Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,749 entities
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc… The hacker requests 2 bitcoins in return for the files.
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. Hidden Tear >> APT Ransomware + HYPERLINK "https://id-ransomware.blogspot.ru/2016/05/remindme-ransomware-2.html" "_blank" RemindMe > FuckSociety
Updated: 2026-08-12
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 moishddxqnpdxpababec
RSLUpdated: N/A
View profile →
APT GROUP
CyberSplitter variant
Updated: 2026-08-12
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
ra group — tracked by MISP Galaxy (ransomware).
Infra: 🔗 pa32ymaeu62yo5th5mra🔗 hkpomcx622gnqp2qhenv🔗 raworldw32b2qxevn3gp+1 more
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
superblack — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
A new ransomware has been discovered that utilizes the legitimate GnuPG, or GPG, encryption program to encrypt a victim's files. Currently in the wild, this ransomware is called Qwerty Ransomware and will encrypt a victims files, overwrite the originals, and the append the .qwerty extension to an encrypted file's name.
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
Brain Cipher emerged in July 2024. Both Windows and Linux variants are available. Brain Cipher using the leaked build of LockBit Black for their operations. The group suspected to have exploited CVE-2023-28252 (Microsoft Windows CLFS Driver Privilege Escalation Vulnerability). The Ransom demand ranges from $150,000 to $1,00,0000. Demand to be paid with Monero (XMR) cryptocurrency. In 2025, they have shifted their new Negotiation portal to new server with vanity TOR Domain starting with 'brain'.
RLUpdated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
Ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
Arkana is a ransomware group that emerged in early 2025 and gained attention by claiming an attack on U.S. broadband provider WideOpenWest (WOW!), operating a three-phase ransom/sale/leak extortion model primarily focused on telecom and internet service providers.
RLUpdated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
Ransomware
Updated: 2026-08-12
View profile →
abrahams ax
Technical ID: abrahams_ax
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 abrahamm32umasogaqoj
RSLUpdated: N/A
View profile →
APT GROUPfinancial
ironchain — tracked by MISP Galaxy (ransomware).
Infra: 💬 ironchaindecrypt7xfz
Updated: 2026-08-12
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUPfinancial
satancd — tracked by MISP Galaxy (ransomware).
Infra: 💬 mzg4llxp4kaf4qq5s4hl
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
ransomware
Updated: 2026-08-12
View profile →
Ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker avoids executable files, probably to avoid rendering the targeted system unusable for paying the ransom. It uses a combination of AES and RSA-2048, and reportedly appends extensions such as .encrypted, .bomber, .boroff, .breakingbad, .locker16, .newlock, .nlocker, and .skynet.
Infra: 🔗 kwvhrdibgmmpkhkidrby💬 kwvhrdibgmmpkhkidrby
RLUpdated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
soleenya — tracked by MISP Galaxy (ransomware).
Infra: 🔗 xzbltrroh4ocknyi7kj2
Updated: 2026-08-12
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 powerj7kmpzkdhjg4szv
RSLUpdated: N/A
View profile →
APT GROUP
Ransomware websites only
Updated: 2026-08-12
View profile →
← PreviousPage 259 / 269Next →