Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,749 entities
APT GROUPfinancial
VFOKX is a low-profile ransomware group tracked on ransomware monitoring platforms with very limited public documentation and no detailed analysis or named victims published by major threat intelligence vendors.
Infra: 🔗 vfokxcdzjbpehgit223v…🔗 746pbrxl7acvrlhzshos…
RLUpdated: N/A
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Domain KZ is used, therefore it is assumed that the decrypter is from Kazakhstan. Coded in Javascript
Updated: 2026-08-11
View profile →APT GROUPfinancial
RA Group, also known as RA World, first surfaced in April 2023, utilizing a custom variant of the Babuk ransomware.
RLUpdated: N/A
View profile →APT GROUP
Ransomware written in C#. Fortunately, all current versions of the MafiaWare666 ransomware are decryptable. The Threat Lab from Avast has developed a free decryption tool for this malware.
Updated: 2026-08-11
View profile →APT GROUPfinancial
3am — tracked by MISP Galaxy (ransomware).
Infra: 🔗 threeamkelxicjsaf2cz…📁 ulkvlj5sirgrbnvb4hvb…💬 threeam7fj33rv5twe5l…
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
Cs‑137 is a newly observed ransomware strain that first appeared in January 2025. It employs the ChaCha20 cipher for encryption and appends obfuscated filenames with a random 10-character alphanumeric identifier while preserving the original file extension. In its current testing phase, it drops a ransom note with a randomized filename (e.g. ABCDEF-README.txt) and sets a randomly named image file as the desktop wallpaper. The note references a Tor-based extortion portal—though access is not yet active, indicating the operation’s early development stage. The strategy suggests single-extortion behavior, focused on disrupting access rather than data theft or leak threats.
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather than a broad affiliate program.
Infra: 🔗 direwolfcdkv5whaz2sp…📁 direwolfgpyqohwxwoet…💬 direwolf66s5zealav7a…
RLUpdated: 2026-08-11
View profile →APT GROUPfinancial
Orca is a ransomware group that emerged in September 2024, identified as a variant of the Zeppelin malware family, targeting organizations in manufacturing and logistics across Taiwan, Tunisia, Austria, and France, claiming to avoid hospitals, government institutions, and non-profits.
Infra: 🔗 orca66hwnpciepupe562…
RLUpdated: 2026-08-11
View profile →APT GROUP
ransomware written by self proclaimed script kiddies that should really be considered trollware
Updated: 2026-08-11
View profile →APT GROUPfinancial
AgainstTheWest (ATW) is a hacktivist group active since October 2021 that targets governments and corporations perceived as authoritarian, breaching organizations like Alibaba, Sberbank, and Gazprom using custom ransomware and wiper malware for ideological disruption rather than financial profit.
RLUpdated: N/A
View profile →APT GROUPfinancial
deadlock — tracked by MISP Galaxy (ransomware).
Infra: 🔗 deadlock.liveblog365…🔗 deadblogdbdu5wprek7w…
RSLUpdated: 2026-08-11
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 monteoamwxlutyovf7ox…🔗 monteoamwxlutyovf7ox…
RSLUpdated: N/A
View profile →APT GROUPfinancial
WALocker is an emerging ransomware group that came to attention in 2025, targeting organizations in Southeast Asia and government entities, with a notable attack breaching Myanmar's Union Civil Service Board and exposing data on approximately 200,000 government officials.
Infra: 🔗 weepangrbqjfsxd2noz4…📁 am7hswbi46e3ozxec3ms…
RLUpdated: 2026-08-11
View profile →APT GROUPfinancial
WereWolves is a Russian-speaking ransomware group that emerged in May 2023, using a modified LockBit 3 (Black) encryptor, operating an unusual public website that actively recruits new members and offers a bug-bounty program with rewards up to $1 million, with at least 26 victims across Russia, the US, and Europe.
Infra: 🔗 werewolves.pro…🔗 weerwolven.biz.…
RLUpdated: 2026-08-11
View profile →APT GROUPfinancial
waissbein — tracked by MISP Galaxy (ransomware).
Infra: 📁 samu747og2fgxujardbh…📁 syympi25sxgm55kyk5wk…
RSLUpdated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →All Your Documents Ransomware
Technical ID: All_Your_Documents Ransomware
APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →