Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,752 entities
APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →APT GROUPfinancial
Red Ransomware (Red CryptoApp) emerged in early 2024, debuting its "Wall of Shame" data leak site with 11 victims across IT, legal, hospitality, manufacturing, and education sectors predominantly in the US, using phishing and vulnerability exploitation with double-extortion tactics.
RLUpdated: N/A
View profile →APT GROUPfinancial
lsd — tracked by MISP Galaxy (ransomware).
Infra: 🔗 t.me…
RSLUpdated: 2026-08-12
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 rktazuzi7hbln7sy.oni…
RSLUpdated: N/A
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Its fake name is Bitcoin and maker’s name is Santiago. Work of the encrypted requires the user to have .NET Framework 4.5.2. on his computer.
Updated: 2026-08-12
View profile →APT GROUPfinancial
Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organizations across manufacturing, healthcare, technology, and hospitality sectors using double-extortion tactics — encrypting files while exfiltrating data and threatening publication via a Tor-based leak site.
Infra: 💬 rwsu75mtgj5oiz3alkfp…🔗 benzona6x5ggng3hx52h…📁 cpjhb63lxycwbyus2n35…+1 more
RLUpdated: 2026-08-12
View profile →APT GROUPfinancial
Black Berserk is a relatively unsophisticated ransomware strain analyzed in late 2023. It operates under a single‑extortion model—encrypting files and demanding payment, with no documented abilities or threats for data exfiltration or public leaks. In observed cases, the malware appends the .Black extension to encrypted files (e.g., 1.jpg.Black) and leaves a ransom note titled Black_Recover.txt, which urges victims to make contact to negotiate payment or test decryption with benign files. The infection method appears opportunistic, delivered via isolated incidents or broad malware distribution—not linked to targeted campaigns or infrastructure. There is no evidence of it functioning as a RaaS operation or targeting any specific victim profiles or sectors.
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
blackhunt — tracked by MISP Galaxy (ransomware).
Infra: 🔗 sdjf982lkjsdvcjlksaf…
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
Obscura is a ransomware strain observed in 2025, written in Go and specifically targeting Windows domain controllers via the SYSVOL/NETLOGON share, using Curve25519 + XChaCha20 encryption with double-extortion tactics and a 10-day payment deadline.
Infra: 🔗 obscurad3aphckihv7wp…📁 obscurad3aphckihv7wp…
RLUpdated: 2026-08-12
View profile →APT GROUPfinancial
team underground — tracked by MISP Galaxy (ransomware).
Infra: 💬 undgrddapc4reaunnrdr…💬 ehehqyhw3iev2vfso4vq…🔗 47glxkuxyayqrvugfumg…+1 more
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
Official twitter account: https://x.com/ValenciaLeaks72
Infra: 🔗 6doyqxqqj36vnedtt2zw…
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
robbing hood — tracked by MISP Galaxy (ransomware).
Infra: 💬 fonektibq4fbgergrorw…
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
dark shinigami — tracked by MISP Galaxy (ransomware).
Infra: 🔗 darkshiz4d5ayumjvgbd…
RSLUpdated: 2026-08-12
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc.. Batch file; Passcode: AES1014DW256 or RSA1014DJW2048
Updated: 2026-08-12
View profile →APT GROUPfinancial
Kyber is a recently identified ransomware group using sophisticated hybrid encryption (AES-256-CTR with X25519 and Kyber1024), operating Tor-based communication channels and employing double-extortion with free partial decryption offered to build negotiation trust, discovered through underground forum monitoring in 2025.
Infra: 🔗 kyblogtz6k3jtxnjjvlu…💬 mlnmlnnrdhcaddwll4zq…📁 tp7e2ekeoqqozyq2t3oy…
RLUpdated: 2026-08-12
View profile →APT GROUPfinancial
quicklock — tracked by MISP Galaxy (ransomware).
Infra: 💬 dmkhn64rhzqtys7rns6z…
RSLUpdated: 2026-08-12
View profile →This ransomware is originated in English, therefore could be used worldwide. Ransomware is spread with the help of email spam, fake ads, fake updates, infected install files.
Updated: 2026-08-12
View profile →APT GROUP
Babuk‑Locker emerged in early 2021 as a Ransomware‑as‑a‑Service (RaaS) gang targeting high‑value “big game” enterprises across sectors like healthcare, telecommunications, finance, education, and government. It initially deployed crypto-ransomware—encrypting files using ChaCha8 encryption with keys secured via elliptic‑curve Diffie‑Hellman—and later added a double‑extortion model involving data theft and leak site threats. Notable incidents include attacks on the Washington, D.C. Metropolitan Police Department and other organizations. In mid‑2021, Babuk’s source code was leaked, prompting both a fragmentation of its core operations and emergence of variants like Babuk Tortilla and Babuk V2. Affiliates exploited vulnerabilities in ESXi hypervisors to deliver destructive variants, and law enforcement actions eventually disrupted key operators.
Updated: 2026-08-12
View profile →