Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters712 entities
APT GROUPfinancial
Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
Affiliates: Ben
Infra: 💬 ozsxj4hwxub7gio347ac…🔗 24kckepr3tdbcomkimbo…💬 wlh3dpptx2gt7nsxcor3…+637 more
RLUpdated: N/A
View profile →APT GROUPfinancial
Monti is a ransomware group first observed in June 2022 that initially copied nearly all of Conti's leaked source code, pivoting to target government, legal, and healthcare entities, later releasing a new Linux variant in 2023 with significantly less Conti code similarity, and experimenting with an affiliate model.
Affiliates: Wazawaka
Infra: 🔗 4s4lnfeujzo67fy2jebz…🔗 mblogci3rudehaagbryj…📁 fzuaswymt34cbkneudij…+18 more
RLUpdated: N/A
View profile →APT GROUPfinancial
IceFire is a ransomware group first observed in 2022 that expanded to Linux in early 2023 by exploiting a vulnerability in IBM Aspera Faspex (CVE-2022-47986), targeting media and entertainment organizations in Turkey, Iran, Pakistan, and the UAE using double-extortion tactics.
Infra: 🔗 kf6x3mjeqljqxjznaw65…🔗 7kstc545azxeahkduxme…💬 nxx3cy6aee2s53v7v5px…
RLUpdated: N/A
View profile →APT GROUPfinancial
Helldown is an aggressive ransomware group first documented in August 2024, known for exploiting Zyxel firewall vulnerabilities to gain initial access and conducting large-scale data exfiltration averaging 70 GB per victim, targeting IT services, telecommunications, manufacturing, and healthcare primarily in the US.
Infra: 🔗 onyxcgfg4pjevvp5h34z…🔗 onyxcym4mjilrsptk5uo…🔗 www.helldown.org…+1 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Founded 4 April 2026
Infra: 🔗 x4bccxlsmjsxlnnf3ocv…🔗 titanblog.org…🔗 x4bccxlsmjsxlnnf3ocv…
RLUpdated: 2026-08-03
View profile →APT GROUP
Malware family tracked by Malpedia. ID: apk.loki
APT GROUPfinancial
TridentLocker is a newly emerged ransomware group (surfaced mid-2025) targeting organizations managing high volumes of regulated or third-party data — including government services, telecom, and engineering firms — across the US, Canada, UK, and Asia using double-extortion tactics.
Infra: 🔗 tridentfrdy6jydwywfx…💬 tridentfrdy6jydwywfx…
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Space Bears is a double-extortion ransomware group that emerged in April 2024, distinguished by a professional "corporate" aesthetic on its leak site, leveraging Phobos RaaS infrastructure and targeting small-to-medium organizations in manufacturing, technology, and healthcare across the US and Europe.
🇷🇺 RU
RLUpdated: N/A
View profile →APT GROUPfinancial
Sinobi is a private vetted-affiliate RaaS group that emerged in mid-2025, believed to be a rebrand of the Lynx/INC ransomware lineage, claiming 176 victims by end of 2025 through double-extortion attacks primarily against mid-market US organizations via compromised SonicWall VPN credentials.
Infra: 🔗 sinobi6ftrg27d6g4sjd…🔗 sinobi6rlec6f2bgn6rd…🔗 sinobi6ywgmmvg2gj2yy…+18 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Not a ransomware group but a hacktivist group that appeared coincidentally days before Russia’s invasion of Ukraine
Infra: 🔗 nv5p2mmpctvyqdyyi5zw…
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members.
Infra: 🔗 toolatedhs5dtr2pv6h5…🔗 shinypogk4jjniry5qi7…📁 91.215.85.22.…+5 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
RansomHouse is a double-extortion RaaS operation active since late 2021, attributed to the threat actor "Jolly Scorpius," targeting over 120 organizations across healthcare, finance, transportation, and government, recently upgrading to a multi-layered dual-key encryption architecture.
Infra: 🔗 xw7au5pnwtl6lozbsudk…🔗 zohlm7ahjwegcedoz7lr…📁 q2injs6dqvzemu2kkfpk…+176 more
RLUpdated: N/A
View profile →APT GROUPfinancial
A hacktivist group protecting artists' rights and ensuring fair compensation for their work.
Infra: 🔗 nullbulge.co…🔗 nullbulge.se…🔗 nullbulge.com…+2 more
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Cybereason Nocturnus describes Moses Staff as an Iranian hacker group, first spotted in October 2021. Their motivation appears to be to harm Israeli companies by leaking sensitive, stolen data.
🇮🇷 IRT1505.003T1021.002T1087.001
RLUpdated: N/A
View profile →APT GROUPfinancial
Mogilevich appeared in February 2024, rapidly claiming high-profile breaches of Epic Games, DJI, Shein, and Kick.com, but was quickly exposed as a fraud — the group's operator admitted they were "professional fraudsters" who sold fake breach data and access to a non-existent RaaS panel.
Infra: 🔗 dkgn45pinr7nwvdaehem…🔗 dkgn45pinr7nwvdaehem…
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.
Infra: 🔗 t.me…🔗 lapsus.by…📁 vunk5dvj634b75xpsj64…+2 more
T1136.003T1578.003T1589
RLUpdated: N/A
View profile →APT GROUPfinancial
KelvinSecurity is a financially motivated hacking group active since at least 2015, primarily engaged in stealing and selling databases from telecommunications, healthcare, and political organizations worldwide, with notable breaches including Vodafone Italia and Frost & Sullivan; the group's leader was arrested by Spanish police.
ES
RLUpdated: N/A
View profile →APT GROUPfinancial
Kazu is an emerging ransomware group active since September 2025 that employs double-extortion tactics, targeting government, healthcare, and financial organizations primarily in Southeast Asia, the Middle East, and Latin America, with notable claimed breaches including Dubai's Ports, Customs and Free Zone Corporation with 1.94 TB exfiltrated.
Affiliates: darkforums.st/User-Kazu • forum.exploit.in/profile/203546-kazu/
Infra: 🔗 6czlbd2jfiy6765fbnbn…
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Karakurt is a pure data-extortion group (no encryption) assessed with high confidence to be the extortion arm of the Conti ransomware group, active from 2021, that steals data and threatens to auction or publish it unless ransoms ranging from $25,000 to $13 million are paid.
Infra: 🔗 3f7nxkjway3d223j27ly…🔗 www.karanews.live…🔗 www.karanews.live…+7 more
RLUpdated: N/A
View profile →APT GROUPfinancial
Kairos is a data extortion group active since late 2024 that focuses solely on data theft with no encryption, primarily targeting small-to-mid-sized organizations in healthcare, manufacturing, and business services in the US, purchasing initial access from brokers and demanding Bitcoin payments.
Infra: 🔗 nerqnacjmdy3obvevyol…📁 dwgxeoaqykd3zdkhol5x…📁 dngqgtcqcz5hgjvk4enc…+9 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
aka Belesn Group
Infra: 🔗 belsenacdodoy3nsmmyj…
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
We are AzzaSec — a decentralized PMC (Private Military Contractor), RaaS (Ransomware-as-a-Service) syndicate, and botnet operator at the intersection of cyberwarfare, asymmetric operations, and underground economics.
<br/>
<br/>Emerging from the collapse of traditional hacktivism, we evolved into a sovereign digital force. We offer custom offensive solutions to clients with political, financial, or strategic objectives. We are stateless, leaderless, and loyal only to code.
<br/>
Infra: 🔗 sebzpewd2zz7jap56r37…
IT
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
A new ransomware group is said to have emerged in mid-April 2024, under the name 'APT73.' It's worth noting that the group reportedly self-proclaimed as an APT, which stands for 'Advanced Persistent Threat' in the cybersecurity field.<br> <br> According to research, much of the available information about the aforementioned group came from another ransomware group known as LockBit.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
RLUpdated: N/A
View profile →APT GROUPfinancial
Everest ransom group collects and analyzes information about their victims. They specialize in customer privacy data, financial information, databases, credit card information, and more. The Everest ransom group leaks the victim's data to the darknet and they announced that any victim that will not contact them will suffer from a data leak and they will not delete hist files for future usage.
Infra: 🔗 ransomocmou6mnbquqz4…🔗 ransomoefralti2zh5nr…📁 2vqamwfdpis5rkjtpkut…+4 more
RLUpdated: N/A
View profile →APT GROUPfinancial
FreeWorld is a ransomware variant first observed in September 2023, and is believed to be derived from the Mimic ransomware family. It is deployed through coordinated campaigns dubbed DB#JAMMER, which exploit poorly secured Microsoft SQL (MSSQL) servers exposed to the internet. Attackers gain initial access via brute force, leverage the xp_cmdshell feature to execute shell commands, disable defenses, deploy remote access tools like Cobalt Strike and AnyDesk, and eventually deliver the FreeWorld payload. The ransomware encrypts files using hybrid encryption and appends the .FreeWorldEncryption extension. Victims receive a ransom note titled FreeWorld-Contact.txt, directing them on payment and data recovery steps.
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
jo of satan — tracked by MISP Galaxy (ransomware).
Infra: 🔗 jos666vxenlqp4xpnsxe…
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
kawa — tracked by MISP Galaxy (ransomware).
Infra: 🔗 kawasa2qo7345dt7ogxm…
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Dark Angels is a highly selective ransomware group active since April 2022 that targets a small number of large enterprises — including Johnson Controls — exfiltrating up to 100 TB of data per victim, and secured the largest known single ransom payment of $75 million from a Fortune 50 company in early 2024.
RLUpdated: N/A
View profile →APT GROUPfinancial
NoEscape was a RaaS operation active from May to December 2023 believed to be a rebrand of the defunct Avaddon ransomware, targeting professional services, manufacturing, and healthcare with triple-extortion capabilities (encryption, data theft, and optional DDoS), before abruptly shutting down in an apparent exit scam.
Affiliates: Wazawaka
Infra: 💬 noescaperjh3gg6oy7rc…🔗 noescapemsqxvizdxyl7…🔗 noescapemsqxvizdxyl7…
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Embargo is a Rust-based ransomware-as-a-service group that emerged in April 2024, primarily targeting US healthcare, manufacturing, and business services organizations using double extortion, assessed as a potential successor to BlackCat/ALPHV with over $34 million in ransom proceeds.
Infra: 🔗 embargobe3n5okxyzqph…💬 5ntlvn7lmkezscee2vha…📁 76yl7gfmz2kkjglcevxp…+50 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Also known as MedusaLocker
Infra: 🔗 z6wkgghtoawog5noty5n…💬 qd7pcafncosqfqu3ha6f…💬 6i42qq2xdu244a3xp2c3…
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
BIDON is a variant of the Monti ransomware family, first observed around mid‑2023. It employs a double‑extortion strategy—encrypting victims’ files and simultaneously threatening to leak stolen data if the ransom isn’t paid. Notably, it appends the .PUUUK extension to encrypted files and drops a readme.txt ransom note outlining the extortion demands. The note offers a free decryption of two files as proof of capability and emphasizes that only authorized company personnel (e.g., top management) should engage. BIDON specifically targets corporate and enterprise organizations, not home users, and warns victims not to involve law enforcement or third-party recovery firms. It represents a shift toward more aggressive extortion tactics within the Monti lineage.
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
mcrypt2019 — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 iw6v2p3cruy7tqfup3yl…🔗 iw6v2p3cruy7tqfup3yl…
RSLUpdated: N/A
View profile →APT GROUPfinancial
desolated — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
PayoutsKing is an active ransomware group observed through at least 2026 that has claimed attacks against a wide range of industries internationally — including Del Monte Foods and V. FRAAS — across the US, UK, Germany, and Ireland using standard double-extortion tactics.
Infra: 🔗 payoutsgn7cy6uliwevd…📁 v2mw3spxqhggig5zjd6t…📁 c6nrwsloenpiat7zilh2…
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
DataKeeper is a ransomware-as-a-service operation dating back to at least 2018 that promoted an affiliate model called "CrystalPartnership RaaS," offering a Windows-focused ransomware toolkit with hybrid RSA-4096 encryption, open dark web registration, and an innovative split-payment mechanism to build affiliate trust.
Infra: 🔗 dc4nwiijwiffwztwzj5f…
RLUpdated: N/A
View profile →APT GROUPfinancial
Tengu is a RaaS operation first observed in October 2025, following a double-extortion model and using Living Off The Land Binaries (LOLBins) to blend malicious activity with normal admin traffic, primarily targeting consumer goods, real estate, automotive, healthcare, and IT sectors.
Infra: 🔗 fuvodyoktsjdwu3mrbbr…🔗 longcc4fqrfcqt5lzceu…🔗 longejh5gj5igfinj36r…+4 more
RLUpdated: 2026-08-03
View profile →