Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters711 entities
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 v76bdil3v7hczufr7kwk
RSLUpdated: N/A
View profile →
APT GROUPfinancial
shadowbyt3$ — tracked by MISP Galaxy (ransomware).
Infra: 🔗 shadowbyt3s.8bit.ca🔗 shadowsblog.cloud-ip🔗 shadoz22.io+5 more
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
vanir group — tracked by MISP Galaxy (ransomware).
Infra: 🔗 6xdpj3sb5kekvq5ulym5🔗 6xdpj3sb5kekvq5ulym5
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
Nova (formerly RALord) is a ransomware-as-a-service (RaaS) group that encrypts victims’files and uses double-extortion tactics to pressure organizations into paying for decryption and data non-disclosure.
Affiliates: Bog1337 • ploja • Hunt3rs0p3r4tion
Infra: 🔗 novavdivko2zvtrvtlln🔗 novazzitmugtbjwuttc5💬 novaeogps7purkdhxmay+20 more
RLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
malek team — tracked by MISP Galaxy (ransomware).
Infra: 🔗 malekteam.ac🔗 195.14.123.2.
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
leakeddata — tracked by MISP Galaxy (ransomware).
Infra: 🔗 business-data-leaks.📁 ep6pheij.com
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
NoName (also known as CosmicBeetle) is a ransomware group active since at least 2020 targeting small and medium-sized businesses globally using its custom ScRansom tool, exploiting vulnerabilities like EternalBlue and ZeroLogon, and becoming a RansomHub affiliate to access that platform's RaaS infrastructure.
Infra: 🔗 noname2j6zkgnt7ftxsj🔗 www.lockbitblog.info🔗 7tkffbh3qiumpfjfq77p+2 more
RLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
Yurei is a ransomware group first observed in September 2025 whose payload is a minimally modified fork of the open-source Prince-Ransomware, using ChaCha20 encryption and propagating across SMB shares, primarily targeting food manufacturing, transportation, and IT sectors in Sri Lanka and Nigeria.
Infra: 🔗 fewcriet5rhoy66k6c4c
RLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia across manufacturing, communications, and construction sectors, operating a Tor-based double-extortion leak site.
Infra: 🔗 brohoodyaifh2ptccph5📁 fotxzhnoxtkpa6cwkimy📁 a5wdkdd7unaacdlzcjm5+12 more
RLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
First seen 2026-07-07
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 flock4cvoeqm4c62gyoh
RSLUpdated: N/A
View profile →
APT GROUPfinancial
M3rx is a small ransomware group first observed in 2025, using AES-CTR/AES-GCM encryption and targeting organizations in England, the US, Australia, Germany, Italy, and Switzerland, with around eight claimed victims including a Sydney-based property firm.
Infra: 💬 pippahtohg6qgioqu3ix🔗 4k6plf4h2cm2nco6ae3i
RLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
MBC is a very obscure ransomware group with minimal public documentation and no significant threat intelligence reports available from mainstream security vendors.
Infra: 🔗 xembshruusobgbvxg4tc
RLUpdated: N/A
View profile →
APT GROUPfinancial
blackfile — tracked by MISP Galaxy (ransomware).
Infra: 🔗 blacknbsxfdmjtx4yn53
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
rapture — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
prinz eugen — tracked by MISP Galaxy (ransomware).
Affiliates: ROOTBOY
Infra: 🔗 6cudc5cqa2bjpwdhcwm2🔗 prinzfkbjiazbrur4mjj🔗 prinzkpn6d3itrgcytms
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
Linkc is a ransomware group first observed in February 2025, operating a Tor-based data leak site and targeting US-based AI, cloud, aerospace, and manufacturing companies — including H2O.ai — demanding ransoms as high as $15 million using double-extortion tactics.
Infra: 🔗 iywqjjaf2zioehzzauys💬 xs4psqhvekjle3qwyiav
RLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
tuborg — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
Insomnia is a data-theft and extortion group that emerged in October 2025, targeting primarily US-based healthcare organizations — stealing patient files and threatening public exposure rather than encrypting files — and avoiding former Soviet states, consistent with Russian-speaking cybercrime norms.
Infra: 🔗 i62huw7ve22rpyw6lnq3📁 r3keoxye5mki4fqcvlk4
RLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
In mid-June 2024, a new ransomware operation named Brain Cipher emerged, notably targeting Indonesia's National Data Center. This attack disrupted immigration operations at airports and various other government services. The payload employed by this group is based on the leaked LockBit 3.0 builder. Comparative analyses have confirmed significant similarities between Brain Cipher and LockBit 3.0 samples. Notably, the attackers modified the ransomware to not only append a new extension to encrypted files but also to encrypt the filenames themselves. Additionally, it was identified that the group appears to be in its early stages, as evidenced by their use of the leaked LockBit 3.0 builder and their recent operations. After encrypting the data, the ransomware generates ransom notes named “added_extension.README.txt.” These notes contain a description of what occurred and a link to the attackers' website hosted on the Tor network.
Infra: 🔗 mybmtbgd7aprdnw2ekxh🔗 vkvsgl7lhipjirmz6j5u📁 cuuhrxbg52c5agytmtjp+36 more
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
b0 group — tracked by MISP Galaxy (ransomware).
Infra: 🔗 bzsn5crutf7eiq5mlohn
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
osyolorz collective — tracked by MISP Galaxy (ransomware).
Infra: 🔗 hackerosyolorz77y7vw
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
JSWorm is a ransomware family that first appeared in May 2019 and is notable for undergoing multiple rebrands and evolutions, later appearing under names such as Nemty, Nefilim, Offwhite, Fusion, and Milihpen. Initially, it was distributed via malicious spam emails containing JavaScript files, hence the “JS” in its name. Later versions moved to targeted intrusions, leveraging compromised RDP services and vulnerable network appliances for initial access. JSWorm encrypts files using AES-256 encryption with RSA-2048 for key protection and appends campaign-specific extensions (e.g., .JSWORM, .Nemty, .Nephilim). The group adopted a double-extortion model in its later stages, stealing data before encryption and threatening to leak it via Tor-hosted sites. Its victimology spans various sectors worldwide, including manufacturing, energy, healthcare, and professional services. The continuous rebranding suggests an effort to evade detection, disrupt attribution, and maintain pressure on victims.
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
Securotrop is a ransomware group established in early 2025 that operates within the Qilin affiliate network while maintaining an independent public identity, focusing exclusively on commercial targets and deliberately avoiding healthcare and government entities, with approximately 32 documented victims.
Infra: 🔗 securo45z554mw7rgrt7
RLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
clop torrents — tracked by MISP Galaxy (ransomware).
Infra: 🔗 toznnag5o3ambca56s2y
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
arkana security — tracked by MISP Galaxy (ransomware).
Infra: 🔗 arkanabb66ee4nsdji6l🔗 ransomwvbabemdnwl7lz
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
CerBerSysLock first appeared in December 2017 as a cryptoransomware imposter, leveraging Cerber-style branding to deceive victims. It uses XOR-based encryption to lock files and appends extensions such as .CerBerSysLocked0009881. Victims receive a ransom note titled “HOW TO DECRYPT FILES.txt”, which falsely claims to be from the Cerber ransomware. The note includes an email contact—TerraBytefiles@scryptmail.com—and instructs victims to reference their ID (e.g., "CerBerSysLocked0009881") when communicating. The ransomware is technically linked to the Xorist family and is generally considered an opportunistic, low-profile scam rather than part of a broader Ransomware-as-a-Service (RaaS) operation.
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
balletspistol — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
lambda — tracked by MISP Galaxy (ransomware).
Infra: 🔗 nn5ua7gc7jkllpoztymt🔗 krjv3wondknwdrlvzp6k
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
devman2 — tracked by MISP Galaxy (ransomware).
Infra: 🔗 wugurgyscp5rxpihef5v🔗 devmanblggk7ddrtqj3t🔗 tygjm32hxyqienrgwxve
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
Our team members are from different countries and we are not interested in anything else, we are only interested in dollars. We do not allow CIS, Cuba, North Korea and China to be targeted. Re-attacks are not allowed for target companies that have already made payments. We do not allow non-profit hospitals and some non-profit organizations be targeted.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Onyx is a ransomware group first observed in April 2022, based on the Chaos ransomware builder, that is notably destructive — files larger than 2MB are overwritten with random data rather than encrypted, making recovery impossible even after ransom payment — claiming approximately 13 victims across six countries.
RLUpdated: N/A
View profile →
APT GROUPfinancial
The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Genesis is an emerging ransomware group first observed in late 2025, targeting small to mid-sized US organizations across healthcare, retail, financial services, legal, and manufacturing using double-extortion tactics, focusing heavily on data exfiltration and public leaking.
Infra: 🔗 genesis6ixpb5mcy4kud
RLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
NetWalker ransomware group operates by the threat actor known as "CIRCUS SPIDER". The NetWalker ransomware was discovered in 2019. The group mainly targeting the Asia Pacific region but can attack globally. The group uses common attacking tools like Mimikatz and other legitimate tools (LOLBINS) like PSTools, AnyDesk, TeamViewer, NLBrute, and more. The group knowing by targeting the healthcare sector. Finally, in January 2021, Netwalker was takedown by the authorities, the police have confiscated hundreds of thousands of dollars in ransom payments collected by the Netwalker group, and they seized servers and disrupted the infrastructure and the darknet websites of the Netwalker ransomware group.
Infra: 🔗 rnfdsgm6wb6j6su5txke🔗 pb36hu4spl6cyjdfhing
RLUpdated: N/A
View profile →
APT GROUPfinancial
wallstreet — tracked by MISP Galaxy (ransomware).
Infra: 🔗 4dwiv37h7hhuhjpvtn72
RSLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
RANSOMED.VC aka Raznatovic
Infra: 🔗 f6amq3izzsgtna4vw24r🔗 f6amq3izzsgtna4vw24r🔗 ransomed.vc+1 more
RLUpdated: 2026-08-03
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 petya37h5tbhyvki.oni🔗 petya5koahtsf7sv.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
RansomedVC2 aka RebornVC aka RansomedVC (rebrand) under new leadership.
Infra: 🔗 ransomed.biz🔗 ransomed.vc
RSLUpdated: 2026-08-03
View profile →