Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters294 entities
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 weepangrbqjfsxd2noz4
RSLUpdated: N/A
View profile →
APT GROUPfinancial
QLocker was a financially motivated ransomware operation active in 2021 that exclusively targeted QNAP NAS devices exposed to the internet, exploiting a hard-coded credentials vulnerability to compress files into password-protected 7-Zip archives and demanding roughly $400 per victim, netting approximately $350,000 in a single month.
Infra: 💬 gvka2m4qt5fod2fltkjm
RSLUpdated: N/A
View profile →
APT GROUPfinancial
RebornVC is a rebrand of RansomedVC re-emerging in July 2025 under new leadership, using data auctions, direct extortion, and double extortion techniques with ransom demands ranging from $10,000 to $1,000,000, with confirmed victims in the US and Brazil.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".
Infra: 🔗 griefcameifmv4hfr3au💬 payorgz3j6hs2gj66nk6
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Underground ransomware is deployed by the Russia-based RomCom group (Storm-0978) and has victimized companies across multiple industries since July 2023 by exploiting CVE-2023-36884, encrypting files without changing extensions and deleting Volume Shadow Copies and Windows event logs in double-extortion campaigns.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Arvin Club is a threat actor with hacktivist leanings that first appeared in May 2021, primarily publishing stolen data via a TOR site and Telegram rather than deploying file-encrypting ransomware, targeting government, education, and banking sectors globally including Iranian government entities.
Infra: 🔗 3kp6j22pz3zkv76yutct🔗 arvinc7prj6ln5wpd6yy
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 moishddxqnpdxpababec
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Brain Cipher emerged in July 2024. Both Windows and Linux variants are available. Brain Cipher using the leaked build of LockBit Black for their operations. The group suspected to have exploited CVE-2023-28252 (Microsoft Windows CLFS Driver Privilege Escalation Vulnerability). The Ransom demand ranges from $150,000 to $1,00,0000. Demand to be paid with Monero (XMR) cryptocurrency. In 2025, they have shifted their new Negotiation portal to new server with vanity TOR Domain starting with 'brain'.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Arkana is a ransomware group that emerged in early 2025 and gained attention by claiming an attack on U.S. broadband provider WideOpenWest (WOW!), operating a three-phase ransom/sale/leak extortion model primarily focused on telecom and internet service providers.
RLUpdated: N/A
View profile →
abrahams ax
Technical ID: abrahams_ax
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 abrahamm32umasogaqoj
RSLUpdated: N/A
View profile →
APT GROUPfinancial
A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker avoids executable files, probably to avoid rendering the targeted system unusable for paying the ransom. It uses a combination of AES and RSA-2048, and reportedly appends extensions such as .encrypted, .bomber, .boroff, .breakingbad, .locker16, .newlock, .nlocker, and .skynet.
Infra: 🔗 kwvhrdibgmmpkhkidrby💬 kwvhrdibgmmpkhkidrby
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 powerj7kmpzkdhjg4szv
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 6dtxgqam4crv6rr6.oni💬 i3ezlvkoi7fwyood.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 mrv44idagzu47oktcipn
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 sekhmetleaks.top🔗 rlmuybcg5h5gaatr.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
🚨 This is a fake group with fake victims.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Direct Extortion Double Extortion
RLUpdated: N/A
View profile →
APT GROUPfinancial
DarkLeakMarket is a dark web data leak marketplace active since at least 2019 that sells stolen data sourced from ransomware groups and hacking forums, with 39 known victim organizations; it operates more as a data resale market than a traditional ransomware operator.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
AiLock is a ransomware operation that emerged in early 2025, marketing itself as AI-assisted ransomware using a hybrid ChaCha20/NTRUEncrypt encryption scheme and double-extortion tactics, actively recruiting affiliates and threatening regulatory reporting if ransoms are unpaid.
RLUpdated: N/A
View profile →
APT GROUPfinancial
BlackNevas is a ransomware group first observed in November 2024, believed to be derived from the Trigona ransomware family, targeting telecommunications, manufacturing, medical, and legal industries primarily in Asia-Pacific, the UK, Italy, and Lithuania using double-extortion with a dual AES/RSA encryption scheme.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
INC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 200 victims in 2025 alone with no sector off-limits.
RLUpdated: N/A
View profile →
APT GROUPfinancial
EP918 is a low-activity ransomware group listed in tracking databases with no confirmed victims and no publicly documented attacks or operational details.
Infra: 🔗 dg5fyig37abmivryrxlo
RSLUpdated: N/A
View profile →
APT GROUPfinancial
a former Conti team
RLUpdated: N/A
View profile →
APT GROUPfinancial
Dark Power emerged in January 2023 as a ransomware group written in the Nim programming language, claiming 10 victims across eight countries within its first month across agriculture, education, healthcare, IT, and manufacturing sectors, demanding $10,000 ransoms payable in Monero.
RLUpdated: N/A
View profile →
APT GROUPfinancial
The Green Blood Group is an emerging ransomware operation first identified in early 2026 whose Go-based Windows payload uses ChaCha8 encryption and aggressively destroys backup and recovery options, targeting organizations in India, Senegal, Egypt, Colombia, and Belgium.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
MadLiberator is a ransomware group that emerged in mid-2024, known for erratic behavior including randomized ransom demands and unpredictable encryption patterns, targeting government entities including the Italian Ministry of Culture and using a data leak site to post exfiltrated files.
RLUpdated: N/A
View profile →
APT GROUPfinancial
TiMc is a ransomware group that emerged in early 2026, claiming high-impact attacks against Spanish IT services leader Seidor (1 TB+ data) and oncology organization Oncologica (100 GB+), targeting Business Services, Healthcare, and IT sectors with a focus on Spanish-speaking and European targets.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 decrypt5bub45vpr.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
RRansom is a low-profile ransomware group whose dark web leak site has been listed as offline in tracking directories, with very limited public threat intelligence available about its targets, tactics, or scale of operations.
Infra: 🔗 t2tqvp4pctcr7vxhgz5y
RSLUpdated: N/A
View profile →
APT GROUPfinancial
PwndLocker is a ransomware that was observed in late 2019 and is reported to have been used to target businesses and local governments/cities. According to one source, ransom amounts demanded as part of PwndLocker activity range from $175k USD to $650k USD depending on the size of the network. PwndLocker attempts to disable a variety of Windows services so that their data can be encrypted. Various processes will also be targeted, such as web browsers and software related to security, backups, and databases. Shadow copies are cleared by the ransomware, and encryption of files occurs once the system has been prepared in this way. Executable files and those that are likely to be important for the system to continue to function appear to be skipped by the ransomware, and a large number of folders mostly related to Microsoft Windows system files are also ignored. As of March 2020, encrypted files have been observed with the added extensions of .key and .pwnd. Ransom notes are dropped in folders where encrypted files are found and also on the user's desktop.
Infra: 🔗 msaoyrayohnp32tcgwca
RSLUpdated: N/A
View profile →
APT GROUPfinancial
IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial services organizations in the US, Croatia, and Indonesia by exploiting exposed perimeter services such as firewalls and VPNs, claiming at least five victims.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 qvo5sd7p5yazwbrgioky
RSLUpdated: N/A
View profile →