Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,755 entities
APT GROUPfinancial
MS13089 is a newly emerged ransomware group (first observed December 2025) that named itself after a 2013 Microsoft Security Bulletin, claiming a handful of victims including a law firm, operating primarily as a double-extortion actor.
RLUpdated: N/A
View profile →APT GROUPfinancial
0mega is a double-extortion ransomware group that emerged in May 2022, targeting businesses across multiple sectors worldwide by encrypting files and threatening to leak stolen data; it also pivoted to cloud-based extortion by compromising Microsoft 365 admin accounts.
Infra: 🔗 omegalock5zxwbhswbis…🔗 0mega.cc…🔗 0mega.ws…+1 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
Members:
<br/>Eco
<br/>Ego
<br/>emo
<br/>elo
<br/>user
<br/>Dante
<br/>Sevy
Infra: 🔗 tooda.sh…
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
Rancoz is a Windows-targeting ransomware strain first observed in November 2022 that appends the ".rec_rans" extension to encrypted files, considered a Vice Society copycat, deployed against a small number of organizations using double extortion and linked to the same developer as the "Buddy" ransomware.
Infra: 🔗 ze677xuzard4lx4iul2y…
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
CRPxO is actively recruiting affiliates, offering:
🔹 70% revenue share
🔹 XMR/BTC payouts
🔹 Claimed payouts within 24 hours
🔹 $333 one-time affiliate access
RLUpdated: N/A
View profile →APT GROUPfinancial
arachna leak — tracked by MISP Galaxy (ransomware).
Infra: 🔗 ptyctpveqfevlukjw4hp…
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
BackMyData is a variant of the Phobos ransomware family, first observed in early 2024. It follows a double‑extortion model: encrypting files and threatening data exposure. The ransomware primarily targets organizations via weak or misconfigured RDP access (e.g., remote desktop services), though phishing and initial-stage payloads like SmokeLoader have also been noted. Technical behavior includes AES‑256 file encryption, with keys secured via a public RSA‑2048 key embedded in the binary. Post-infection actions involve disabling firewalls, deleting volume shadow copies, inhibiting recovery functionality, and establishing persistence through registry Run keys and startup folder entries. Encrypted files receive the extension .BACKMYDATA, and victims are left with ransom notes (info.txt, info.hta, or .backmydata) that instruct them to contact attackers via email or Session Messenger. A significant incident involved a coordinated attack on Romania’s Hipocrate Information System (HIS), impacting 26 hospitals and causing widespread system outages across nearly 100 facilities, with ransom demands of approximately 3.5 BTC (~$175,000).
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
argonauts group — tracked by MISP Galaxy (ransomware).
Infra: 🔗 jbmk7h6xlkedn2gg5yi7…💬 4xi5jklauqmjfkwxhs2a…
RSLUpdated: 2026-08-12
View profile →APT GROUP
This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hacker spread the virus using email spam, fake updates, and harmful attachments. All your files are compromised including music, MS Office, Open Office, pictures, videos, shared online files etc..
Updated: 2026-08-12
View profile →justice blade
Technical ID: justice_blade
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 justice-blade.io…
RSLUpdated: N/A
View profile →APT GROUP
LockCrypt is an example of yet another simple ransomware created and used by unsophisticated attackers. Its authors ignored well-known guidelines about the proper use of cryptography. The internal structure of the application is also unprofessional. Sloppy, unprofessional code is pretty commonplace when ransomware is created for manual distribution. Authors don’t take much time preparing the attack or the payload. Instead, they’re rather focused on a fast and easy gain, rather than on creating something for the long run. Because of this, they could easily be defeated.
Updated: 2026-08-12
View profile →APT GROUPfinancial
Hotarus Corp is a ransomware group that came to attention in early 2021 after attacking Ecuador's Ministry of Finance and Banco Pichincha — the country's largest private bank — deploying PHP-based ransomware and claiming to have stolen tens of millions of customer records.
Infra: 🔗 r6d636w47ncnaukrpvlh…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Mamona was a short-lived ransomware rebrand attempted by the operator behind BlackLock RaaS in March 2025 that failed before reverting; as a standalone strain it operates entirely offline with no C2 communication, uses custom encryption, and targets Windows systems.
Infra: 🔗 owt3kwkxod2pvxlv3ulj…🔗 185.158.113.114.…🔗 185.158.113.114.…+1 more
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
"Unknown" is a catch-all tracking label used on ransomware monitoring platforms for attacks where the responsible threat actor has not been positively attributed to a known named group, serving as a placeholder for unattributed incidents.
Infra: 🔗 tdoe2fiiamwkiadhx2a4…🔗 darktorhvabc652txfc5…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Slug is a very obscure ransomware or extortion group with only a single documented victim (AerCap, the aircraft leasing company) recorded on ransomware tracking platforms; no detailed threat intelligence reports exist for this group.
Infra: 🔗 3ytm3d25hfzvbylkxiwy…
RSLUpdated: 2026-08-12
View profile →APT GROUPfinancial
obsidian orb — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-12
View profile →APT GROUP
Kelvin Security is a cybercrime group active since at least 2013, primarily known for hacktivism, data breaches, and website defacements rather than traditional ransomware operations. The group has claimed responsibility for intrusions targeting government agencies, educational institutions, and private companies across multiple regions, including Latin America, Europe, and the Middle East. While it has engaged in data theft and leak threats, there is no confirmed evidence that Kelvin Security operates a ransomware encryption component. Instead, their extortion model focuses on stealing sensitive data and threatening public disclosure, often publicizing breaches via social media and underground forums. The group’s activities have been linked to politically motivated campaigns as well as financially motivated breaches. Victim selection appears opportunistic, exploiting vulnerabilities in web servers, poorly configured databases, and exposed credentials.
Updated: 2026-08-12
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 ransomyktqx2m3xg.oni…
RSLUpdated: N/A
View profile →