Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,749 entities
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
himalayaa — tracked by MISP Galaxy (ransomware).
Infra: 🔗 ohu6eschnuhxfg46wvco
RSLUpdated: 2026-08-11
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Here is the original ransomware under this name: http://id-ransomware.blogspot.co.il/2016/09/donald-trump-ransomware.html
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
Jakub Kroustek found what appears to be an in-dev version of the CreamPie Ransomware. It does not currently display a ransom note, but does encrypt files and appends the .[backdata@cock.li].CreamPie extension to them.
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware Russian Koolova Variant
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
The [Windigo](https://attack.mitre.org/groups/G0124) group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the [Ebury](https://attack.mitre.org/software/S0377) SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, [Windigo](https://attack.mitre.org/groups/G0124) operators continued updating [Ebury](https://attack.mitre.org/software/S0377) through 2019.(Citation: ESET Windigo Mar 2014)(Citation: CERN Windigo June 2019)
T1059T1189T1082
Updated: N/A
View profile →
APT GROUP
Avos — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
farattack — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →
APT GROUPfinancial
elonmusknow — tracked by MISP Galaxy (ransomware).
Infra: 🔗 leaksbcwijsbkxcx76s2
RSLUpdated: 2026-08-11
View profile →
APT GROUP
Jakub Kroustek discovered the RedEye Ransomware, which appends the .RedEye extension and wipes the contents of the files. RedEye can also rewrite the MBR with a screen that gives authors contact info and YouTube channel. Bart also wrote an article on this ransomware detailing how it works and what it does on a system.The ransomware author contacted BleepingComputer and told us that this ransomware was never intended for distribution and was created just for fun.
Updated: 2026-08-11
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUPfinancial
Abyss (also known as Abyss Locker) is a ransomware operation first identified in March 2023, derived from the Babuk source code, that targets Windows and Linux/VMware ESXi systems using double-extortion tactics across healthcare, manufacturing, finance, and technology sectors — predominantly in North America.
RLUpdated: N/A
View profile →
APT GROUPfinancial
phantom — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
BlackNevas ransomware — also referred to as “Trial Recovery” — was first observed in November 2024. It is a direct derivative of the Trigona ransomware family and continues the lineage's focus on extortion over public shaming. BlackNevas operators support a double-extortion model, encrypting files using AES-256 with RSA-4112-protected keys, and appending the .-encrypted or .ENCRYPTED file extension to affected files. Hybrid payloads are available for Windows, Linux, NAS, and VMware ESXi platforms. <br/> <br/>While BlackNevas does not host its own data leak site, it reportedly collaborates with other ransomware groups for data publication — known partners include Kill Security, Hunters International, DragonForce, Blackout, Embargo Team, and Mad Liberator. The group has predominantly targeted large enterprises in sectors such as finance, telecommunications, manufacturing, healthcare, and legal. Initial access is commonly achieved via phishing or exploitation of vulnerabilities, with lateral movement facilitated through SMB enumeration and optional LAN-wide propagation.
Infra: 🔗 ctyfftrjgtwdjzlgqh4a
RSLUpdated: 2026-08-11
View profile →
APT GROUPfinancial
inc ransom — tracked by MISP Galaxy (ransomware).
Infra: 🔗 incblog7vmuq7rktic73🔗 incapt.blog🔗 incapt.su+7 more
RSLUpdated: 2026-08-11
View profile →
ransomware
Updated: 2026-08-11
View profile →
Typical ransom software, Aurora virus plays the role of blackmailing PC operators. It encrypts files and the encryption cipher it uses is pretty strong. After encryption, the virus attaches .aurora at the end of the file names that makes it impossible to open the data. Thereafter, it dispatches the ransom note totaling 6 copies, without any change to the main objective i.e., victims must write an electronic mail addressed to anonimus.mr@yahoo.com while stay connected until the criminals reply telling the ransom amount.
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
CiphBit is a ransomware-as-a-service group active since April 2023, targeting small-to-mid-sized businesses across the UK, Europe, and North America with 38 known victims, employing a data-broker model with selective free leaks to pressure victims alongside standard double extortion.
Infra: 🔗 ciphbitqyg26jor7eeo6💬 sonarmsng5vzwqezlvtu💬 ciphbitekvxj27jmtw5s
RSLUpdated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware Code to decrypt: 83KYG9NW-3K39V-2T3HJ-93F3Q-GT
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware Based on Hidden Tear
Updated: 2026-08-11
View profile →
← PreviousPage 250 / 269Next →