Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,750 entities
APT GROUP
[PittyTiger](https://attack.mitre.org/groups/G0011) is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control.(Citation: Bizeul 2014)(Citation: Villeneuve 2014)
T1588.002T1078
Updated: N/A
View profile →
APT GROUPfinancial
CryptBB is a ransomware group with likely Russian origins active around 2023, whose payload appends random extensions to encrypted files and whose data leak site copied 8Base's source code, listing approximately 8 victims as of September 2023.
Infra: 🔗 crypuglupv3bsqnbt5ru🔗 basemmnnqwxevlymli5b
RLUpdated: 2026-08-12
View profile →
APT GROUP
Ransomware Based on EDA2
Updated: 2026-08-12
View profile →
APT GROUPfinancial
turkish crypter — tracked by MISP Galaxy (ransomware).
Infra: 💬 vbzxvet5nbga7jblaksu
RSLUpdated: 2026-08-12
View profile →
APT GROUP
Once installed, Ako will attempt to delete Volume Shadow Copies and disable recovery services. It will then begin to encrypt all files that do not match a hard-coded list using an unknown algorithm. Whilst this is happening, Ako will scan the affected network for any connected devices or drives for it to propagate to.
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
doommageddon — tracked by MISP Galaxy (ransomware).
Infra: 🔗 iacjvmxjb2ivqkxxzmde
RSLUpdated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware Apocalypse ransomware version which uses VMprotect
Updated: 2026-08-12
View profile →
APT GROUPfinancial
wiki ransomware — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Lapsus$ is a cyber extortion group first observed in late 2021, known for high-profile breaches and data theft campaigns against major global companies rather than traditional ransomware encryption. The group primarily focuses on data exfiltration and public leak threats without encrypting victim systems. Lapsus$ uses a combination of social engineering, SIM swapping, MFA fatigue attacks, and purchasing access from insiders or access brokers to infiltrate corporate networks. Their victim list includes Microsoft, Okta, NVIDIA, Samsung, Uber, and telecom operators, with operations targeting multiple regions worldwide. Once inside, Lapsus$ actors exfiltrate source code, proprietary data, and customer information, often leaking samples to pressure victims into negotiation. The group is known for a brash and public-facing style, communicating directly with followers on Telegram channels and occasionally mocking victims. Several members, including minors, have been arrested in the UK, but the group’s activities have persisted in some form.
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
ransomware
Updated: 2026-08-12
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc… The ransom is 1bitcoin.
Updated: 2026-08-12
View profile →
BansomQare Manna Ransomware — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Rincrypt — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
APT GROUP
Mostly Hidden Tear with some codes from Eda2 & seems compiled w/ Italian VS. Maybe related to OpsVenezuela?
Updated: 2026-08-12
View profile →
APT GROUP
Ranzy — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
APT GROUPfinancial
triple x — tracked by MISP Galaxy (ransomware).
Infra: 🔗 ojcmpbdncjo5dhaxxll4📁 6qqz6m3b6htudohg2mlf
RSLUpdated: 2026-08-12
View profile →
Ransomware Attempt to steal passwords
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
Forma Ransomware — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Ranion Raas gives the opportunity to regular people to buy and distribute ransomware for a very cheap price. (More info in the link below). RaaS service
Updated: 2026-08-12
View profile →
Lorenz is a ransomware group that has been active since at least February 2021 and like many ransomware groups, performs double-extortion by exfiltrating data before encrypting systems.
Updated: 2026-08-12
View profile →
APT GROUPfinancial
Dark Project is a newly emerged ransomware leak operation active as of August 2026. The group utilizes a double extortion model (stealing sensitive data before encrypting local systems and threatening to leak it on their dark web portal).
RLUpdated: N/A
View profile →
APT GROUPfinancial
DarkVault is a data-exfiltration and double-extortion group first identified in late 2023, targeting medium-to-large organizations in finance, professional services, legal, and technology sectors across Europe, the UK, and North America, with a suspected connection to LockBit.
Infra: 🔗 mdhby62yvvg6sd5jmx5g📁 kkvanuf7on5uglvdhihy
RLUpdated: 2026-08-12
View profile →
APT GROUP
[INC Ransom](https://attack.mitre.org/groups/G1032) is a ransomware and data extortion threat group associated with the deployment of [INC Ransomware](https://attack.mitre.org/software/S1139) that has been active since at least July 2023. [INC Ransom](https://attack.mitre.org/groups/G1032) has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.(Citation: Bleeping Computer INC Ransomware March 2024)(Citation: Cybereason INC Ransomware November 2023)(Citation: Secureworks GOLD IONIC April 2024)(Citation: SentinelOne INC Ransomware)
T1657T1069.002T1049
Updated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
AiLock is a ransomware operation that emerged in early 2025, marketing itself as AI-assisted ransomware using a hybrid ChaCha20/NTRUEncrypt encryption scheme and double-extortion tactics, actively recruiting affiliates and threatening regulatory reporting if ransoms are unpaid.
RLUpdated: N/A
View profile →
MalwareHunterTeam found a new ransomware called God Crypt that does not appear to decrypt and appears to be a joke ransomware. Has an unlock code of 29b579fb811f05c3c334a2bd2646a27a.
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
According to numerous open-source reports, a widespread ransomware campaign is affecting various organizations with reports of tens of thousands of infections in as many as 74 countries, including the United States, United Kingdom, Spain, Russia, Taiwan, France, and Japan. The software can run in as many as 27 different languages. The latest version of this ransomware variant, known as WannaCry, WCry, or Wanna Decryptor, was discovered the morning of May 12, 2017, by an independent security researcher and has spread rapidly over several hours, with initial reports beginning around 4:00 AM EDT, May 12, 2017. Open-source reporting indicates a requested ransom of .1781 bitcoins, roughly $300 U.S.
Updated: 2026-08-12
View profile →
APT GROUPfinancial
BlackNevas is a ransomware group first observed in November 2024, believed to be derived from the Trigona ransomware family, targeting telecommunications, manufacturing, medical, and legal industries primarily in Asia-Pacific, the UK, Italy, and Lithuania using double-extortion with a dual AES/RSA encryption scheme.
RLUpdated: N/A
View profile →
← PreviousPage 262 / 269Next →