Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,747 entities
APT GROUPfinancial
mario esxi — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
Pro-Palestinian Group
Infra: 🔗 toufanleaks.org…
RSLUpdated: 2026-08-11
View profile →APT GROUP
Supposed joke ransomware, decrypt when running an exectable with the string "csgo"
Updated: 2026-08-11
View profile →APT GROUPfinancial
LeakTheAnalyst is a data-theft extortion group that operates a dark web leak site with approximately 20 claimed victims, notable for a 2017 operation targeting a Mandiant security researcher; the group focuses on stealing and publishing sensitive corporate data rather than deploying file-encrypting ransomware.
RLUpdated: N/A
View profile →APT GROUPfinancial
In September The El Dorado ransomware group have been rebrand as BlackLock
RLUpdated: N/A
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc… This hacker request your IP address in return for the decryption.
Updated: 2026-08-11
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 h44jyyfomcbnnw5dha7z…
RSLUpdated: N/A
View profile →APT GROUPfinancial
This ransomware uses a combination of different crypto algorithms (ChaCha20, AES-128, Curve25519). The activity of this malware is dated to mid-June 2021. The extension of the encrypted files are set to the compromised company: .<target_company>
Infra: 🔗 wtyafjyhwqrgo4a45wdv…🔗 wtyafjyizleuw4yhepmd…💬 wtyafjyhwqrgo4a45wdv…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Cry0 is a ransomware-as-a-service operation that recruits affiliates via underground forums, using a Rust-written payload with blockchain-based (Internet Computer Protocol) negotiation infrastructure to resist law enforcement takedowns and offering affiliates a 90/10 revenue split.
Infra: 🔗 cryoblogedawivdcknyd…📁 pwn3dky35tub4ktj5bol…
RSLUpdated: 2026-08-11
View profile →APT GROUP
A ransomware family that targets users from certain countries or regions. It locks the computer and displays a location-specific webpage that covers the desktop and demands that the user pay a fine for the supposed possession of illicit material. The Reveton ransomware is one of the first screen-locking ransomware strains, and it appeared when Bitcoin was still in its infancy, and before it became the cryptocurrency of choice in all ransomware operations. Instead, Reveton operators asked victims to buy GreenDot MoneyPak vouchers, take the code on the voucher and enter it in the Reveton screen locker.
Updated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →APT GROUP
S!Ri found a new ransomware called Donut that appends the .donut extension and uses the email donutmmm@tutanota.com.
Updated: 2026-08-11
View profile →APT GROUPfinancial
D4rk4rmy is a ransomware and data extortion group active since at least 2025, targeting financial services, hospitality, technology, and logistics sectors, operating a RaaS model with notable claimed victims including the Monte Carlo casino resort.
Infra: 🔗 d4rkd2fybtclo44hss2d…
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
SatanLock is a short-lived ransomware group that first appeared in April 2025 and abruptly shut down in July 2025 after claiming attacks against roughly 67 organizations — though over 65% of listed victims were duplicates from other groups — leaking all stolen data publicly upon shutdown.
RLUpdated: N/A
View profile →