Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,754 entities
APT GROUP
Babuk‑Locker emerged in early 2021 as a Ransomware‑as‑a‑Service (RaaS) gang targeting high‑value “big game” enterprises across sectors like healthcare, telecommunications, finance, education, and government. It initially deployed crypto-ransomware—encrypting files using ChaCha8 encryption with keys secured via elliptic‑curve Diffie‑Hellman—and later added a double‑extortion model involving data theft and leak site threats. Notable incidents include attacks on the Washington, D.C. Metropolitan Police Department and other organizations. In mid‑2021, Babuk’s source code was leaked, prompting both a fragmentation of its core operations and emergence of variants like Babuk Tortilla and Babuk V2. Affiliates exploited vulnerabilities in ESXi hypervisors to deliver destructive variants, and law enforcement actions eventually disrupted key operators.
Updated: 2026-08-12
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →APT GROUP
A new ransomware has been discovered by MalwareHunterTeam that is based off of the InfiniteTear ransomware family, of which BlackRuby and Zenis are members. When this ransomware infects a computer it will encrypt the files, scramble the filenames, and append the .WHITEROSE extension to them.
Updated: 2026-08-12
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 cloak.su…
RSLUpdated: N/A
View profile →APT GROUPfinancial
buddyransome — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 mrdxtxy6vqeqbmb4rvbv…
RSLUpdated: N/A
View profile →APT GROUP
It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc…
Updated: 2026-08-12
View profile →APT GROUPfinancial
rustylocker — tracked by MISP Galaxy (ransomware).
Infra: 🔗 rustydl5ak6p6ajqnja6…🔗 rustyb2uj3aceqsouwei…🔗 rustye6pskjsu5vo2wlx…+10 more
RSLUpdated: 2026-08-12
View profile →APT GROUP
The NMCRYPT Ransomware is a generic file encryption Trojan that was detected in the middle of April 2018. The NMCRYPT Ransomware is a file encoder Trojan that is designed to make data unreadable and convince users to pay a fee for unlocking content on the infected computers. The NMCRYPT Ransomware is nearly identical to hundreds of variants of the HiddenTear open-source ransomware and compromised users are unable to use the Shadow Volume snapshots made by Windows to recover. Unfortunately, the NMCRYPT Ransomware disables the native recovery features on Windows, and you need third-party applications to rebuild your data.
Updated: 2026-08-12
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 hitleransomware.cf…
RSLUpdated: N/A
View profile →