Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,749 entities
APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Written on Delphi. The user requests the victim to get in touch with him through ICQ to get the ransom and return the files.
Updated: 2026-08-12
View profile →APT GROUPfinancial
NightSpire is a ransomware group that first emerged in March 2025 and rapidly claimed over 250 victims across retail, manufacturing, healthcare, finance, and education sectors in the US, France, India, Taiwan, and Japan, using aggressive double-extortion with ransom deadlines as short as two days.
Affiliates: Phantom • Reaper • Volt • Blaze +2
Infra: 🔗 nspireyzmvapgiwgtuoz…🔗 nspireyzmvapgiwgtuoz…🔗 a2lyiiaq4n74tlgz4fk3…+5 more
Updated: 2026-08-12
View profile →APT GROUPfinancial
sensayq — tracked by MISP Galaxy (ransomware).
Infra: 🔗 gmixcebhni6c3kcf5m7x…💬 ppzmaodrgtg7r6zcputd…
Updated: 2026-08-12
View profile →APT GROUPfinancial
money message — tracked by MISP Galaxy (ransomware).
Infra: 🔗 blogvl7tjyjvsfthobtt…💬 clientcuworpelkdwecu…📁 6xkylzxoxpd6bnl5ymhr…+26 more
Updated: 2026-08-12
View profile →APT GROUPfinancial
schoolboys — tracked by MISP Galaxy (ransomware).
Infra: 💬 pnanlicgxkku2aonwsg2…
Updated: 2026-08-12
View profile →APT GROUP
Anomali researchers have observed a new ransomware family, dubbed eCh0raix, targeting QNAP Network Attached Storage (NAS) devices. QNAP devices are created by the Taiwanese company QNAP Systems, Inc., and contain device storage and media player functionality, amongst others. The devices appear to be compromised by brute forcing weak credentials and exploiting known vulnerabilities in targeted attacks. The malicious payload encrypts the targeted file extensions on the NAS using AES encryption and appends .encrypt extension to the encrypted files. The ransom note created by the ransomware has the form shown below.
eCh0raix was first seen in June 2019, after victims began reporting ransomware attacks in a forum topic on BleepingComputer.
On June 1st, 2020, there has been a sudden surge of eCh0raix victims seeking help in our forums and submissions to the ransomware identification site ID-Ransomware.
Updated: 2026-08-12
View profile →APT GROUPfinancial
providence — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →APT GROUP
Ransomware no decryption possible, throws key away, destroys the files
Updated: 2026-08-12
View profile →APT GROUPfinancial
Weyhro is a data-extortion group (relying on data theft and leak threats without file encryption) that launched a Tor leak site in March 2025, focusing on manufacturing, financial services, and real estate sectors with victims in the US, Italy, and Canada.
Infra: 🔗 xtxtpqpyaaek4p4525ks…📁 p7teg7yh2dwxg2tsbgnk…📁 p7teg7yh2dwxg2tsbgnk…+2 more
Updated: 2026-08-12
View profile →APT GROUPfinancial
black x — tracked by MISP Galaxy (ransomware).
Infra: 🔗 blackxppq2jvqyg4slyg…
Updated: 2026-08-12
View profile →APT GROUPfinancial
Dunghill Leak is the data extortion site operated by the Dark Angels ransomware group, active since early 2023, targeting large enterprises across healthcare, finance, industrial, and technology sectors using a highly selective non-affiliate model, and responsible for a record-breaking $75 million ransom payment in 2024.
Infra: 🔗 p66slxmtum2ox4jpayco…🔗 nsalewdnfclsowcal6kn…🔗 5kvv27efetbcqgem4tl7…+4 more
Updated: 2026-08-12
View profile →APT GROUPfinancial
LunaLock emerged in September 2025 targeting creative and digital platforms, notably breaching an illustrator marketplace and a Mexican ISP, and is notable for threatening to submit stolen artwork to AI companies for training if the ransom is not paid.
Infra: 🔗 lunalockcccxzkpfovwz…💬 lunachataclss7bvlhk5…
Updated: 2026-08-12
View profile →APT GROUPfinancial
sharpboys — tracked by MISP Galaxy (ransomware).
Infra: 🔗 sharpboyz.io…
Updated: 2026-08-12
View profile →APT GROUP
Arvin Club is a popular Ransomware group with a widespread Telegram presence, which includes personal group chats, and official channels.
The group recently launched their official TOR/ Onion website to update their status and release details of their latest attacks and data breaches.
Their latest target is Kendriya Vidyala, a chain of Schools in India. The group has exposed the Personally Identifiable Information (PII) of some students.
Updated: 2026-08-12
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 scbrksw5fgjtujc2ah42…
RSLUpdated: N/A
View profile →