Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters446 entities
APT GROUPfinancial
RAMP (Russian Anonymous Marketplace) was a Russian-speaking dark web forum founded in 2021 that served as a central marketplace and recruitment hub for ransomware operators, affiliates, and initial access brokers — not a ransomware group itself but the backbone of the RaaS ecosystem; it was seized by the FBI in January 2026.
Affiliates: LockBitSupp • Wazawaka
Infra: 🔗 wavbeudogz6byhnardd2🔗 rampjcdlqvgkoz5oywut🔗 ramp4u5iz4xx75vmt6nk+1 more
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 k7kzrgcoxsjm7fujj5vo
RSLUpdated: N/A
View profile →
la piovra
Technical ID: la_piovra
APT GROUPfinancial
ℹ️ La Piovra Ransomware is an exercise of the company Offensive Security (also known as OffSec)
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Bluebox is a data extortion group that emerged in December 2024, employing double-extortion tactics against victims primarily in France, Sweden, and the French Caribbean, and threatening to notify data protection authorities to add regulatory pressure on victims.
Infra: 🔗 zu3wfrmrkl4ltqqnpt3o
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 eraleignews.com🔗 wn6vonooq6fggjdgyocp🔗 basheqtvzqwz4vp6ks5l+12 more
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Sabbath (also known as 54BB47h, operated by UNC2190) is a ransomware group active from mid-2021 that emerged as a rebrand of the Arcane ransomware, targeting critical infrastructure in the US and Canada — particularly hospitals, schools, and natural resources — using double extortion, backup destruction, and affiliate recruitment on Russian-language dark web forums.
Infra: 🔗 54bb47h5qu4k7l4d7v5i🔗 54bb47h.blog
RLUpdated: N/A
View profile →
lockbit3 fs
Technical ID: lockbit3_fs
APT GROUPfinancial
LockBit 3.0 ("LockBit Black"), active since June 2022, is the third iteration of the LockBit RaaS platform incorporating code from BlackMatter ransomware, featuring modular encrypted payloads that evade analysis and targeting Windows and VMware ESXi environments across all sectors globally.
RLUpdated: N/A
View profile →
APT GROUPfinancial
LockBit 2.0 is the second major iteration of the LockBit RaaS platform, launched in mid-2021, introducing automated domain-wide encryption via Active Directory Group Policy and claiming the fastest encryption speed among ransomware families, accounting for 46% of ransomware breach events in early 2022.
RLUpdated: N/A
View profile →
APT GROUPfinancial
CMD is a new kind of company that specializes in corporate system security and in identifying vulnerabilities across all aspects of the software used by a company. CMD operates on a global scale recognizing the critical importance of timeliness and confidentiality.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victims in Indonesia, Italy, Venezuela, and the US, with minimal public threat-intelligence coverage.
Infra: 🔗 bl4cktorpms2gybrcyt5
RLUpdated: N/A
View profile →
APT GROUPfinancial
LV ransomware group main message: "Here are companies which didn't meet consumer data protection obligations. They rejected to fix their mistakes, they rejected to protect this data in the case when they could and had to ptotect it. These companies prefered to sell their private information, their employees' and customers' personal data". Security researchers claim that the LV group is utilizing the REvil ransomware group malware. The LV group claim to have compromised the corporate network of Groupe Reorev.
Infra: 🔗 rbvuetuneohce3ouxjlb🔗 4qbxi3i2oqmyzxsjg4fw💬 l55ysq5qjpin2vq23ul3
RLUpdated: N/A
View profile →
APT GROUPfinancial
Abyss (also known as Abyss Locker) is a ransomware operation first identified in March 2023, derived from the Babuk source code, that targets Windows and Linux/VMware ESXi systems using double-extortion tactics across healthcare, manufacturing, finance, and technology sectors — predominantly in North America.
RLUpdated: N/A
View profile →
APT GROUPfinancial
CiphBit is a ransomware-as-a-service group active since April 2023, targeting small-to-mid-sized businesses across the UK, Europe, and North America with 38 known victims, employing a data-broker model with selective free leaks to pressure victims alongside standard double extortion.
Infra: 🔗 ciphbitqyg26jor7eeo6💬 sonarmsng5vzwqezlvtu💬 ciphbitekvxj27jmtw5s
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Booba
RLUpdated: N/A
View profile →
APT GROUPfinancial
LostTrust is a double-extortion ransomware operation that emerged in March 2023 and publicized over 50 victims within days of launching its leak site in September 2023, believed to be a rebrand of the MetaEncryptor gang, primarily targeting manufacturing, professional services, construction, and education sectors with 71% of known victims in the US.
Infra: 🔗 hscr6cjzhgoybibuzn2x
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
MyDecryptor is a low-profile ransomware group with minimal public documentation, appearing on ransomware tracking platforms but not the subject of major threat intelligence reporting, suggesting it is a small or relatively inactive operation.
Infra: 🔗 5s4ixqul2enwxrqv.oni
RLUpdated: N/A
View profile →
APT GROUPfinancial
Crypto24 is a double-extortion ransomware-as-a-service group that surfaced on the RAMP forum in mid-2024, targeting large organizations in financial services, healthcare, manufacturing, and technology across Asia, Europe, and North America, with notable victims including CMC Group, Vietnam's second-largest ICT conglomerate.
Infra: 🔗 j5o5y2feotmhvr7cbcp2🔗 j5o5y2feotmhvr7cbcp2
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
CryLock (originally known as Cryakl/Fantomas since 2014) is a ransomware operation run by a Russian couple who targeted roughly 400,000 victims over eight years and earned over €64 million in Bitcoin; the operators were arrested in Spain in June 2023 and extradited to Belgium.
Infra: 🔗 d57uremugxjrafyg.oni
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 zhuobnfsddn2myfxxdqt
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Shadow is a low-profile ransomware group tracked on ransomware monitoring platforms with limited public documentation; specific attribution details regarding its targets, origin, or scale remain sparse in published threat intelligence reports.
Infra: 🔗 lc65fb3wrvox6xlyn4hk
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 💬 yboa7nidpv5jdtumgfm4
RSLUpdated: N/A
View profile →
APT GROUPfinancial
Arcus Media is a ransomware-as-a-service group that emerged in May 2024, employing double extortion with ChaCha20 + RSA-2048 encryption and recruiting affiliates via a referral-based vetting process, claiming 50+ victims across manufacturing, healthcare, retail, and business services globally.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Argonauts is a ransomware group that emerged in September 2024, operating a double-extortion model targeting logistics, healthcare, energy, and telecom sectors, with approximately 13 claimed victims tracked via a TOR-based leak site.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support for Windows, Linux, ESXi, and NAS device encryption, and became notable for a public feud with rival group 0APT in which each breached and leaked the other's operator data.
Infra: 🔗 krybitxdpxohsmjooeb3🔗 krybitx3fh5krdnhegyp🔗 krybitqsdzwmhnitvwuh+1 more
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
RSLUpdated: N/A
View profile →
APT GROUPfinancial
VFOKX is a low-profile ransomware group tracked on ransomware monitoring platforms with very limited public documentation and no detailed analysis or named victims published by major threat intelligence vendors.
Infra: 🔗 vfokxcdzjbpehgit223v🔗 746pbrxl7acvrlhzshos
RLUpdated: N/A
View profile →
APT GROUPfinancial
RA Group, also known as RA World, first surfaced in April 2023, utilizing a custom variant of the Babuk ransomware.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather than a broad affiliate program.
Infra: 🔗 direwolfcdkv5whaz2sp📁 direwolfgpyqohwxwoet💬 direwolf66s5zealav7a
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Orca is a ransomware group that emerged in September 2024, identified as a variant of the Zeppelin malware family, targeting organizations in manufacturing and logistics across Taiwan, Tunisia, Austria, and France, claiming to avoid hospitals, government institutions, and non-profits.
Infra: 🔗 orca66hwnpciepupe562
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
AgainstTheWest (ATW) is a hacktivist group active since October 2021 that targets governments and corporations perceived as authoritarian, breaching organizations like Alibaba, Sberbank, and Gazprom using custom ransomware and wiper malware for ideological disruption rather than financial profit.
RLUpdated: N/A
View profile →
APT GROUPfinancial
No detailed intelligence profile available.
Infra: 🔗 monteoamwxlutyovf7ox🔗 monteoamwxlutyovf7ox
RSLUpdated: N/A
View profile →
APT GROUPfinancial
WALocker is an emerging ransomware group that came to attention in 2025, targeting organizations in Southeast Asia and government entities, with a notable attack breaching Myanmar's Union Civil Service Board and exposing data on approximately 200,000 government officials.
Infra: 🔗 weepangrbqjfsxd2noz4📁 am7hswbi46e3ozxec3ms
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
WereWolves is a Russian-speaking ransomware group that emerged in May 2023, using a modified LockBit 3 (Black) encryptor, operating an unusual public website that actively recruits new members and offers a bug-bounty program with rewards up to $1 million, with at least 26 victims across Russia, the US, and Europe.
Infra: 🔗 werewolves.pro🔗 weerwolven.biz.
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
World Leaks emerged in January 2025 as a rebrand of the Hunters International ransomware operation, shifting its focus from file encryption to solely stealing sensitive data and threatening to leak it unless a ransom is paid
Infra: 🔗 worldleaksartrjm3c6v
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Unlike many other groups, Silent claims to operate with a high level of anonymity and discretion. According to their own statement, they avoid public negotiations and encrypt minimal data. Instead, their focus is on stealing valuable confidential corporate information — and either selling it to competitors, on the dark web, or publishing it selectively.
Infra: 🔗 silentbgdghp3zeldwpu📁 jf2zjpxfh3sob5xr6uc5
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Ranstreet is a low-profile ransomware group with very limited public documentation, appearing in ransomware tracking lists but without major vendor research reports or significant attributed attacks.
RLUpdated: N/A
View profile →
APT GROUPfinancial
NightSpire is a ransomware group that first emerged in March 2025 and rapidly claimed over 250 victims across retail, manufacturing, healthcare, finance, and education sectors in the US, France, India, Taiwan, and Japan, using aggressive double-extortion with ransom deadlines as short as two days.
Affiliates: Phantom • Reaper • Volt • Blaze +2
Infra: 🔗 nspireyzmvapgiwgtuoz🔗 nspireyzmvapgiwgtuoz🔗 a2lyiiaq4n74tlgz4fk3+5 more
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
Weyhro is a data-extortion group (relying on data theft and leak threats without file encryption) that launched a Tor leak site in March 2025, focusing on manufacturing, financial services, and real estate sectors with victims in the US, Italy, and Canada.
Infra: 🔗 xtxtpqpyaaek4p4525ks📁 p7teg7yh2dwxg2tsbgnk📁 p7teg7yh2dwxg2tsbgnk+2 more
RLUpdated: 2026-08-04
View profile →