Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters446 entities
APT GROUPfinancial
Marketo, launched in April 2021, is a data-theft extortion marketplace that steals and sells data to third parties or back to victims without encrypting files, applying aggressive pressure by emailing victims' competitors with sample data packs.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Ranzy Locker, Former known as ThunderX. The group hosting a data leak site in the darknet where they posting sensitive information of victims who do not pay the ransom. ThunderX was launched at the end of August 2020. Soon after launching, weaknesses were found in the code, that allowed decrypting the files that the malware encrypted. The group has fixed the code and publish a new version, then released it under the name Ranzy Locker. The Tor onion URL used by the Ranzy Leak site is the same as the one used by Ako Ransomware. The use of the same URL could indicate that both groups merged, or they are cooperating similarly to the Maze cartel.
Infra: 🔗 37rckgo66iydpvgpwve7
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 dzkxxcsbrg7bwnlwwer5
RSLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 restoredz4xpmuqr.oni
RSLUpdated: N/A
View profile →
APT GROUPfinancial
settra — tracked by MISP Galaxy (ransomware).
Infra: 🔗 settra5ldqwgtw5q7z5a📁 26z3gms2rshr2zzedxhw📁 ttfy4zmtiaywfkkmykpx+2 more
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
DarkRace is a ransomware variant that surfaced in mid-2023 sharing strong code similarities with LockBit, employing double-extortion via a dark web leak site, but remained a minor player with fewer than 15 posted victims in its first half-year.
Infra: 🔗 wkrlpub5k52rjigwxfm6
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
LockBit is one of the most prolific ransomware groups in history, operating as a full RaaS platform that at its peak accounted for an estimated 44% of all ransomware incidents globally in 2023, targeting virtually every sector worldwide through an affiliate model where developers maintain infrastructure and affiliates conduct intrusions.
Affiliates: LockBitSupp • Wazawaka • bassterlord
Infra: 🔗 lockbitkodidilol.oni💬 lockbitks2tvnmwk.oni
RLUpdated: N/A
View profile →
APT GROUPfinancial
Flocker (also linked to the FSociety brand) is a ransomware-as-a-service group active since 2023–2024, targeting Windows and Linux systems via phishing, compromised RDP, and exploit kits using a double extortion model, and observed collaborating with FunkSec.
RLUpdated: N/A
View profile →
APT GROUPfinancial
SHAOleaks is a low-profile data leak and extortion group with minimal public documentation, operating a leak site but lacking detailed analysis by major threat intelligence firms, suggesting a very limited or short-lived operation.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Ransom Cartel is a ransomware-as-a-service operation that surfaced in December 2021, assessed by Palo Alto Unit 42 to share source code and technical overlap with the defunct REvil group, suggesting its operators had prior access to REvil's codebase, conducting double-extortion attacks against corporate networks.
Infra: 🔗 u67aylig7i6l657wxmp2🔗 cartelraqonekult2cxb
RLUpdated: N/A
View profile →
APT GROUPfinancial
FreeCivilian is a data extortion group with suspected ties to Russian GRU military intelligence, known for targeting Ukrainian government websites — including sites offering surrender guidance to Russian troops — blending cybercrime with apparent state-aligned political objectives.
Infra: 🔗 gcbejm2rcjftouqbxuhi
RLUpdated: N/A
View profile →
APT GROUPfinancial
Sicarii is a pro-Israeli/Jewish-branded ransomware-as-a-service operation that emerged in late 2025, explicitly targeting Arab and Muslim-majority organizations while avoiding Israeli systems, exploiting exposed RDP services and Fortinet devices, with its admin later instructing operators to migrate to the BQTLock platform.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 kelvinsecteamcyber.w
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Radiant is a financially motivated ransomware group that emerged in September 2025, conducting double- and single-extortion attacks without affiliates, drawing widespread condemnation after attacking UK childcare provider Kido International and publishing photographs, names, and home addresses of over 8,000 children.
RLUpdated: N/A
View profile →
APT GROUPfinancial
New possible leak site posted to a forum on November 20th, 2022, no victims at present. Unclear if its for a ransomware or extortion group
Infra: 🔗 hkk62og3s2tce2gipcdx
RLUpdated: N/A
View profile →
APT GROUPfinancial
ZeroTolerance is a low-profile ransomware group tracked on monitoring platforms with no detailed threat actor profiles, technical analysis, or named victim reports published by major threat intelligence vendors.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Cryp70n1c0d3 is a low-profile ransomware group with limited public documentation; specific targets, attack methodology, and operational model remain poorly documented in open sources.
Infra: 🔗 7k4yyskpz3rxq5nyokf6
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Cloak is a ransomware-as-a-service operation active since late 2022, primarily targeting small-to-medium enterprises in Europe — especially Germany — across manufacturing, healthcare, education, and government sectors, with expansion into North American and Asian targets by 2025.
Infra: 🔗 cloak7jpvcb73rtx2ff7💬 6mw4yczxeqoiq7rgwnpi💬 7puvv4qtcrigzbxshqib+36 more
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 gammax6w3dkfdjfrjtht
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Launched on April 24th, 2025 RansomBay is a new project operating under the DragonForce initiative
Infra: 🔗 rrrbay3nf4c2wxmhprc6💬 rrrbayguhgtgxrdg5myx📁 rrrbaygxp3f2qtgvfqk6
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Nasir Security is a pro-Iranian threat actor that emerged around October 2025, primarily targeting energy sector organizations in the Middle East (UAE, Oman, Saudi Arabia, Iraq) and Israeli IT supply chain firms, using spear-phishing, BEC, and exploitation of public-facing applications.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Trinity ransomware was first discovered in May 2024, believed to be a rebrand of the Venus/2023Lock variants, using ChaCha20 encryption and double-extortion via a Tor leak site; the US HHS flagged it as a specific threat to the healthcare sector after confirmed attacks on healthcare organizations.
Infra: 🔗 txtggyng5euqkyzl2knb🔗 txtggyng5euqkyzl2knb
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
⚠️ The group appears unreliable. Most, if not all, of its alleged victims cannot be verified. WE HAVE DECIDED TO REMOVE ENTRIES FOR THIS GROUP
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
N3tw0rm ransomware group is linked to Iran by many security researchers especially for the fact that the group targeting only Israeli companies. Like other ransomware groups, N3tw0rm has a data leak site in the darknet. Due to the low ransom price the group requested and lack of response to negotiations, some security researchers believe that the N3tw0rm group's main goal is to be used for sowing chaos for Israeli interests and not for profit.
Infra: 🔗 n3twormruynhn3oetmxv
RLUpdated: N/A
View profile →
APT GROUPfinancial
VECT is a RaaS group that launched its affiliate program in December 2025 with a five-tier revenue-sharing model and a formal partnership with BreachForums; its VECT 2.0 payload contains a critical encryption flaw that irreversibly destroys files larger than 128 KB rather than encrypting them.
Infra: 🔗 bu7zr6fotni3qxxoxlcm🔗 158.94.210.11.🔗 vectordntlcrlmfkcm4a
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Donut Leaks (D0nut) is a data-extortion group active since August 2022 that developed its own ransomware encryptor, linked to attacks on Greece's DESFA gas company and Continental, believed to be an affiliate of multiple RaaS operations who pivoted to running an independent extortion platform.
Infra: 🔗 sbc2zv2qnz5vubwtx3ao📁 doq32rjiuomfghm5a4ly🔗 sbc2zv2qnz5vubwtx3ao+4 more
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Affiliates: Wazawaka
Infra: 🔗 nq4zyac4ukl4tykmidbz
RSLUpdated: N/A
View profile →
Abrahams Ax
Technical ID: Abrahams_Ax
APT GROUPfinancial
Abraham's Ax is an Iranian-linked hacktivist persona tied to Moses Staff that emerged in November 2022, primarily targeting Saudi Arabian government institutions for geopolitical reasons related to Saudi-Israeli normalization, using destructive wiper malware and data leak tactics rather than financial ransomware.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Desolator is a ransomware group that emerged in May 2025, targeting construction and engineering firms in Latin America and Europe and technology companies in Asia, actively recruiting pen testers, initial access brokers, and social engineers via dark web forums to build an affiliate program.
Infra: 🔗 po4tq2brx4rgwbdx4mac
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Vice Society ransomware appends the .v-society extension when encrypting Linux machines. Running a leak site on the darkweb, Possible relations with "HelloKitty"
Infra: 🔗 4hzyuotli6maqa4u.oni🔗 vsociethok6sbprvevl4🔗 ml3mjpuhnmse4kjij7gg+5 more
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
The group appears unreliable. Most, if not all, of its alleged victims cannot be verified and appear to be randomly selected organizations. WE HAVE DECIDED TO REMOVE ENTRIES FOR THIS GROUP
Infra: 🔗 oaptxiyisljt2kv3we2w
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →