims began posting about it in the BleepingComputer forums towards the end of November. As this is a Python-to-exe executable, once the script was extracted ID Ransomware creator Michael Gillespie was able determine that it was decryptable and released a decryptor.
Unfortunately, a few days later, the ransomware developers released a new version called HC7 that was not decryptable. Thi sis because they removed the hard coded encryption key and instead switched to inputting the key as a command line argument when the attackers run the ransomware executable. Thankfully, there may be a way to get around that as well so that victims can recover their keys.
Updated: 2026-08-11
View profile →APT GROUPfinancial
"aGl0bGVyCg" (Base64 for "hitler") is a reference to the Hitler-Ransomware (2016), a German-origin proof-of-concept that displayed a Hitler image, did not actually encrypt files, and demanded a 25-euro Vodafone card payment; assessed as an amateur test project rather than a serious criminal operation.
RLUpdated: 2026-08-11
View profile →APT GROUP
On October 24, 2017, Cisco Talos was alerted to a widescale ransomware campaign affecting organizations across eastern Europe and Russia. As was the case in previous situations, we quickly mobilized to assess the situation and ensure that customers remain protected from this and other threats as they emerge across the threat landscape. There have been several large scale ransomware campaigns over the last several months. This appears to have some similarities to Nyetya in that it is also based on Petya ransomware. Major portions of the code appear to have been rewritten. The distribution does not appear to have the sophistication of the supply chain attacks we have seen recently.
Updated: 2026-08-11
View profile →APT GROUPfinancial
ank — tracked by MISP Galaxy (ransomware).
Infra: 🔗 ankexpn6vk3qc5ooyyj7…
RSLUpdated: 2026-08-11
View profile →APT GROUP
Zero Tolerance Gang — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →APT GROUPfinancial
w3crypto — tracked by MISP Galaxy (ransomware).
Infra: 💬 fdevb3qh24ak7wujqsf7…
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
scattered lapsus$ hunters — tracked by MISP Galaxy (ransomware).
Infra: 🔗 shinypogk4jjniry5qi7…🔗 breachforums.hn…
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
punisher — tracked by MISP Galaxy (ransomware).
Infra: 💬 jh3zjsqgqk5woyuls7dx…
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 qd7pcafncosqfqu3ha6f…
RSLUpdated: N/A
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. Written in Delphi
Updated: 2026-08-11
View profile →APT GROUPfinancial
lcryptorx — tracked by MISP Galaxy (ransomware).
Infra: 🔗 lcryxdecryptor4f6xzy…🔗 lcryptordecrypt7xfzq…
RSLUpdated: 2026-08-11
View profile →