Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,748 entities
APT GROUPfinancial
Risen, which is a fully optimized and high-speed program, is the result of our years of experience in the field of malware writing. Risen is written in C language and completely using winapi. We produced many products with different features and options, but we came to the conclusion that none of the options have the benefit and efficiency they should; So, instead of spending time on useless and inefficient options, we decided to spend all our time on the strength, speed and security of our cryptography, and that's how we created Risen. Software features in version 1:
<br/>
<br/>
<br/> -Encryption security, utilizing Chacha20 and RSA 2048 algorithms.
<br/> -High encryption speed and software optimization
<br/> -compatible with all versions of Windows on any hardware without any issues.
<br/> -Automatic option settings, its easy to using and default configuration set to the best mode.
<br/> -Utilization of Threadpool method and queue creation for encryption.
<br/> -A powerful file unlocker, unlock files without closing processes.
<br/> -Safe deletion of backups, shadow copies, and all windows logs.
<br/> -A blog, Leak website, and management panel on TOR for leaking data of non-paying companies.
<br/>
Infra: 🔗 s2wk77h653qn54csf4gp…🔗 o6pi3u67zyag73ligtsu…🔗 cqqzfmdd2fwshfyic6sr…
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
redact — tracked by MISP Galaxy (ransomware).
Infra: 🔗 neclc36yt4yaa5lv54kh…📁 ursba4dbibo27dtwtgy3…
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
Bluebox is a data extortion group that emerged in December 2024, employing double-extortion tactics against victims primarily in France, Sweden, and the French Caribbean, and threatening to notify data protection authorities to add regulatory pressure on victims.
Infra: 🔗 zu3wfrmrkl4ltqqnpt3o…
RLUpdated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. These hackers claim to be students from Syria. This ransomware poses as the popular torrent movie screener called PopCorn. These criminals give you the chance to retrieve your files “for free” by spreading this virus to others. Like shown in the note bellow: https://www.bleepstatic.com/images/news/ransomware/p/Popcorn-time/refer-a-friend.png
Updated: 2026-08-11
View profile →APT GROUPfinancial
Connected to GD Lockersec and Babuk-Bjorka.
<br/>
<br/>Group is aka SalanLock (from typo on victim pages).
Infra: 🔗 212.24.99.211.…🔗 5g2e.l.time4vps.clou…🔗 mgeegnexyhhn5dpqewih…+4 more
RSLUpdated: 2026-08-11
View profile →APT GROUP
A targeted email campaign has been spotted distributing the JasperLoader to victims. While the JasperLoader was originally used to then install Gootkit, Certego has observed it now being used to infect victims with a new ransomware dubbed FTCODE. Using an invoice-themed email appearing to target Italian users, the attackers attempt to convince users to allow macros in a Word document. The macro is used to run PowerShell to retrieve additional PowerShell code.
Updated: 2026-08-11
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 eraleignews.com…🔗 wn6vonooq6fggjdgyocp…🔗 basheqtvzqwz4vp6ks5l…+12 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
radiant group — tracked by MISP Galaxy (ransomware).
Infra: 🔗 trfqksm6peaeyz4q6egx…
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums.
Infra: 🔗 54bb47h5qu4k7l4d7v5i…🔗 54bb47h.blog…
RLUpdated: N/A
View profile →lockbit3 fs
Technical ID: lockbit3_fs
APT GROUPfinancial
LockBit 3.0 ("LockBit Black"), active since June 2022, is the third iteration of the LockBit RaaS platform incorporating code from BlackMatter ransomware, featuring modular encrypted payloads that evade analysis and targeting Windows and VMware ESXi environments across all sectors globally.
RLUpdated: N/A
View profile →APT GROUPfinancial
malphas — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
LockBit 2.0 is the second major iteration of the LockBit RaaS platform, launched in mid-2021, introducing automated domain-wide encryption via Active Directory Group Policy and claiming the fastest encryption speed among ransomware families, accounting for 46% of ransomware breach events in early 2022.
RLUpdated: N/A
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. CryptoLocker Copycat
Updated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. CryptoShield 1.0 is a ransomware from the CryptoMix family.
Updated: 2026-08-11
View profile →