Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,747 entities
APT GROUP
Dataleak — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →
APT GROUP
Everest — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Predecessor of HC7
Updated: 2026-08-11
View profile →
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
gangbang — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →
First spotted in May 2016, however made a big comeback in January 2017. It’s directed to English speaking users, therefore is able to infect worldwide. Ransomware is spread with the help of email spam, fake ads, fake updates, infected install files.
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
BabyLockerKZ is a variant of MedusaLocker ransomware, first observed in late 2023. It operates under a double‑extortion model, combining file encryption with data exfiltration and extortion. Technically, it reuses MedusaLocker’s AES + RSA‑2048 hybrid encryption, appends the .hazard file extension to encrypted files, and includes a unique autorun registry key (“BabyLockerKZ”) alongside dedicated public/private key data inserted into registry values. Initial access is achieved through opportunistic methods like RDP compromises, with lateral movement facilitated by compromised credentials and tools such as Mimikatz. The variant employs a custom toolkit codenamed paid_memes, which includes tools like "Checker" for scanning credentials, facilitating automation, and bridging toolsets for further exploitation. Starting late 2022, its operators have compromised over 100 organizations per month, initially targeting European victims before shifting toward Latin America in 2023.
RSLUpdated: 2026-08-11
View profile →
APT GROUP
Ransomware Encrypts first 0x2000 and last 0x2000 bytes. Via remote attacker
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. This hacker demands that the victim contacts him through email and decrypts the files for FREE.(moreinfo in the link below)
Updated: 2026-08-11
View profile →
APT GROUPfinancial
tssxx25 — tracked by MISP Galaxy (ransomware).
Infra: 🔗 techscckl72ibnfg2ksj
RSLUpdated: 2026-08-11
View profile →
Michael Gillespie found a new ransomware that appends the .garrantydecrypt extension and drops a ransom note named #RECOVERY_FILES#.txt
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
This crypto ransomware encrypts enterprise LAN data with AES (ECB mode), and then requires a ransom in # BTC to return the files.
Updated: 2026-08-11
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 restoredz4xpmuqr.oni
RSLUpdated: N/A
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
DUMB variant discovered on November 16, 2017. Disguised itself as a popular virtual private network (VPN) in Iran known as Psiphon and infected Iranian users. Included Farsi-language ransom note, decryptable in the same way as previous DUMB-based variants. Message requested only US$15 for unlock key. Advertised two local and Iran-based payment processors: exchange.ir and webmoney.ir.Shared unique and specialized indicators with RASTAKHIZ; iDefense threat intelligence analysts believe this similarity confirms that the same actor was behind the repurposing of both types of ransomware.
Updated: 2026-08-11
View profile →
APT GROUPfinancial
settra — tracked by MISP Galaxy (ransomware).
Infra: 🔗 settra5ldqwgtw5q7z5a📁 26z3gms2rshr2zzedxhw📁 ttfy4zmtiaywfkkmykpx+2 more
RLUpdated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
M@r1a ransomware — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →
ransomware
Updated: 2026-08-11
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. The ransom amount is 349.99$ and the hacker seems to be from India. He disguises himself as Microsoft Support.
Updated: 2026-08-11
View profile →
APT GROUPfinancial
D0glun is a crypto-ransomware strain first observed in January 2025, believed to be derived from Babuk via an intermediary variant known as Cheng Xilun. It uses AES-256 symmetric encryption and appends filenames with patterns such as .@D0glun@<original extension> or similar. The malware encrypts files rapidly, changes the desktop wallpaper, and drops ransom notes typically named @[email protected], Desktopcxl.txt, or help.exe. The campaign has shown signs of shared infrastructure and code reuse from Cheng Xilun, but there is no confirmed evidence of a large-scale or mature operation. Its activity so far suggests it is being tested or deployed by a small group or individual rather than a structured affiliate network.
Infra: 🔗 33333333h45xwqlf3s3e
RSLUpdated: 2026-08-11
View profile →
APT GROUPfinancial
aka ShinyHunters
Infra: 🔗 fjg4zi4opkxkvdz7mvwp📁 vkhztfqsjbh2in6425uv📁 c7izex5h5shupbutwzsj+9 more
RSLUpdated: 2026-08-11
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
← PreviousPage 242 / 269Next →