Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,749 entities
APT GROUPfinancial
LostTrust is a double-extortion ransomware operation that emerged in March 2023 and publicized over 50 victims within days of launching its leak site in September 2023, believed to be a rebrand of the MetaEncryptor gang, primarily targeting manufacturing, professional services, construction, and education sectors with 71% of known victims in the US.
Infra: 🔗 hscr6cjzhgoybibuzn2x…
RLUpdated: 2026-08-11
View profile →APT GROUPfinancial
MyDecryptor is a low-profile ransomware group with minimal public documentation, appearing on ransomware tracking platforms but not the subject of major threat intelligence reporting, suggesting it is a small or relatively inactive operation.
Infra: 🔗 5s4ixqul2enwxrqv.oni…
RLUpdated: N/A
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Maker is arizonacode and ransom amount is 20-30$. If the victim decides to pay the ransom, he will have to copy HWID and then speak to the hacker on Skype and forward him the payment.
Updated: 2026-08-11
View profile →APT GROUPfinancial
Crypto24 is a double-extortion ransomware-as-a-service group that surfaced on the RAMP forum in mid-2024, targeting large organizations in financial services, healthcare, manufacturing, and technology across Asia, Europe, and North America, with notable victims including CMC Group, Vietnam's second-largest ICT conglomerate.
Infra: 🔗 j5o5y2feotmhvr7cbcp2…🔗 j5o5y2feotmhvr7cbcp2…
RLUpdated: 2026-08-11
View profile →APT GROUP
Groove was a short-lived ransomware group and cybercrime gang that emerged in August 2021 and became notable for its aggressive, publicity-driven tactics. Unlike traditional Ransomware-as-a-Service (RaaS) groups, Groove functioned more as a loose criminal collective, encouraging other threat actors to join forces in attacking U.S. entities, particularly in the government and financial sectors. The group ran a Tor-based leak site where it published stolen data, but its operators claimed to focus more on building an “underground alliance” than on ransomware deployment itself. Analysts noted overlaps between Groove and actors behind Babuk and BlackMatter, as well as forum personas known for data theft operations. By early 2022, Groove’s activity had largely ceased, with some experts suggesting the group was either a short-term recruitment campaign or a misinformation effort.
Updated: 2026-08-11
View profile →APT GROUPfinancial
CryLock (originally known as Cryakl/Fantomas since 2014) is a ransomware operation run by a Russian couple who targeted roughly 400,000 victims over eight years and earned over €64 million in Bitcoin; the operators were arrested in Spain in June 2023 and extradited to Belgium.
Infra: 🔗 d57uremugxjrafyg.oni…
RLUpdated: N/A
View profile →APT GROUPfinancial
timc — tracked by MISP Galaxy (ransomware).
Infra: 🔗 rzzfiwoop67jrxadngcy…
RSLUpdated: 2026-08-11
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 zhuobnfsddn2myfxxdqt…
RSLUpdated: N/A
View profile →APT GROUPfinancial
skira team — tracked by MISP Galaxy (ransomware).
Infra: 🔗 mtgc3qvyedjnfu7cen2z…
RSLUpdated: 2026-08-11
View profile →APT GROUP
Mr. Dec ransomware is cryptovirus that was first spotted in mid-May 2018, and since then was updated multiple times. The ransomware encrypts all personal data on the device with the help of AES encryption algorithm and appends .[ID]random 16 characters[ID] file extension, preventing from their further usage.
Updated: 2026-08-11
View profile →APT GROUP
[LazyScripter](https://attack.mitre.org/groups/G0140) is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.(Citation: MalwareBytes LazyScripter Feb 2021)
T1566.001T1102T1204.001
Updated: N/A
View profile →APT GROUPfinancial
Shadow is a low-profile ransomware group tracked on ransomware monitoring platforms with limited public documentation; specific attribution details regarding its targets, origin, or scale remain sparse in published threat intelligence reports.
Infra: 🔗 lc65fb3wrvox6xlyn4hk…
RLUpdated: 2026-08-11
View profile →APT GROUP
Ransomware no extension change Encrypted files have prefix: Version 1: ABCXYZ11 - Version 2: !DMALOCK - Version 3: !DMALOCK3.0 - Version 4: !DMALOCK4.0
Updated: 2026-08-11
View profile →APT GROUPfinancial
spy corporate — tracked by MISP Galaxy (ransomware).
Infra: 🔗 spycorp.pro…
RSLUpdated: 2026-08-11
View profile →APT GROUP
Ransomware Includes a feature to disable the victim's windows firewall Modified in-dev HiddenTear
Updated: 2026-08-11
View profile →APT GROUP
Ransomware Exploited Synology NAS firmware directly over WAN
Updated: 2026-08-11
View profile →