Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,749 entities
APT GROUPfinancial
Dragon Ransomware, is promising rapid and customizable ransomware operations for Windows systems. Key features include a compact 50KB file size, ultra-fast encryption speed, and a builder tool that allows users to personalize ransomware configurations. The tool will be available to the public once the team reaches 1,000 subscribers on their channel, signaling a potential rise in availability to threat actors.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Nokoyawa is a double-extortion ransomware group that launched a RaaS program in 2022 (operated by threat actor "farnetwork"), primarily targeting businesses in South America across healthcare, financial services, government, and manufacturing, gaining significant attention in 2023 for exploiting a Windows CLFS zero-day (CVE-2023-28252).
Infra: 🔗 lirncvjfmdhv6samxvvl🔗 6yofnrq7evqrtz3tzi3d🔗 nokoleakb76znymx443v+25 more
RLUpdated: N/A
View profile →
This is most likely to affect German speaking users, since the note is written in German. Mostly affects users in German speaking countries. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
piratelock — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
APT GROUPfinancial
Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities in Canada, France, and Germany before expanding to telecommunications, mining, and manufacturing sectors, operating a double-extortion model with a data leak site.
Infra: 🔗 black3gnkizshuynieig📁 4qyjonpyksc52bc3fsgf📁 ao5oo2luy6avdfomyw7h+6 more
RLUpdated: N/A
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUPfinancial
dAn0n is a data-extortion actor that first appeared in April 2024. Operating primarily in a leak-focused extortion model, they publish stolen data on a Tor-hosted site rather than encrypting files. Their victims include organizations across sectors like business services, technology, healthcare, transportation, and legal—all largely based in the United States, with a few in Ireland and South Korea. Activity surged in May 2024, landing them in the top 10 most active ransomware actors that month. Despite limited branding efforts, their smaller operational footprint has allowed for swift, targeted breaches that prioritize rapid data exposure over elaborate cryptographic tactics.
Infra: 🔗 2c7nd54guzi6xhjyqrj5
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 weepangrbqjfsxd2noz4
RSLUpdated: N/A
View profile →
Ransomware Factorization
Updated: 2026-08-12
View profile →
APT GROUPfinancial
imn crew — tracked by MISP Galaxy (ransomware).
Infra: 🔗 imncrewwfkbjkhr2oyle🔗 ho7yirtlkkkytbzkn4bk
Updated: 2026-08-12
View profile →
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware StilerX credential stealing
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
killsec3 — tracked by MISP Galaxy (ransomware).
Infra: 🔗 ks5424y3wpr5zlug5c7i🔗 ks5424y3wpr5zlug5c7i📁 xo4o2o2ezgydykywn6zk
Updated: 2026-08-12
View profile →
APT GROUPfinancial
nblock — tracked by MISP Galaxy (ransomware).
Infra: 💬 nblockn6jjp3xxh2do4c
RLUpdated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
mydata — tracked by MISP Galaxy (ransomware).
Infra: 🔗 mydatae2d63il5oaxxan📁 xszpovfd3q52omk5larj📁 ot3vo3od2pajc7ymxdk6+2 more
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
QLocker was a financially motivated ransomware operation active in 2021 that exclusively targeted QNAP NAS devices exposed to the internet, exploiting a hard-coded credentials vulnerability to compress files into password-protected 7-Zip archives and demanding roughly $400 per victim, netting approximately $350,000 in a single month.
Infra: 💬 gvka2m4qt5fod2fltkjm
RLUpdated: N/A
View profile →
APT GROUP
cloak.su — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
APT GROUPfinancial
c3rb3r — tracked by MISP Galaxy (ransomware).
Infra: 💬 j3qxmk6g5sk3zw62i2yh💬 c3rb3rnow2alp26exjwl
Updated: 2026-08-12
View profile →
APT GROUPfinancial
RebornVC is a rebrand of RansomedVC re-emerging in July 2025 under new leadership, using data auctions, direct extortion, and double extortion techniques with ransom demands ranging from $10,000 to $1,000,000, with confirmed victims in the US and Brazil.
RLUpdated: N/A
View profile →
APT GROUPfinancial
This is not a ransomware group but a data broker
Infra: 🔗 e27z5kd2rjsern2gpguk🔗 cybertube.video🔗 e27z5kd2rjsern2gpguk+4 more
RLUpdated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".
Infra: 🔗 griefcameifmv4hfr3au💬 payorgz3j6hs2gj66nk6
RLUpdated: N/A
View profile →
APT GROUPfinancial
Qiulong is a ransomware group that emerged around April 2024 primarily targeting Brazilian organizations using double extortion and unique tactics such as publishing identity documents of victims' family members to pressure payment.
Infra: 🔗 62brsjf2w77ihz5paods
RLUpdated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
Ransomware Based on HiddenTear
Updated: 2026-08-12
View profile →
← PreviousPage 257 / 269Next →