Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,747 entities
Lalabitch ransomware
Technical ID: Lalabitch_ransomware
APT GROUP
ransomware
Updated: 2026-08-11
View profile →APT GROUPfinancial
Malek Team is an Iranian-linked threat actor that emerged on October 8, 2023 (the day after the Hamas attack on Israel), believed to be tied to Iranian military intelligence, primarily targeting Israeli organizations using data exfiltration and extortion, with notable attacks on Ziv Medical Center and Ono Academic College.
RLUpdated: N/A
View profile →APT GROUPfinancial
Malas is a lesser-documented ransomware group that maintains an active dark web presence; detailed information about its targets, victims, or operational model is limited in public reporting.
Infra: 🔗 malas2urovbyyavjzaez…🔗 malas2urovbyyavjzaez…
RLUpdated: 2026-08-11
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. Python Ransomware
Updated: 2026-08-11
View profile →APT GROUPfinancial
X001xs is a low-profile ransomware group tracked on monitoring platforms with minimal public documentation, employing standard double-extortion tactics with no detailed technical analysis published by major vendors.
RLUpdated: N/A
View profile →APT GROUPfinancial
Groove emerged in mid-2021 as a loose criminal collective linked to former Babuk gang members, known for publicly leaking Fortinet VPN credentials to attract affiliates and calling for attacks on US government and financial targets; the group later claimed its entire operation was a hoax to mislead security researchers.
Infra: 🔗 ws3dh6av66sjbxxkjpw5…
RLUpdated: N/A
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Ransom is 500$ in bitcoins. Requires .NET Framework 4.0. Gets into your startup system and sends you notes like the one below: https://4.bp.blogspot.com/-xrr6aoB_giw/WG1UrGpmZJI/AAAAAAAAC-Q/KtKdQP6iLY4LHaHgudF5dKs6i1JHQOBmgCLcB/s1600/green1.jpg
Updated: 2026-08-11
View profile →APT GROUPfinancial
Blue Locker targets Pakistan’s vital energy sector, particularly Pakistan Petroleum
RLUpdated: N/A
View profile →APT GROUPfinancial
D1R Claims Synopsys and Bosch Breaches, but Synopsys Disputes Intrusion
RLUpdated: N/A
View profile →APT GROUP
Abraham's Ax announced their existence and mission through social media channels such as Twitter posts on November 8, 2022.
Abraham's Ax use a WordPress blog as the basis for their leak sites. Abraham's Ax site is available in Hebrew, Farsi, and English. The site also provides versions available via Tor websites, although it appeared to be under construction at the time of analysis. Used domain is registered with EgenSajt.se
Updated: 2026-08-11
View profile →APT GROUPfinancial
Dataleak is a low-profile ransomware group with approximately 6 known victims including entities in Brazil; very limited public threat intelligence exists on this group's tools, TTPs, or origins.
Infra: 🔗 woqjumaahi662ka26jzx…🔗 woqjumaahi662ka26jzx…
RLUpdated: N/A
View profile →APT GROUP
GrujaRS discovered the EQ Ransomware that drops a ransom note named README_BACK_FILES.htm and uses .f**k (censored) as its extension for encrypted files. May be GlobeImposter.
Updated: 2026-08-11
View profile →APT GROUPfinancial
Aware is a recently emerged ransomware group that operates a Tor-based data leak site with very limited public documentation and no publicly catalogued victims, tools, or TTPs in major threat intelligence databases.
Infra: 🔗 ui2uleaiisccbtcooyi3…
RLUpdated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Based on HiddenTear
Updated: 2026-08-11
View profile →APT GROUP
Michael Gillespie saw an encrypted file uploaded to ID Ransomware that appends the .cassetto extension and drops a ransom note named IMPORTANT ABOUT DECRYPT.txt.
Updated: 2026-08-11
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 mll5ddmdzgiq2siv3qno…
RSLUpdated: N/A
View profile →APT GROUPfinancial
elcometa — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
ESXiArgs is a ransomware campaign that emerged in February 2023, targeting VMware ESXi servers by exploiting the CVE-2021-21974 vulnerability. It encrypts virtual machine configuration files (.vmdk, .vmx, .vmxf, .vmsd, .vmsn, .vswp, .vmss, .nvram, .vmem) rendering VMs inaccessible. The campaign compromised thousands of unpatched servers globally, primarily affecting European organizations. A decryptor was later released by CISA and FBI.
RLUpdated: N/A
View profile →