Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,749 entities
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 6dtxgqam4crv6rr6.oni💬 i3ezlvkoi7fwyood.oni
RSLUpdated: N/A
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. Demands 10 BTC
Updated: 2026-08-12
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 mrv44idagzu47oktcipn
RSLUpdated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. This ransomware uses VBS-script to send a voice message as the first few lines of the note.
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware Possible affiliation with Pony
Updated: 2026-08-12
View profile →
APT GROUPfinancial
silent ransom — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-12
View profile →
Ransomware Unlock code is: ajVr/G\ RJz0R
Updated: 2026-08-12
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
homeland — tracked by MISP Galaxy (ransomware).
Infra: 🔗 homelandjustice.ru
RSLUpdated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUP
When the CryptoNar, or Crypto Nar, Ransomware encrypts a victims files it will perform the encryption differently depending on the type of file being encrypted. If the targeted file has a .txt or .md extension, it will encrypt the entire file and append the .fully.cryptoNar extension to the encrypted file's name. All other files will only have the first 1,024 bytes encrypted and will have the .partially.cryptoNar extensions appended to the file's name.
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. Georgian ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Babyduck — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 sekhmetleaks.top🔗 rlmuybcg5h5gaatr.oni
RSLUpdated: N/A
View profile →
APT GROUP
Ransomware Has a GUI
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware CryptXXX clone/spinoff
Updated: 2026-08-12
View profile →
APT GROUPfinancial
Gunra is a financially motivated ransomware group that emerged in April 2025, using double-extortion tactics against real estate, pharmaceuticals, and manufacturing sectors across Japan, Egypt, Panama, Italy, and Argentina, deploying separate Windows and Linux variants with a strict five-day payment deadline.
Infra: 🔗 gunrabxbig445sjqa535💬 2bw7r32r5eshwk2h7uek💬 jzbhtsuwysslrzi2n5is+9 more
RSLUpdated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Operation [Sharpshooter](https://attack.mitre.org/groups/G0104) is the name of a cyber espionage campaign discovered in October 2018 targeting nuclear, defense, energy, and financial companies. Though overlaps between this adversary and [Lazarus Group](https://attack.mitre.org/groups/G0032) have been noted, definitive links have not been established.(Citation: McAfee Sharpshooter December 2018)
Updated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware Does not encrypt the files / Files are destroyed
Updated: 2026-08-12
View profile →
← PreviousPage 260 / 269Next →