Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,749 entities
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
RunSomeWares is an emerging ransomware group that surfaced in February 2025 with initial victims across supply-chain services, financial services, accounting, and manufacturing, with unclear deployment of an encryptor vs. pure data-theft extortion.
RLUpdated: N/A
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
[Blue Mockingbird](https://attack.mitre.org/groups/G0108) is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.(Citation: RedCanary Mockingbird May 2020)
T1021.002T1027.013T1588.002
Updated: N/A
View profile →
Michael Gillespie discovered a new ransomware that renamed encrypted files to "[[email]][original].[random].lucky" and drops a ransom note named _How_To_Decrypt_My_File_.txt.
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware Does not encrypt Unlock code=suckmydicknigga
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →
APT GROUPfinancial
Insane is a relatively obscure ransomware family first reported in late 2021, with few confirmed incidents in public threat intelligence. It encrypts victim files using symmetric encryption (AES) combined with RSA for key protection and appends the .insane extension to affected files. The ransom note, typically named INSANE_README.txt, directs victims to contact the operators via email for decryption instructions. Based on limited reporting, Insane does not appear to operate as a Ransomware-as-a-Service (RaaS) platform; instead, it seems to be deployed by the core operators in targeted attacks. Initial access methods are not well-documented, but suspected vectors include phishing attachments and exploitation of exposed RDP services. The group’s small footprint in open-source intelligence suggests limited distribution or use in highly selective campaigns.
Infra: 🔗 nv5lbsrr4rxmewzmpe25🔗 gfksiwpsqudibondm6o2🔗 gfksiwpsqudibondm6o2+3 more
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
Ransomware
Updated: 2026-08-12
View profile →
ransomware
Updated: 2026-08-12
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc… Based on the idiotic open-source ransomware called CryptoWire
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware VaultCrypt family
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
Snake ransomware first attracted the attention of malware analysts in January 2020 when they observed the crypto-malware family targeting entire corporate networks. Shortly after this discovery, the threat quieted down. It produced few new detected infections in the wild for the next few months. That was until May 4, when ID Ransomware registered a sudden spike in submissions for the ransomware.
Updated: 2026-08-12
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →
APT GROUPfinancial
Apos is a data-broker extortion group that surfaced in April 2024, focusing on data exfiltration and threatening to publish or sell stolen information rather than encrypting files, targeting technology, healthcare, manufacturing, telecom, and government sectors across multiple countries.
Infra: 🔗 apos.blog🔗 yrz6bayqwhleymbevite🔗 yrz6bayqwhleymbevite
RLUpdated: 2026-08-12
View profile →
APT GROUP
Ransomware Windows, Linux. Campaign stopped. Actor claimed he deleted the master key.
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
blackfield — tracked by MISP Galaxy (ransomware).
Infra: 🔗 xcou7t6a4qlecsr7ipmx
Updated: 2026-08-12
View profile →
APT GROUP
Moisha — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. From the developer behind the Apocalypse Ransomware, Fabiansomware, and Esmeralda
Updated: 2026-08-12
View profile →
Gerber Ransomware 3.0 — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
A new ransomware was discovered this week by MalwareHunterTeam called Zenis Ransomware. While it is currently unknown how Zenis is being distributed, multiple victims have already become infected with this ransomware. What is most disturbing about Zenis is that it not encrypts your files, but also purposely deletes your backups.
Updated: 2026-08-12
View profile →
APT GROUPfinancial
XINOF (also known as Fonix/FonixCrypter) is a RaaS operation that began in June 2020 with no upfront affiliate cost and four methods of encryption per file; the operators shut down the service and released the master decryption key in January 2021, allowing free decryption for all victims.
Infra: 🔗 wj3b2wtj7u2bzup75tzh
RLUpdated: N/A
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUPfinancial
Haron appeared in July 2021 as a ransomware-as-a-service operation heavily borrowing from the defunct Avaddon ransomware (copying ransom notes and leak site structure) and built on the Thanos ransomware builder, targeting enterprise organizations with a six-day negotiation window.
Infra: 💬 ft4zr2jzlqoyob7yg4fc🔗 midasbkic5eyfox4dhni
RLUpdated: N/A
View profile →
APT GROUPfinancial
.crYpt <br/>MD5: 54EFAC23D7B524D56BEDBCE887E11849 <br/> <br/>Babuk Variant
Infra: 💬 lhwhi2kmewfas6tk47ps
Updated: 2026-08-12
View profile →
APT GROUPfinancial
DeathGrip is a Ransomware-as-a-Service (RaaS) that emerged around June 2024, offering malware payloads built with leaked LockBit 3.0 and Yashma/Chaos builders. Designed to lower technical barriers, it enables even low-skilled operators to deploy highly capable ransomware attacks. DeathGrip campaigns typically employ AES-256 encryption, delete shadow copies and recovery features, and modify system settings to hinder restoration. Earlier infections include low-tier ransom demands (e.g., around $100), reflecting entry-level targeting, though its flexible tooling allows a range of payload configurations.
Updated: 2026-08-12
View profile →
APT GROUPfinancial
BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies including insurance firm Shirbit and hosting provider Cyberserve, leaking medical records of 290,000 patients, using extortion as a tool of geopolitical disruption rather than purely for financial gain.
Infra: 🔗 544corkfh5hwhtn4.oni🔗 blackshadow.cc
RLUpdated: N/A
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware Based on HiddenTear
Updated: 2026-08-12
View profile →
XiaoBa ransomware — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
← PreviousPage 256 / 269Next →