Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,749 entities
APT GROUP
Ransomware Stores your files in a password protected RAR file
Updated: 2026-08-12
View profile →APT GROUPfinancial
bober — tracked by MISP Galaxy (ransomware).
Infra: 💬 myosbja7hixkkjqihsjh…
RSLUpdated: 2026-08-12
View profile →APT GROUP
Attackers are targeting Internet accessible HPE iLO 4 remote management interfaces, supposedly encrypting the hard drives, and then demanding Bitcoins to get access to the data again.
According to the victim, the attackers are demanding 2 bitcoins to gain access to the drives again. The attackers will also provide a bitcoin address to the victim that should be used for payment. These bitcoin addresses appear to be unique per victim as the victim's was different from other reported ones.
An interesting part of the ransom note is that the attackers state that the ransom price is not negotiable unless the victim's are from Russia. This is common for Russian based attackers, who in many cases tries to avoid infecting Russian victims.
Finally, could this be a decoy/wiper rather than an actual true ransomware attack? Ransomware attacks typically provide a unique ID to the victim in order to distinguish one victim from another. This prevents a victim from "stealing" another victim's payment and using it to unlock their computer.
In a situation like this, where no unique ID is given to identify the encrypted computer and the email is publicly accessible, it could be a case where the main goal is to wipe a server or act as a decoy for another attack.
Updated: 2026-08-12
View profile →APT GROUPfinancial
DarkLeakMarket is a dark web data leak marketplace active since at least 2019 that sells stolen data sourced from ransomware groups and hacking forums, with 39 known victim organizations; it operates more as a data resale market than a traditional ransomware operator.
RLUpdated: N/A
View profile →It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Based on RemindMe
Updated: 2026-08-12
View profile →APT GROUPfinancial
Anubis is a ransomware-as-a-service group active since December 2024 that targets healthcare, engineering, construction, and professional services sectors, offering affiliates a flexible revenue split model and an optional destructive "wipe mode" alongside standard encryption.
Infra: 🔗 om6q4a6cyipxvt7ioudx…🔗 anubisyfkh5rixydjpoo…
RSLUpdated: 2026-08-12
View profile →APT GROUP
MalwareHunterTeam discovered a new Paradise Ransomware variant that uses the extension _V.0.0.0.1{paradise@all-ransomware.info}.prt and drops a ransom note named PARADISE_README_paradise@all-ransomware.info.txt.
Updated: 2026-08-12
View profile →APT GROUPfinancial
DataCarry is a ransomware and data-extortion operation first observed in May 2025, operating a double-extortion model with a Tor-hosted leak portal and claiming victims across insurance, healthcare, aerospace, legal, and retail sectors in at least six countries.
Infra: 🔗 dcarryhaih5oldidg3tb…
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 hpo7htcpddfanilkntts…💬 36h3fldzkrx7jjjbdelw…
RSLUpdated: N/A
View profile →APT GROUP
Ransomware Has a GUI. CryptoGraphic Locker family. Newer CoinVault variant.
Updated: 2026-08-12
View profile →APT GROUPfinancial
krypt — tracked by MISP Galaxy (ransomware).
Infra: 💬 decryptjhpol6zezc72x…💬 decryptrrx2fojgfcof3…
RSLUpdated: 2026-08-12
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. Uses the name “Chrome Update” to confuse its victims. Then imitates the chrome update process ,while encrypting the files. DO NOT pay the ransom, since YOUR COMPUTER WILL NOT BE RESTORED FROM THIS MALWARE!!!!
Updated: 2026-08-12
View profile →APT GROUPfinancial
invaderx — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
Darky Lock is a commodity-style ransomware strain first identified in July 2022, derived from publicly available Babuk source code. Victim systems undergo file encryption with an added “.darky” extension, and a “Restore-My-Files.txt” ransom note is placed in all impacted locations. The malware attempts to disable backup mechanisms, including shadow copies and specific applications. Its distribution leverages phishing and trojanized installers, complemented by payloads dropped via frameworks like Empire, Metasploit, and Cobalt Strike.
RSLUpdated: 2026-08-12
View profile →APT GROUP
Attackers are actively exploiting a recently disclosed vulnerability in Oracle WebLogic to install a new variant of ransomware called "Sodinokibi." Sodinokibi attempts to encrypt data in a user's directory and delete shadow copy backups to make data recovery more difficult. Oracle first patched the issue on April 26, outside of their normal patch cycle, and assigned it CVE-2019-2725. This vulnerability is easy for attackers to exploit, as anyone with HTTP access to the WebLogic server could carry out an attack. Because of this, the bug has a CVSS score of 9.8/10. Attackers have been making use of this exploit in the wild since at least April 17. Cisco's Incident Response (IR) team, along with Cisco Talos, are actively investigating these attacks and Sodinokibi.
Updated: 2026-08-12
View profile →APT GROUP
[PittyTiger](https://attack.mitre.org/groups/G0011) is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control.(Citation: Bizeul 2014)(Citation: Villeneuve 2014)
T1588.002T1078
Updated: N/A
View profile →