Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters712 entities
APT GROUPfinancial
Fog, which uses the .flocked extension for encrypted files, was first observed in May in campaigns by Storm-0844, a threat actor known for distributing Akira. By June, Storm-0844 was deploying Fog more than Akira.
Infra: 💬 xql562evsy7njcsngacp…🔗 xbkv2qey6u3gd3qxcojy…🔗 xbkv2qey6u3gd3qxcojy…+3 more
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
According to PCrisk, Exorcist is a ransomware-type malicious program. Systems infected with this malware experience data encryption and users receive ransom demands for decryption. During the encryption process, all compromised files are appended with an extension consisting of a ransom string of characters.For example, a file originally named "1.jpg" could appear as something similar to "1.jpg.rnyZoV" following encryption. After this process is complete, Exorcist ransomware changes the desktop wallpaper and drops HTML applications - "[random-string]-decrypt.hta" (e.g. "rnyZoV-decrypt.hta") - into affected folders. These files contain identical ransom messages.
Infra: 🔗 7iulpt5i6whht6zo2r52…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Entropy is a ransomware first seen in 1st quarter of 2022, is being used in conjunction of Dridex infection. The ransomware uses a custom packer to pack itself which has been seen in some early dridex samples.
Infra: 🔗 leaksv7sroztl377bboh…
RSLUpdated: N/A
View profile →APT GROUPfinancial
DragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue share, then rebranded as a "ransomware cartel" in 2025, gaining notoriety for high-profile attacks on UK retailers Marks & Spencer, Co-op, and Harrods.
Infra: 🔗 z3wqggtxft7id3ibr7sr…💬 3pktcrcbmssvrnwe5skb…📁 dragonforxxbp3awc7mz…+17 more
MY
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".
Infra: 🔗 hpoo4dosa3x4ognfxpqc…💬 qkbbaxiuqqcqb5nox4np…
RSLUpdated: N/A
View profile →APT GROUPfinancial
DoNex is a ransomware strain that emerged in March 2024 as the latest rebrand of a lineage beginning with Muse (2022) → DarkRace (2023) → DoNex, targeting enterprises in the US and Europe using double-extortion; Avast released a free decryptor in July 2024 after discovering a cryptographic flaw.
Infra: 🔗 g3h3klsev3eiofxhykmt…
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
A ransomware with potential ties to Wizard Spider.
Infra: 💬 7ypnbv3snejqmgce4kbe…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Dharma is a prolific ransomware family active since at least 2016, evolving from the earlier CrySiS ransomware. It operates under a Ransomware-as-a-Service (RaaS) model, allowing affiliates to deploy customized builds with their own contact emails and extensions. Dharma typically appends encrypted files with patterns like .id-[victimID].[email].dharma or other campaign-specific suffixes. Initial access is often gained through exposed Remote Desktop Protocol (RDP) services secured with weak or stolen credentials, sometimes combined with brute-force attacks. The malware encrypts files using AES with RSA to secure the keys and drops ransom notes in text files and pop-up windows. Numerous variants have emerged over time, each linked to different affiliates, making attribution difficult.
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
Former RansomHub and INC Ransom affiliate.
Infra: 🔗 qljmlmp4psnn3wqskkf3…
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
Darkside ransomware group has started its operation in August of 2020 with the model of RaaS (Ransomware-as-a-Service). They have become known for their operations of large ransoms scale. They have announced that they prefer not to attack hospitals, schools, non-profits, and governments, but rather big organizations that can be able to pay large ransoms. Darkside ransomware group became very famous following the cyberattack of the Colonial Pipeline and Toshiba unit. The FBI finally terminate the Darkside operation and Managed to pull money from their wallets back.
Infra: 🔗 darksidc3iux462n6yun…💬 dark24zz36xm4y2phwe7…🔗 darksidedxcftmqa.oni…
RSLUpdated: N/A
View profile →APT GROUPfinancial
DarkBit is an ideologically motivated ransomware group that appeared in February 2023, primarily targeting Israeli entities — most notably the Technion Institute of Technology — with politically charged ransom notes condemning Israeli government policies, assessed to be linked to Iranian state-sponsored activity.
RLUpdated: N/A
View profile →APT GROUPfinancial
Cyclops emerged in May 2023 as a cross-platform RaaS operation targeting Windows, macOS, and Linux systems; it rebranded as "Knight" in August 2023 and its codebase was ultimately sold, with affiliates largely migrating to RansomHub.
Infra: 🔗 nt3rrzq5hcyznvdkpslv…💬 wy35mxvqxff4vufq64v4…
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted.<br> <br> Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba. The group has been linked to a Russian-language threat actor by Profero researchers due to some details of incorrect translation they discovered, as well as the discovery of a 404 page containing text in Russian on the threat actor's own leak site.<br> <br> According to BlackBerry, based on the analysis of the code strings used in the campaign analyzed in 2023, there were indications that the developer behind the Cuba ransomware speaks Russian.<br> <br> The ransomware operators use a double extortion approach, and following the USA, in August 2022, it was believed that the Cuba ransomware group had compromised 101 entities, demanding $145 million in ransom payments and receiving up to $60 million.<br> <br> The group used a similar set of TTPs, with only a slight change each year, as they generally consist of LOLBins (executables that are part of the operating system and can be exploited to support an attack), exploits, off-the-shelf and custom malware, as well as intrusion tools like Cobalt Strike and Metasploit.<br> <br> In 2022, the group allegedly developed a relationship with operators of the Industrial Spy market, using their platform as a means of data leakage.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 cuba4mp6ximo2zlo.oni…🔗 cuba4ikm4jakjgmkezyt…📁 i34gbmo5rxx3bxc4yl7f…+1 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
aka Critroni
<br/>CTB‑Locker emerged in mid‑2014, introducing a new era of ransomware by leveraging elliptic curve cryptography (ECC), Tor-based C&C communication, and Bitcoin payments—earning its name from “Curve-Tor-Bitcoin Locker.” It was packaged and sold as a ransomware kit for approximately $1,500–$3,000, allowing affiliates to deploy customized campaigns. The malware encrypts user data (including network and removable drives), changes desktop wallpapers, and appends file extensions like .CTBL, .CTB2, or randomized strings. Victims receive instructions for payment, typically within a limited timeframe, or risk permanent data loss. In 2015–2017, law enforcement and cybersecurity firms (including McAfee and Kaspersky) disrupted the network, arrested operators, and facilitated decryption tools.
Infra: 💬 ohmva4gbywokzqso.oni…💬 tmc2ybfqzgkaeilm.oni…
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
According to OALabs, this ransomware has the following features: * Files are encrypted with AES CBC using a generated 256 bit key and IV.* The generated AES keys are encrypted using a hard coded RSA key and appended to the encrypted files.
Infra: 💬 cryptr3fmuv4di5uiczo…🔗 blog6zw62uijolee7e6a…
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
CrossLock is a short-lived Go-based ransomware group that appeared in April 2023 and went dark by July 2023, using Curve25519 and ChaCha20 encryption and double-extortion tactics with only one known confirmed victim in the IT sector in Brazil.
Infra: 🔗 crosslock5cwfljbw4v3…
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese organizations in healthcare, education, and industrial sectors using BYOVD techniques and tools like SharpGPOAbuse for lateral movement.
RLUpdated: N/A
View profile →APT GROUPfinancial
Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang.
Affiliates: Wazawaka
Infra: 🔗 continewsnv5otx5kaoj…🔗 continews.click…💬 m232fdxbfmbrcehbrj5i…+6 more
🇷🇺 RU
RSLUpdated: N/A
View profile →APT GROUPfinancial
The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505.<br> <br> At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware.<br> <br> After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.'<br> <br> The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 ekbgzchl6x2ias37.oni…🔗 santat7kpllt6iyvqbr7…📁 3ws3t4uo7fehnn4qpmad…+8 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
Cicada3301 is a ransomware-as-a-service group (tracked as Repellent Scorpius by Palo Alto) that emerged in mid-2024 using Rust-based ransomware targeting Windows, Linux, and ESXi systems, suspected to be a successor of BlackCat/ALPHV and running an affiliate program with 20% commissions.
Infra: 🔗 cicadabv7vicyvgz5khl…🔗 cicadacnft7gcgnveb7w…💬 cicadaxousmk6nbntd3u…+13 more
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
CatB ransomware was first observed in late 2022, gaining attention for abusing DLL hijacking via the Microsoft Distributed Transaction Coordinator (MSDTC) service—loading a malicious payload through DLL sideloading methods. The malware arrives in a two-stage dropper: the first DLL unpacks and launches the main payload (commonly named oci.dll), which subsequently encrypts files using hybrid RSA/AES cryptography. Unlike conventional ransomware, CatB does not rename files or distribute typical ransom notes; instead, it prepends the ransom message directly to the start of each encrypted file, making detection more difficult. Victims are instructed to contact the attackers via email (e.g., catB9991@protonmail.com or fishA001@protonmail.com), with the ransom demand escalating daily. Initial analysis suggests CatB may be a rebrand or evolution of Pandora ransomware, sharing various code artifacts and operational behavior.
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure.<br> <br> There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox.<br>Source: https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 cactusbloguuodvqjmnz…🔗 cactus5dqnqkppa5ayck…📁 vhfd5qagh6j7qbisjqvl…+4 more
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
BQTLock is a ransomware-as-a-service operation that emerged in 2025, using AES-256/RSA-4096 encryption with Monero payment demands, linked to pro-Palestinian hacktivist networks and targeting organizations with wave-based campaigns with 48-hour ransom deadlines.
Infra: 🔗 yywhylvqeqynzik6iboc…
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
BlueSky is a financially motivated ransomware group active from mid-2022 into early 2023, using multi-threaded ChaCha20/Curve25519 encryption for fast file locking on Windows hosts, with code sharing significant overlap with Conti v2/v3 and Babuk, attributed with high confidence to Russian-origin threat actors.
Infra: 🔗 ccpyeuptrlatb2piua4u…
RSLUpdated: N/A
View profile →APT GROUPfinancial
According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.
RLUpdated: N/A
View profile →APT GROUPfinancial
BlackSnake is a Ransomware-as-a-Service (RaaS) operation that first appeared in August 2022, when its operators began recruiting affiliates on underground forums with an unusually low revenue share of 15%. It primarily targets home users rather than large enterprises and does not maintain a public leak site. Built on the Chaos ransomware code base, it features both file encryption and a cryptocurrency clipper module to steal funds from victims. The ransomware is developed in .NET and includes safeguards to avoid execution in Turkish or Azerbaijani environments, suggesting geographic targeting preferences. Infections result in encrypted files and ransom notes instructing victims to make contact via email for payment negotiations. The group’s operational scale and visibility remain limited compared to major RaaS families.
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
Ransomware-as-a-Service
Infra: 🔗 blackmax7su6mbwtcyo3…💬 supp24yy6a66hwszu2pi…💬 supp24maprinktc7uizg…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Ransomware. Uses dropper written in JavaScript to deploy a .NET payload.
Infra: 🔗 6iaj3efye3q62xjgfxye…🔗 f5uzduboq4fa2xkjlopr…🔗 dlyo7r3n4qy5fzv4645n…+10 more
T1112T1053.005T1055.012
RSLUpdated: N/A
View profile →APT GROUPfinancial
"Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebrand of a previous top-tier ransomware gang that brought along their affiliates.
Infra: 🔗 stniiomyjliimcgkvdsz…💬 bastad5huzwkepdixedg…📁 6y2qjrzzt4inluxzygdf…+14 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog.
Infra: 🔗 bianlianlbc5an4kgnay…🔗 bianlivemqbawcco4cx4…🔗 bianliaoxoeriowgqohc…+1 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
BERT is a newly emerged ransomware group first identified in mid-2025, targeting Windows and Linux platforms across healthcare, technology, and event services sectors in Asia, Europe, and the US, with ransomware derived from a Linux variant of REvil using AES encryption and multi-threaded file locking.
Infra: 🔗 bertblogsoqmm4ow7nqy…📁 wtwdv3ss4d637dka7iaf…
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
Babuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys.
RLUpdated: N/A
View profile →APT GROUPfinancial
AvosLocker is the ransomware payload of the Avos RaaS group, active from July 2021 to approximately May 2023, targeting education, manufacturing, and healthcare sectors on Windows, Linux, and VMware ESXi environments, with the US accounting for ~72% of victims.
Infra: 🔗 avosqxh72b5ia23dl5fg…💬 avosjon4pfh3y7ew3jdw…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Avaddon is a ransomware malware targeting Windows systems often spread via malicious spam. The first known attack where Avaddon ransomware was distributed was in February 2020. Avaddon encrypts files using the extension .avdn and uses a TOR payment site for the ransom payment.
Infra: 🔗 avaddongun7rngel.oni…💬 avaddonbotrxmuyl.oni…
RSLUpdated: N/A
View profile →APT GROUPfinancial
AtomSilo is a double-extortion ransomware group that emerged in September 2021, exploiting the Atlassian Confluence vulnerability (CVE-2021-26084) for initial access and demanding ransoms up to $1 million, attributed to the Chinese state-linked threat actor BRONZE STARLIGHT.
Infra: 🔗 mhdehvkomeabau7gsetn…🔗 l5cjga2ksw6rxumu5l4x…🔗 npmh5ahrgakbniuntyc7…+1 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
AstraLocker first appeared in 2021, likely as a fork of Babuk ransomware using leaked source code. It follows a single-extortion, smash-and-grab approach: distributed directly via phishing Microsoft Word documents containing embedded OLE objects. Once executed, it kills security and backup processes, deletes shadow copies, and encrypts files using modified HC-128 and Curve25519 algorithms, appending extensions like .Astra or .babyk. A “smash-and-grab” style attack, it’s less methodical than more sophisticated campaigns—deploying ransomware immediately upon user action rather than conducting prolonged network reconnaissance. In mid-2022, the operator ceased ransomware operations, releasing decryptors and announcing a pivot to cryptojacking.
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
AlphaLocker is a low-cost ransomware operation built on the EDA2 open-source project that sells affiliates an admin panel, ransomware executable, and decryption key generator, lowering the barrier for entry-level cybercriminals using double-extortion tactics.
RLUpdated: N/A
View profile →APT GROUPfinancial
The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group.<br> <br> It's worth noting that with the end of CONTI's operation, several affiliates migrated to independent campaigns such as Royal, BlackBasta, and others.<br> <br> According to some reports, Akira affiliates also work with other ransomware operations, such as Snatch and BlackByte, as an open directory of tools used by an Akira operator was identified, which also had connections to the Snatch ransomware.<br> <br> The first version of the Akira ransomware was written in C++ and appended files with the '.akira' extension, creating a ransom note named 'akira_readme.txt,' partially based on the Conti V2 source code. However, on June 29, 2023, a decryptor for this version was reportedly released by Avast.<br> <br> Subsequently, a version was released that fixed the decryption flaw on July 2, 2023. Since then, the new version is said to be written in Rust, this time called 'megazord.exe,' and it changes the extension to '.powerranges' for encrypted files.<br> <br> Most of Akira's initial access vectors use brute-force attempts on Cisco VPN devices (which use single-factor authentication only).<br> Additionally, exploitation of CVEs: CVE-2019-6693 and CVE-2022-40684 for initial access has been identified.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 akiral2iz6a7qgd3ayp3…💬 akiralkzxzq2dsrzsrvb…🔗 akiral2iz6a7qgd3ayp3…
T1482T1486T1567.002
RSLUpdated: N/A
View profile →APT GROUPfinancial
The 8base Ransomware group made its first appearance in early March 2022, remaining somewhat quiet after the attacks. This group operates like other ransomware actors, engaging in double extortion. <BR> However, in mid-May and June 2023, the ransomware operation saw a spike in activity against organizations from various sectors, listing 131 organizations in just 3 months.<BR> The 8base data leak site was created and made available in March 2023, claiming honesty and simplicity in its discourse.<BR> VMware published a report on 8base, drawing some similarities with the ransomware group `RansomHouse`, pointing out resemblances such as the website used by 8base and the ransom notes presented in its attacks.<BR> Interestingly, the 8base Ransomware group does not have its own ransomware developed by the group. Instead, the actors took advantage of other leaked ransomware builders to customize the ransom note and present it to the victim organization as 8base's operation.<BR>Source : https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 basemmnnqwxevlymli5b…🔗 xb6q2aggycmlcrjtbjen…🔗 92.118.36.204.…+2 more
RSLUpdated: 2026-08-02
View profile →APT GROUPfinancial
Stormous is an Arabic-speaking, pro-Russian ransomware and hacktivist group active since at least 2022, known for politically motivated attacks across 15+ countries, collaborating with GhostSec on the GhostLocker 2.0 RaaS platform and inheriting GhostSec's RaaS operations in mid-2024.
On 1st July 2026 the group has annonced the end of their operations & ervices
Infra: 🔗 3slz4povugieoi3tw7sb…🔗 h3reihqb2y7woqdary2g…🔗 h3reihqb2y7woqdary2g…+3 more
RSLUpdated: N/A
View profile →