Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,749 entities
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →
ransomware
Updated: 2026-08-11
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc… CHIP > DALE
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
bavacai — tracked by MISP Galaxy (ransomware).
Infra: 🔗 t33zoj4qwv455fog7qnb
RSLUpdated: 2026-08-11
View profile →
APT GROUPfinancial
pyrx — tracked by MISP Galaxy (ransomware).
Infra: 🔗 c2mdhim6btaiyae3xqth🔗 c2mdhim6btaiyae3xqth🔗 c2mdhim6btaiyae3xqth+1 more
RSLUpdated: 2026-08-11
View profile →
APT GROUPfinancial
CMD is a new kind of company that specializes in corporate system security and in identifying vulnerabilities across all aspects of the software used by a company. CMD operates on a global scale recognizing the critical importance of timeliness and confidentiality.
RLUpdated: N/A
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Unsafe — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. After the files are decrypted, the shadow files are deleted using the following command: vssadmin.exe Delete Shadows /All /Quiet
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Fsteam — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
SHINRA ransomware is a variant of the Proton ransomware family, known for its malicious activities involving data encryption and demanding a ransom for data decryption. After encrypting files, the ransomware renames them with a sequence of random characters and appends the ".SHINRA3" extension to the filenames. It is worth noting that this ransomware uses AES and ECC encryption algorithms to lock files on the victim's computer. Following the encryption, it creates a ransom note named "SHINRA-Recovery.txt." There are not many details about its operation or methods of infecting its victims, but after encryption, the victim needs to send an email regarding recovery to the addresses provided, including their ID as generated by the ransomware: Qq.decrypt@gmail.com Qq.encrypt@gmail.com ethan@fastmsg.info The ransomware also changes the victim's wallpaper, displaying the need to send the data and contact the threat actor.
Updated: 2026-08-11
View profile →
APT GROUP
Icefire — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →
ransomware
Updated: 2026-08-11
View profile →
Ransomware. Infection: drive-by-download; Platform: Windows; Extorsion by Prepaid Voucher
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →
APT GROUPfinancial
BlackSuit is a type of malicious software classified as ransomware. Its operation involves multifaceted extortion, encrypting and exfiltrating victim data, and hosting public data leak sites for victims who fail to meet its demands. BlackSuit’s activities first began in early May 2023. Designed to prevent access to files by encrypting them, this ransomware appends the “.blacksuit” extension to the names of all affected files. Furthermore, it changes the desktop wallpaper and creates a ransom note file named “README.BlackSuit.txt.” This threat actor targets large corporations, small and medium-sized enterprises (SMEs), with no apparent specific discrimination regarding industry or type of victim.
Infra: 🔗 weg7sdx54bevnvulapqu🔗 c7jpc6h2ccrdwmhofuij📁 nz2ihtemh2zli2wc3bov+15 more
RSLUpdated: 2026-08-11
View profile →
APT GROUPfinancial
deadbydawn — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victims in Indonesia, Italy, Venezuela, and the US, with minimal public threat-intelligence coverage.
Infra: 🔗 bl4cktorpms2gybrcyt5
RSLUpdated: N/A
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
LV ransomware group main message: "Here are companies which didn't meet consumer data protection obligations. They rejected to fix their mistakes, they rejected to protect this data in the case when they could and had to ptotect it. These companies prefered to sell their private information, their employees' and customers' personal data". Security researchers claim that the LV group is utilizing the REvil ransomware group malware. The LV group claim to have compromised the corporate network of Groupe Reorev.
Infra: 🔗 rbvuetuneohce3ouxjlb🔗 4qbxi3i2oqmyzxsjg4fw💬 l55ysq5qjpin2vq23ul3
RSLUpdated: N/A
View profile →
Ransomware
Updated: 2026-08-11
View profile →
ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
0day — tracked by MISP Galaxy (ransomware).
Infra: 🔗 odaygplp3zhyx7zl45eg
RSLUpdated: 2026-08-11
View profile →
Bart ransomware is distributed by the same Russian Cyber Mafia behind Dridex 220 and Locky. Bart doesn't communicate with a command and control (C&C) server, so it can encrypt files without being connected to a computer. Bart is spread to end users via phishing emails containing .zip attachments with JavaScript Code and use social engineering to trick users into opening the 'photo' attachments. The zipped files are obfuscated to make it more hard to tell what actions they are performing. See screenshot above for an example of what they look like. If opened, these attachments download and install the intermediary loader RockLoader which downloads Bart onto the machine over HTTPS. Once executed, it will first check the language on the infected computer. If the malware detects Russian, Belorussian, or Ukrainian, the ransomware will terminate and will not proceed with the infection. If it's any other language, it will start scanning the computer for certain file extensions to encrypt. Because Bart does not require communication with C&C infrastructure prior to encrypting files, Bart could possibly encrypt machines sitting behind corporate firewalls that would otherwise block such traffic. Thus, organizations need to ensure that Bart is blocked at the email gateway using rules that block zipped executables.
Updated: 2026-08-11
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. The hacker demands 0.2 bitcoins. The ransomware poses as a Window update.
Updated: 2026-08-11
View profile →
Uses APK Editor Pro. Picks and activates DEX>Smali from APK Editor. Utilizes LockService application and edits the “const-string v4, value” to a desired unlock key. Changes contact information within the ransom note. Once the victim has downloaded the malicious app, the only way to recover its content is to pay the ransom and receive the unlock key.
Updated: 2026-08-11
View profile →
Ransomware email addresses overlap with .777 addresses
Updated: 2026-08-11
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. The word Kaandsona is Estonian, therefore the creator is probably from Estonia. Crashes before it encrypts
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
← PreviousPage 249 / 269Next →