Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,748 entities
APT GROUP
Ransomware Coded by "The_Rainmaker"
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
[Play](https://attack.mitre.org/groups/G1040) is a ransomware group that has been active since at least 2022 deploying [Playcrypt](https://attack.mitre.org/software/S1162) ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. [Play](https://attack.mitre.org/groups/G1040) actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.(Citation: CISA Play Ransomware Advisory December 2023)(Citation: Trend Micro Ransomware Spotlight Play July 2023)
T1560.001T1059.001T1587.001
Updated: N/A
View profile →
APT GROUPfinancial
Radiant is a financially motivated ransomware group that emerged in September 2025, conducting double- and single-extortion attacks without affiliates, drawing widespread condemnation after attacking UK childcare provider Kido International and publishing photographs, names, and home addresses of over 8,000 children.
RLUpdated: N/A
View profile →
APT GROUP
Ransomware, written in .NET.
Updated: 2026-08-11
View profile →
Michael Gillespie noticed numerous submissions to ID Ransomware from South Korea for the StorageCrypter ransomware. This version is using a new ransom note named read_me_for_recover_your_files.txt.
Updated: 2026-08-11
View profile →
APT GROUPfinancial
New possible leak site posted to a forum on November 20th, 2022, no victims at present. Unclear if its for a ransomware or extortion group
Infra: 🔗 hkk62og3s2tce2gipcdx
RSLUpdated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →
Nodera is a ransomware family that uses the Node.js framework and was discovered by Quick Heal researchers. The infection chain starts with a VBS script embedded with multiple JavaScript files. Upon execution, a directory is created and both the main node.exe program and several required NodeJS files are downloaded into the directory. Additionally, a malicious JavaScript payload that performs the encryption process is saved in this directory. After checking that it has admin privileges and setting applicable variables, the malicious JavaScript file enumerates the drives to create a list of targets. Processes associated with common user file types are stopped and volume shadow copies are deleted. Finally, all user-specific files on the C: drive and all files on other drives are encrypted and are appended with a .encrypted extension. The ransom note containing instructions on paying the Bitcoin ransom are provided along with a batch script to be used for decryption after obtaining the private key. Some mistakes in the ransom note identified by the researchers include the fact that it mentions a 2048-bit RSA public key instead of 4096-bit (the size that was actually used), a hard-coded private key destruction time dating back almost 2 years ago, and a lack of instructions for how the private key will be obtained after the ransom is paid. These are signs that the ransomware may be in the development phase and was likely written by an amateur. For more information, see the QuickHeal blog post in the Reference section below.
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
ZeroTolerance is a low-profile ransomware group tracked on monitoring platforms with no detailed threat actor profiles, technical analysis, or named victim reports published by major threat intelligence vendors.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Cryp70n1c0d3 is a low-profile ransomware group with limited public documentation; specific targets, attack methodology, and operational model remain poorly documented in open sources.
Infra: 🔗 7k4yyskpz3rxq5nyokf6
RSLUpdated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
Cloak is a ransomware-as-a-service operation active since late 2022, primarily targeting small-to-medium enterprises in Europe — especially Germany — across manufacturing, healthcare, education, and government sectors, with expansion into North American and Asian targets by 2025.
Infra: 🔗 cloak7jpvcb73rtx2ff7💬 6mw4yczxeqoiq7rgwnpi💬 7puvv4qtcrigzbxshqib+36 more
RSLUpdated: 2026-08-11
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 gammax6w3dkfdjfrjtht
RSLUpdated: N/A
View profile →
Unnamed ramsomware 2 — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
ransomware
Updated: 2026-08-11
View profile →
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. The hacker tries to get the user to play a game and when the user clicks the button, there is no game, just 20 pictures in a .gif below: https://3.bp.blogspot.com/-1zgO3-bBazs/WAkPYqXuayI/AAAAAAAABxI/DO3vycRW-TozneSfRTdeKyXGNEtJSMehgCLcB/s1600/all-images.gif
Updated: 2026-08-11
View profile →
APT GROUPfinancial
telegram — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →
APT GROUPfinancial
white lock — tracked by MISP Galaxy (ransomware).
Infra: 💬 l3e4ct2egnlfz4ymexwn
RSLUpdated: 2026-08-11
View profile →
APT GROUPfinancial
Launched on April 24th, 2025 RansomBay is a new project operating under the DragonForce initiative
Infra: 🔗 rrrbay3nf4c2wxmhprc6💬 rrrbayguhgtgxrdg5myx📁 rrrbaygxp3f2qtgvfqk6
RSLUpdated: 2026-08-11
View profile →
Ransomware
Updated: 2026-08-11
View profile →
← PreviousPage 245 / 269Next →