Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,752 entities
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUP
QuantumLocker — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
APT GROUP
TOX: AB33BC51AFAC64D98226826E70B483593C81CB22E6A3B504F7A75348C38C862F00042F5245AC
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
MadLiberator is a ransomware group that emerged in mid-2024, known for erratic behavior including randomized ransom demands and unpredictable encryption patterns, targeting government entities including the Italian Ministry of Culture and using a data leak site to post exfiltrated files.
RLUpdated: N/A
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
[Equation](https://attack.mitre.org/groups/G0020) is a sophisticated threat group that employs multiple remote access tools. The group is known to use zero-day exploits and has developed the capability to overwrite the firmware of hard disk drives. (Citation: Kaspersky Equation QA)
T1564.005T1120T1480.001
Updated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
CipherForce is a newly emerged ransomware group first detected in early 2026, operating a dark web leak site and targeting technology, business services, and logistics companies across the US, China, Vietnam, India, and UAE, with at least 6 claimed victims.
Infra: 🔗 o3ydbkayttkyg4iw2nc7🔗 22evxpggnkyrxpluewqs
RSLUpdated: 2026-08-12
View profile →
APT GROUPfinancial
luckbit — tracked by MISP Galaxy (ransomware).
Infra: 💬 luckbit53sdne5yd5vde
RSLUpdated: 2026-08-12
View profile →
APT GROUP
Ransomware Based on EDA2 and RemindMe
Updated: 2026-08-12
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware OS X ransomware (PoC)
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUPfinancial
NetRunner is a ransomware group active from at least 2025 targeting diverse sectors including healthcare, telecommunications, manufacturing, and agriculture across Japan, Italy, the US, and Jordan, notably demanding a $100M ransom from Nippon Medical School Musashi Kosugi Hospital.
Infra: 🔗 netrunrsb3bivj5gnwaj📁 netrunrs65cn2yidokrm
RSLUpdated: 2026-08-12
View profile →
APT GROUP
Supposed joke ransomware, decrypt when running an exectable with the string "Minecraft"
Updated: 2026-08-12
View profile →
APT GROUPfinancial
TiMc is a ransomware group that emerged in early 2026, claiming high-impact attacks against Spanish IT services leader Seidor (1 TB+ data) and oncology organization Oncologica (100 GB+), targeting Business Services, Healthcare, and IT sectors with a focus on Spanish-speaking and European targets.
RLUpdated: N/A
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware Packaged with Petya PDFBewerbungsmappe.exe
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
ransomware
Updated: 2026-08-12
View profile →
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. Based on Locky
Updated: 2026-08-12
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 decrypt5bub45vpr.oni
RSLUpdated: N/A
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Ransom is 0.2 bitcoins.
Updated: 2026-08-12
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc… FILES DON’T REALLY GET DELETED NOR DO THEY GET ENCRYPTED!!!!!!!
Updated: 2026-08-12
View profile →
Ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
RRansom is a low-profile ransomware group whose dark web leak site has been listed as offline in tracking directories, with very limited public threat intelligence available about its targets, tactics, or scale of operations.
Infra: 🔗 t2tqvp4pctcr7vxhgz5y
RSLUpdated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
← PreviousPage 265 / 269Next →