Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,750 entities
Ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
Ransomware delivered using fake Windows Update spam
Updated: 2026-08-12
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is NOT spread using email spam, fake updates, attachments and so on. It simply places a decrypt file on your computer.
Updated: 2026-08-12
View profile →
APT GROUPfinancial
lyrix — tracked by MISP Galaxy (ransomware).
Infra: 💬 4hfwnas3oexnkdimschy
RSLUpdated: 2026-08-12
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
nasir security — tracked by MISP Galaxy (ransomware).
Infra: 🔗 yzcpwxuhbkyjnyn4qsf4🔗 nasir.cc
RSLUpdated: 2026-08-12
View profile →
APT GROUPfinancial
toxic — tracked by MISP Galaxy (ransomware).
Infra: 💬 cwybfdfhstmmoaxmnz4o
RSLUpdated: 2026-08-12
View profile →
APT GROUP
Security researchers uncovered a new ransomware named ShurL0ckr (detected by Trend Micro as RANSOM_GOSHIFR.B) that reportedly bypasses detection mechanisms of cloud platforms. Like Cerber and Satan, ShurL0ckr’s operators further monetize the ransomware by peddling it as a turnkey service to fellow cybercriminals, allowing them to earn additional income through a commission from each victim who pays the ransom.
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
INC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 200 victims in 2025 alone with no sector off-limits.
RLUpdated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
naga — tracked by MISP Galaxy (ransomware).
Infra: 💬 nagapay2ypwzsj7gb2hl
RSLUpdated: 2026-08-12
View profile →
APT GROUPfinancial
LockData Auction is a dark web marketplace that emerged around May 2021 operating an invite-only stolen data auction portal, representing a shift toward pure data-theft extortion with auctions for stolen corporate data starting from $50,000, rather than a traditional ransomware encryptor operation.
Infra: 🔗 wm6mbuzipviusuc42kcg
RLUpdated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware Comes with Bedep
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Sabbath — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Security researchers have discovered a new ransomware strain named qkG that targets only Office documents for encryption and infects the Word default document template to propagate to new Word documents opened through the same Office suite on the same computer.
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
Crynox (sometimes referred to as “Crynox Ransomware”) appears to be a generic file-locker threat that appends .crynox to encrypted files and drops a ransom note (read_it.txt) instructing victims to contact crynoxWARE@proton.me. It seems to use RSA-4096 and AES for encryption and may change desktop wallpaper, but there's no evidence of double-extortion or leak site operation. Distribution methods cited include phishing, pirated software, and malicious websites.
RSLUpdated: 2026-08-12
View profile →
APT GROUPfinancial
HellCat is a ransomware-as-a-service group that formed in Q4 2024 and quickly became notable for high-profile attacks against Schneider Electric, Telefónica, and Israel's Knesset, primarily gaining initial access via stolen Jira credentials harvested by infostealer malware, targeting critical infrastructure and government entities.
Infra: 🔗 hellcakbszllztlyqbjz📁 r7i4vprxr2vznmhnnxj3🔗 hellcat.rw+2 more
RLUpdated: 2026-08-12
View profile →
Ransomware Has a GUI. Subvariants: CoinVault BitCryptor
Updated: 2026-08-12
View profile →
APT GROUPfinancial
ZeroLockerSec is a small ransomware group with very limited public documentation that became inactive by Q2 2025 with no recorded leak posts, suggesting a brief operational period before going dormant.
Infra: 🔗 ghfuviaplse6nbeowu7g
RLUpdated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
EP918 is a low-activity ransomware group listed in tracking databases with no confirmed victims and no publicly documented attacks or operational details.
Infra: 🔗 dg5fyig37abmivryrxlo
RLUpdated: N/A
View profile →
APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc…
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
claims it detected "Children Pornsites" in your browser history
Updated: 2026-08-12
View profile →
APT GROUP
embrago — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Ransom is 0.1 Bitcoins. Original name is TrojanRansom.
Updated: 2026-08-12
View profile →
← PreviousPage 263 / 269Next →