Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,752 entities
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
[UNC788](https://attack.mitre.org/groups/G1029) is a group of hackers from Iran that has targeted people in the Middle East.(Citation: Meta Adversarial Threat Report 2022)
Updated: N/A
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
AiLock is a ransomware operation that emerged in early 2025, marketing itself as AI-assisted ransomware using a hybrid ChaCha20/NTRUEncrypt encryption scheme and double-extortion tactics, actively recruiting affiliates and threatening regulatory reporting if ransoms are unpaid.
Updated: N/A
View profile →
APT GROUPfinancial
NightSpire is a ransomware group that first emerged in March 2025 and rapidly claimed over 250 victims across retail, manufacturing, healthcare, finance, and education sectors in the US, France, India, Taiwan, and Japan, using aggressive double-extortion with ransom deadlines as short as two days.
Updated: N/A
View profile →
APT GROUPfinancial
Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land Binaries (LOLBins) to blend malicious activity with normal admin traffic, primarily targeting consumer goods, real estate, automotive, healthcare, and IT sectors.
Updated: N/A
View profile →
APT GROUPfinancial
inc ransom — tracked by MISP Galaxy (ransomware).
T1657T1069.002T1049
Updated: N/A
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
locus — tracked by MISP Galaxy (ransomware).
Infra: 🔗 ugn5khvt4kitlivv4ddf
RSLUpdated: 2026-08-12
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 helixr2sncrd3ndsz5oh🔗 helixr2sncrd3ndsz5oh📁 helix2kvkqjzrkh3ospy
RSLUpdated: N/A
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUPfinancial
Orion is a ransomware operation first observed in October 2025 that listed 13 alleged victims on a dark web leak site across financial services, manufacturing, and healthcare, though analysts determined its victim list was recycled from prior LockBit and BlackCat disclosures rather than fresh compromises.
Infra: 🔗 cjfntkj5qeizxowuy3sr
RLUpdated: 2026-08-12
View profile →
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUPfinancial
PwndLocker is a ransomware that was observed in late 2019 and is reported to have been used to target businesses and local governments/cities. According to one source, ransom amounts demanded as part of PwndLocker activity range from $175k USD to $650k USD depending on the size of the network. PwndLocker attempts to disable a variety of Windows services so that their data can be encrypted. Various processes will also be targeted, such as web browsers and software related to security, backups, and databases. Shadow copies are cleared by the ransomware, and encryption of files occurs once the system has been prepared in this way. Executable files and those that are likely to be important for the system to continue to function appear to be skipped by the ransomware, and a large number of folders mostly related to Microsoft Windows system files are also ignored. As of March 2020, encrypted files have been observed with the added extensions of .key and .pwnd. Ransom notes are dropped in folders where encrypted files are found and also on the user's desktop.
Infra: 🔗 msaoyrayohnp32tcgwca
RLUpdated: N/A
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
Simple Encoder
Technical ID: Simple_Encoder
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
First discovered by malware security analyst, Lawrence Abrams, PLANETARY is an updated variant of another high-risk ransomware called HC7.
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
ulose — tracked by MISP Galaxy (ransomware).
Infra: 🔗 egm34gsyx65wb6jyqds4
RSLUpdated: 2026-08-12
View profile →
APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. Poses as Hewlett-Packard 2016
Updated: 2026-08-12
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUPfinancial
IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial services organizations in the US, Croatia, and Indonesia by exploiting exposed perimeter services such as firewalls and VPNs, claiming at least five victims.
RLUpdated: N/A
View profile →
APT GROUPfinancial
gazprom — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-12
View profile →
APT GROUP
previous clearnet domain coomingproject.com
Updated: 2026-08-12
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 qvo5sd7p5yazwbrgioky
RSLUpdated: N/A
View profile →
APT GROUP
Ransomware
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Creator is staffttt and the ransom is 0.5 botcoins.
Updated: 2026-08-12
View profile →
APT GROUP
ransomware
Updated: 2026-08-12
View profile →
APT GROUP
DeLpHiMoRix — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-12
View profile →
It’s directed to English and Italian speaking users, therefore is able to infect worldwide. Most attacks are on organizations and servers. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. They pose as a Consumer complaint notification that’s coming from Federal Trade Commission from USA, with an attached file called “complaint.pdf”. Written in Delphi by hacker MicrRP.
Updated: 2026-08-12
View profile →
It’s directed to English speaking users, therefore is able to strike worldwide. This ransomware does not really encrypt your files. Ransom requested is £50 using credit card.
Updated: 2026-08-12
View profile →
Ransomware
Updated: 2026-08-12
View profile →
← PreviousPage 266 / 269Next →