Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,747 entities
APT GROUPfinancial
cylance — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. The name of the creator is puff69.
Updated: 2026-08-11
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 gandcrabmfe6mnef.oni…
RSLUpdated: N/A
View profile →APT GROUPfinancial
ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.
RLUpdated: N/A
View profile →APT GROUP
This is most likely to affect Russian speaking users, since the note is written in Russian. Therefore, residents of Russian speaking country are affected. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. The ransomware’s authors would request around $75 from their victims to provide them with a decryptor (payments are accepted via Russian payment services Qiwi or Yandex.Money ). Right from the start, however, researchers suggested that TeleCrypt was written by cybercriminals without advanced skills. Telecrypt will generate a random string to encrypt with that is between 10-20 length and only contain the letters vo,pr,bm,xu,zt,dq.
Updated: 2026-08-11
View profile →APT GROUP
Black Basta is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebrand of a previous top-tier ransomware gang that brought along their affiliates.
Updated: 2026-08-11
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 g6gwcbiylnvrzj6txsyp…
RSLUpdated: N/A
View profile →APT GROUPfinancial
cryptedpay — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
key group — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →APT GROUP
Leo discovered a screenlocker that calls itself Acroware Cryptolocker Ransomware. It does not encrypt.
Updated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Based on the idiotic open-source ransomware called CryptoWire
Updated: 2026-08-11
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →APT GROUP
Cheers is a Linux-based ransomware variant observed starting in May 2022, engineered specifically to target VMware ESXi servers. The malware was developed from leaked Babuk ransomware source code and leverages the SOSEMANUK stream cipher combined with ECDH key exchange for encryption. It terminates all running virtual machines before renaming and encrypting log files and VM-related extensions—like .vmdk, .vmsn, and .vswp—appending a .Cheers extension. A ransom note titled "How To Restore Your Files.txt" is dropped per directory. The ransomware is attributed to the Chinese-affiliated group BRONZE STARLIGHT (also known as Emperor Dragonfly, DEV-0401), which has previously deployed other strains like Rook, NightSky, and Pandora. Cheers targets a range of industry sectors, with confirmed victims across healthcare, finance, logistics, and manufacturing.
Updated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc… The ransom is 0.25 bitcoins and the nickname of the hacker is FRC 2016.
Updated: 2026-08-11
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →APT GROUPfinancial
The locker is written in C/C++/ASM.
<br/>It supports all systems starting from Windows 2003, has a separate binary for ESXi, and uses a unified encrypted file format across all systems.
<br/>WINDOWS:
<br/> • Two encryption modes: patch-based and file header.
<br/> • Extensive configuration settings: from ignoring specific paths/extensions to terminating services/processes, unlocking occupied files, working with network shares, and more.
<br/> • Arguments available for shutting down Hyper-V virtual machines, deleting backups, network scanning with logged-in user tokens.
<br/> • Each build includes an obfuscated PowerShell script.
<br/> • Execution is password-protected.
<br/> • The locker itself is shellcode for x86/x64; if you have custom execution methods, we can provide the shellcode.
<br/>ESXI:
<br/> • Encrypts files in patches, with configurable path exclusions.
<br/>The default configuration is pre-set to avoid disrupting Windows/ESXi/Linux systems.
<br/>
<br/>Our commission is 20% of payouts
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
Likely associated with the cybercrime group BlingLibra (ShinyHunters)
RLUpdated: N/A
View profile →