Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters294 entities
APT GROUPfinancial
No detailed intelligence profile available.
Affiliates: Wazawaka
Infra: 🔗 nq4zyac4ukl4tykmidbz…
RSLUpdated: N/A
View profile →Abrahams Ax
Technical ID: Abrahams_Ax
APT GROUPfinancial
Abraham's Ax is an Iranian-linked hacktivist persona tied to Moses Staff that emerged in November 2022, primarily targeting Saudi Arabian government institutions for geopolitical reasons related to Saudi-Israeli normalization, using destructive wiper malware and data leak tactics rather than financial ransomware.
RLUpdated: N/A
View profile →APT GROUPfinancial
Vice Society ransomware appends the .v-society extension when encrypting Linux machines. Running a leak site on the darkweb, Possible relations with "HelloKitty"
Infra: 🔗 4hzyuotli6maqa4u.oni…🔗 vsociethok6sbprvevl4…🔗 ml3mjpuhnmse4kjij7gg…+5 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
RAMP (Russian Anonymous Marketplace) was a Russian-speaking dark web forum founded in 2021 that served as a central marketplace and recruitment hub for ransomware operators, affiliates, and initial access brokers — not a ransomware group itself but the backbone of the RaaS ecosystem; it was seized by the FBI in January 2026.
Affiliates: LockBitSupp • Wazawaka
Infra: 🔗 wavbeudogz6byhnardd2…🔗 rampjcdlqvgkoz5oywut…🔗 ramp4u5iz4xx75vmt6nk…+1 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 k7kzrgcoxsjm7fujj5vo…
RSLUpdated: N/A
View profile →la piovra
Technical ID: la_piovra
APT GROUPfinancial
ℹ️ La Piovra Ransomware is an exercise of the company Offensive Security (also known as OffSec)
RLUpdated: N/A
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 eraleignews.com…🔗 wn6vonooq6fggjdgyocp…🔗 basheqtvzqwz4vp6ks5l…+12 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums.
Infra: 🔗 54bb47h5qu4k7l4d7v5i…🔗 54bb47h.blog…
RSLUpdated: N/A
View profile →lockbit3 fs
Technical ID: lockbit3_fs
APT GROUPfinancial
LockBit 3.0 ("LockBit Black"), active since June 2022, is the third iteration of the LockBit RaaS platform incorporating code from BlackMatter ransomware, featuring modular encrypted payloads that evade analysis and targeting Windows and VMware ESXi environments across all sectors globally.
RLUpdated: N/A
View profile →APT GROUPfinancial
LockBit 2.0 is the second major iteration of the LockBit RaaS platform, launched in mid-2021, introducing automated domain-wide encryption via Active Directory Group Policy and claiming the fastest encryption speed among ransomware families, accounting for 46% of ransomware breach events in early 2022.
RLUpdated: N/A
View profile →APT GROUPfinancial
CMD is a new kind of company that specializes in corporate system security and in identifying vulnerabilities across all aspects of the software used by a company. CMD operates on a global scale recognizing the critical importance of timeliness and confidentiality.
RLUpdated: N/A
View profile →APT GROUPfinancial
Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victims in Indonesia, Italy, Venezuela, and the US, with minimal public threat-intelligence coverage.
Infra: 🔗 bl4cktorpms2gybrcyt5…
RSLUpdated: N/A
View profile →APT GROUPfinancial
LV ransomware group main message: "Here are companies which didn't meet consumer data protection obligations. They rejected to fix their mistakes, they rejected to protect this data in the case when they could and had to ptotect it. These companies prefered to sell their private information, their employees' and customers' personal data". Security researchers claim that the LV group is utilizing the REvil ransomware group malware. The LV group claim to have compromised the corporate network of Groupe Reorev.
Infra: 🔗 rbvuetuneohce3ouxjlb…🔗 4qbxi3i2oqmyzxsjg4fw…💬 l55ysq5qjpin2vq23ul3…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Abyss (also known as Abyss Locker) is a ransomware operation first identified in March 2023, derived from the Babuk source code, that targets Windows and Linux/VMware ESXi systems using double-extortion tactics across healthcare, manufacturing, finance, and technology sectors — predominantly in North America.
RLUpdated: N/A
View profile →APT GROUPfinancial
MyDecryptor is a low-profile ransomware group with minimal public documentation, appearing on ransomware tracking platforms but not the subject of major threat intelligence reporting, suggesting it is a small or relatively inactive operation.
Infra: 🔗 5s4ixqul2enwxrqv.oni…
RSLUpdated: N/A
View profile →APT GROUPfinancial
CryLock (originally known as Cryakl/Fantomas since 2014) is a ransomware operation run by a Russian couple who targeted roughly 400,000 victims over eight years and earned over €64 million in Bitcoin; the operators were arrested in Spain in June 2023 and extradited to Belgium.
Infra: 🔗 d57uremugxjrafyg.oni…
RSLUpdated: N/A
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 zhuobnfsddn2myfxxdqt…
RSLUpdated: N/A
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 yboa7nidpv5jdtumgfm4…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Arcus Media is a ransomware-as-a-service group that emerged in May 2024, employing double extortion with ChaCha20 + RSA-2048 encryption and recruiting affiliates via a referral-based vetting process, claiming 50+ victims across manufacturing, healthcare, retail, and business services globally.
RLUpdated: N/A
View profile →APT GROUPfinancial
Argonauts is a ransomware group that emerged in September 2024, operating a double-extortion model targeting logistics, healthcare, energy, and telecom sectors, with approximately 13 claimed victims tracked via a TOR-based leak site.
RLUpdated: N/A
View profile →APT GROUPfinancial
VFOKX is a low-profile ransomware group tracked on ransomware monitoring platforms with very limited public documentation and no detailed analysis or named victims published by major threat intelligence vendors.
Infra: 🔗 vfokxcdzjbpehgit223v…🔗 746pbrxl7acvrlhzshos…
RSLUpdated: N/A
View profile →APT GROUPfinancial
RA Group, also known as RA World, first surfaced in April 2023, utilizing a custom variant of the Babuk ransomware.
RLUpdated: N/A
View profile →APT GROUPfinancial
AgainstTheWest (ATW) is a hacktivist group active since October 2021 that targets governments and corporations perceived as authoritarian, breaching organizations like Alibaba, Sberbank, and Gazprom using custom ransomware and wiper malware for ideological disruption rather than financial profit.
RLUpdated: N/A
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 monteoamwxlutyovf7ox…🔗 monteoamwxlutyovf7ox…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Ranstreet is a low-profile ransomware group with very limited public documentation, appearing in ransomware tracking lists but without major vendor research reports or significant attributed attacks.
RLUpdated: N/A
View profile →APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 scbrksw5fgjtujc2ah42…
RSLUpdated: N/A
View profile →APT GROUPfinancial
RunSomeWares is an emerging ransomware group that surfaced in February 2025 with initial victims across supply-chain services, financial services, accounting, and manufacturing, with unclear deployment of an encryptor vs. pure data-theft extortion.
RLUpdated: N/A
View profile →APT GROUPfinancial
XINOF (also known as Fonix/FonixCrypter) is a RaaS operation that began in June 2020 with no upfront affiliate cost and four methods of encryption per file; the operators shut down the service and released the master decryption key in January 2021, allowing free decryption for all victims.
Infra: 🔗 wj3b2wtj7u2bzup75tzh…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Haron appeared in July 2021 as a ransomware-as-a-service operation heavily borrowing from the defunct Avaddon ransomware (copying ransom notes and leak site structure) and built on the Thanos ransomware builder, targeting enterprise organizations with a six-day negotiation window.
Infra: 💬 ft4zr2jzlqoyob7yg4fc…🔗 midasbkic5eyfox4dhni…
RSLUpdated: N/A
View profile →APT GROUPfinancial
BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies including insurance firm Shirbit and hosting provider Cyberserve, leaking medical records of 290,000 patients, using extortion as a tool of geopolitical disruption rather than purely for financial gain.
Infra: 🔗 544corkfh5hwhtn4.oni…🔗 blackshadow.cc…
RSLUpdated: N/A
View profile →APT GROUPfinancial
Dragon Ransomware, is promising rapid and customizable ransomware operations for Windows systems. Key features include a compact 50KB file size, ultra-fast encryption speed, and a builder tool that allows users to personalize ransomware configurations. The tool will be available to the public once the team reaches 1,000 subscribers on their channel, signaling a potential rise in availability to threat actors.
RLUpdated: N/A
View profile →APT GROUPfinancial
Nokoyawa is a double-extortion ransomware group that launched a RaaS program in 2022 (operated by threat actor "farnetwork"), primarily targeting businesses in South America across healthcare, financial services, government, and manufacturing, gaining significant attention in 2023 for exploiting a Windows CLFS zero-day (CVE-2023-28252).
Infra: 🔗 lirncvjfmdhv6samxvvl…🔗 6yofnrq7evqrtz3tzi3d…🔗 nokoleakb76znymx443v…+25 more
RSLUpdated: N/A
View profile →APT GROUPfinancial
Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities in Canada, France, and Germany before expanding to telecommunications, mining, and manufacturing sectors, operating a double-extortion model with a data leak site.
Infra: 🔗 black3gnkizshuynieig…📁 4qyjonpyksc52bc3fsgf…📁 ao5oo2luy6avdfomyw7h…+6 more
RSLUpdated: N/A
View profile →