Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,749 entities
Siri discovered a new ransomware that is appending the .mvp extension to encrypted files.
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
World Leaks emerged in January 2025 as a rebrand of the Hunters International ransomware operation, shifting its focus from file encryption to solely stealing sensitive data and threatening to leak it unless a ransom is paid
Infra: 🔗 worldleaksartrjm3c6v
RLUpdated: 2026-08-11
View profile →
APT GROUPfinancial
Unlike many other groups, Silent claims to operate with a high level of anonymity and discretion. According to their own statement, they avoid public negotiations and encrypt minimal data. Instead, their focus is on stealing valuable confidential corporate information — and either selling it to competitors, on the dark web, or publishing it selectively.
Infra: 🔗 silentbgdghp3zeldwpu📁 jf2zjpxfh3sob5xr6uc5
RLUpdated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Mydecryptor — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →
ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
Ranstreet is a low-profile ransomware group with very limited public documentation, appearing in ransomware tracking lists but without major vendor research reports or significant attributed attacks.
RLUpdated: N/A
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. RaaS, baed on HiddenTear
Updated: 2026-08-11
View profile →
APT GROUPfinancial
xleaks — tracked by MISP Galaxy (ransomware).
Infra: 💬 fqb6joilbbd26d574bfa
RSLUpdated: 2026-08-11
View profile →
APT GROUPfinancial
spirigatito — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
Ben Hunter discovered a new ransomware called Termite Ransomware. When encrypting a computer it will append the .aaaaaa extension to encrypted files.
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Affiliates: BigBro
Infra: 🔗 yqhecvqtdvq6p7duqcgw
RSLUpdated: N/A
View profile →
The ransomware appears to target users in Korea, and may have been developed with at least knowledge of the Korean language.
Updated: 2026-08-11
View profile →
APT GROUPfinancial
Hellcome Bjorkanism
Infra: 🔗 netleaks.net📁 wki2kiikvycnowcygyz7📁 3lce6cov7sj7vovrr3cb+3 more
RSLUpdated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware no extension change, Javascript Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware CryptoGraphic Locker family. Has a GUI. Do not confuse with CrypVault!
Updated: 2026-08-11
View profile →
APT GROUPfinancial
abyss-data — tracked by MISP Galaxy (ransomware).
Infra: 🔗 3ev4metjirohtdpshsql📁 ufvi7hpcawesdklmomme📁 t7ogwvu74a6flssns55y+44 more
RSLUpdated: 2026-08-11
View profile →
aka black shrantac
Updated: 2026-08-11
View profile →
APT GROUPfinancial
ArcRypt (also known as ARCrypter or ChileLocker) was first identified in August 2022, originally targeting government entities in Latin America and subsequently expanding globally. The group employs a single-extortion model—there is no evidence of a data-leak threat or RaaS ecosystem. The malware encrypts files using extensions such as .crypt, .crYpt, and .crYptA3, and uniquely drops the ransom note before commencing encryption. It has variants for both Windows and Linux, including a Go-based Linux version. Communication with victims occurs via Tor-based portals, evolving over time from a single shared site to individualized mirror sites for each victim. In some cases, threat actors have instructed victims to contact them using Tox, creating a Tox profile for communication. Targets have included Chile’s government infrastructure, Colombia’s Invima agency, and organizations in China and Canada.
RSLUpdated: 2026-08-11
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →
Ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
run some wares — tracked by MISP Galaxy (ransomware).
Infra: 🔗 rnsmwareartse3m4hjsu📁 nidzkoszg57upoq7wcal🔗 oow7rehrxlzpy6vh3hez+3 more
RSLUpdated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Ransomware
Updated: 2026-08-11
View profile →
APT GROUPfinancial
2023Lock is a ransomware strain first observed in January 2024, believed to be an evolution of the Venus and Zeoticus families and a direct precursor to the later TrinityLock variant. It employs a hybrid encryption method combining XChaCha20 and curve25519xsalsa20poly1305, appending the “.2023lock” extension to encrypted files. Upon infection, it delivers ransom notes in HTML, TXT, and HTA formats containing decryption instructions. Unlike many modern ransomware groups, there is no evidence that 2023Lock engages in double extortion or data exfiltration, operating purely through file encryption to pressure victims into payment. Its codebase and operational patterns strongly align with TrinityLock, which emerged a few months later with more sophisticated extortion tactics.
RSLUpdated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
APT GROUP
Spook — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-11
View profile →
APT GROUPfinancial
mimic — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-11
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-11
View profile →
APT GROUP
ransomware
Updated: 2026-08-11
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. In devVenisRansom@protonmail.com
Updated: 2026-08-11
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. The Ransom is 249$ and the hacker demands that the victim gets in contact through e-mail and a Polish messenger called Gadu-Gadu.
Updated: 2026-08-11
View profile →
ransomware
Updated: 2026-08-11
View profile →
← PreviousPage 254 / 269Next →