Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters712 entities
APT GROUPfinancial
Icarus is a modular stealer software, written in .NET. One module is the open source r77 rootkit.
APT GROUPfinancial
FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration of cloud-hosted databases by exploiting unrotated API keys and misconfigured cloud permissions rather than deploying encryption, with known victims including Australian fintech youX and LexisNexis.
Infra: 🔗 gsgot6tua7ffammwdv6v…🔗 fulcrumsec.net…🔗 4e3p3in2bl67hxchuwza…+2 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
MetaEncryptor is a ransomware group first observed in mid-2023, targeting medium-to-large enterprises in legal, technology, logistics, manufacturing, and finance sectors primarily in the UK, Europe, and Southeast Asia, using AES-256/RSA-2048 encryption and double extortion.
Infra: 🔗 metacrptmytukkj7ajwj…🔗 metacrpttdfpbm4qoxzc…
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and agriculture sectors, claiming 12 victims across seven countries within hours of launching its leak site.
Infra: 🔗 payloadrz5yw227brtbv…💬 payloadynyvabjacbun4…📁 payload6eualw6kni6v2…
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Karma is a ransomware group first observed in mid-2021, part of a lineage tracing back through Nefilim and FiveHands, operating double-extortion attacks against enterprises in healthcare, manufacturing, and technology; the group was managed by threat actor "farnetwork" who ran multiple RaaS programs across related strains.
Platforms: Windows and Linux
Infra: 🔗 3nvzqyo6l4wkrzumzu5a…
T1123T1566T1125
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Lamashtu is an extortion group that first appeared in April 2026, claiming attacks against organizations in France, Romania, and Thailand across energy, pharmaceutical, and film sectors; it has not yet been confirmed as operating actual file-encrypting ransomware rather than pure data-theft extortion.
Infra: 🔗 lamashtux5j74mcm7lww…🔗 lamashtux5j74mcm7lww…
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
killada — tracked by MISP Galaxy (ransomware).
Infra: 💬 killadaayyuzdshwskrn…💬 killadaxczzw3wnuaxky…💬 killadax36r6bbb3md67…+3 more
APT GROUPfinancial
CoinbaseCartel specializes in data acquisition through system access and strategic partnerships. It focus exclusively on data exfiltration—our operations never involve system encryption or operational disruption.
RLUpdated: N/A
View profile →APT GROUPfinancial
Reynolds is a ransomware family first identified in early 2026, notable for embedding BYOVD (Bring Your Own Vulnerable Driver) defense evasion by exploiting CVE-2025-68947 to terminate security software before encrypting files, initially attributed to Black Basta and considered attractive to RaaS affiliates.
Infra: 🔗 bs2tlg32pfjwmclm22cy…
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
According to PCrisk, Yanluowang is ransomware that encrypts (and renames) files, ends all running processes, stops services, and creates the README.txt file containing a ransom note. It appends the .yanluowang extension to filenames. Cybercriminals behind Yanluowang are targeting enterprise entities and organizations in the financial sector.Files encrypted by Yanluowang can be decrypted with this tool (it is possible to decrypt all files if the original file is larger than 3GB. If the original file is smaller than 3GB, then only smaller files can be decrypted).
Infra: 🔗 jukswsxbh3jsxuddvidr…
RLUpdated: N/A
View profile →APT GROUPfinancial
The Warlock ransomware and operator(s) are believed to be attributed to Storm-2603, a China-based threat actor who is also known to have deployed LockBit ransomware. There's also a crossover between victims with Black Basta. Both are RaaS and have a long list of known and unknown affiliates. Having said that, this is possibly an affiliate (likely a cybergroup) of both of those groups. The Alliance & Association would technically be Encryptor Sharing, but this is realistically more of an "Old Affiliate" that created their own ransomware encryptor and operation.
Infra: 🔗 elqfbcx5nofwtqfookqm…🔗 zfytizegsze6uiswodhb…📁 ocwjy4ynmpbbzhumh2am…+7 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Ransomware, which appears to be a rebranding of win.cuba.
RLUpdated: N/A
View profile →APT GROUPfinancial
VanHelsing is a multi-platform RaaS operation that launched on March 7, 2025, requiring a $5,000 affiliate deposit and splitting ransoms 80/20, supporting Windows, Linux, BSD, ARM, and ESXi targets, reaching at least five victims across the US, France, Italy, and Australia within its first two months.
APT GROUPfinancial
According to PCrisk, Trigona is ransomware that encrypts files and appends the ._locked extension to filenames. Also, it drops the how_to_decrypt.hta file that opens a ransom note. An example of how Trigona renames files: it renames 1.jpg to 1.jpg._locked, 2.png to 2.png._locked, and so forth.It embeds the encrypted decryption key, the campaign ID, and the victim ID in the encrypted files.
Affiliates: Wazawaka
Infra: 🔗 6n5tfadusp4sarzuxntz…🔗 trigonax2zb3fw34rbaa…🔗 trigonax2zb3fw34rbaa…+7 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
thunder x — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Termite is a ransomware group first identified in late 2024 using a modified version of Babuk ransomware code; its most notable attack was the November 2024 breach of supply-chain software firm Blue Yonder, claiming 680 GB of exfiltrated data and disrupting major customers including Starbucks.
Infra: 🔗 termiteuslbumdge2zmf…📁 pqw3hepvky2pgyyv6dup…📁 4xklh64cl2lymm6n5xyw…+2 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
targetcompany — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
SynAck is a sophisticated ransomware operation first spotted in 2017, known for using hybrid ECIES encryption and the Doppelganging process injection technique to evade detection; in August 2021 the group rebranded as El_Cometa, transitioning to a full RaaS model and releasing master decryption keys for prior victims.
Infra: 🔗 xqkz2rmrqkeqf6sjbrb4…
RLUpdated: N/A
View profile →APT GROUPfinancial
SunCrypt is a RaaS operation first observed in October 2019, notable for pioneering triple extortion (encryption, data publication threats, and DDoS attacks on non-paying victims), operating a closed small affiliate program and partnering with TrickBot for initial access.
Infra: 🔗 x2miyuiwpib2imjr5yky…🔗 nbzzb6sa6xuura2z.oni…
RLUpdated: N/A
View profile →APT GROUPfinancial
Ransomware, written in Delphi.
Infra: 💬 chat5sqrnzqewampznyb…🔗 sugarpanel.space…
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Ransomware, written in .NET.
Infra: 🔗 solidb2jco63vbhx4sfi…
RLUpdated: N/A
View profile →APT GROUPfinancial
Snatch is a ransomware which infects victims by rebooting the PC into Safe Mode. Most of the existing security protections do not run in Safe Mode so that it the malware can act without expected countermeasures and it can encrypt as many files as it finds. It uses common packers such as UPX to hide its payload.
Infra: 🔗 hl66646wtlp2naoqnhat…🔗 snatch.press…🔗 snatchteam.cc…+8 more
RLUpdated: N/A
View profile →APT GROUPfinancial
slam — tracked by MISP Galaxy (ransomware).
Infra: 💬 encr9djfOJdew92nfjK9…💬 encrKdm13nfKJNdwf7kd…💬 encr5RhdkjNNJdwq62df…+2 more
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Sarcoma is a ransomware group that debuted in October 2024, immediately ranking among the top three most active groups globally and surpassing 116 documented victims by mid-2025, targeting mid-market companies across manufacturing, retail, healthcare, legal, and business services with roughly 50% of victims in the United States.
Infra: 🔗 sarcomawmawlhov7o5md…📁 bi32pq7y3gqq3qacgvam…📁 54yjkjwjqbm74nchm6o6…+126 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.
Infra: 🔗 nj5qix45sxnl4h4og6hc…🔗 nz4z6ruzcekriti5cjji…📁 qkzxzeabulbbaevqkoy2…+10 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
rtm locker — tracked by MISP Galaxy (ransomware).
Infra: 🔗 nv4addu4insb7x6aagdv…💬 3wugtklp46ufx7dnr6j5…💬 nvfutdbq3ubteaxj4m2j…
RSLUpdated: 2026-08-03
View profile →APT GROUPfinancial
According to PCrisk, Rook is ransomware (an updated variant of Babuk) that prevents victims from accessing/opening files by encrypting them. It also modifies filenames and creates a text file/ransom note (HowToRestoreYourFiles.txt). Rook renames files by appending the .Rook extension. For example, it renames 1.jpg to 1.jpg.Rook, 2.jpg to 2.jpg.Rook.
Infra: 🔗 gamol6n6p2p4c3ad7gxm…
RLUpdated: N/A
View profile →APT GROUPfinancial
RobbinHood is a ransomware group first observed in April–May 2019, responsible for high-profile attacks on US cities including Baltimore, Maryland — demanding 13 BTC and causing months of disruption to city services — believed to operate as a limited closed-circle model rather than a broad public affiliate program.
Infra: 🔗 robinhoodleaks.tumbl…
RLUpdated: N/A
View profile →APT GROUPfinancial
Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads.<br> <br> The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development.<br> <br> The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin.<br> <br> After encryption, the ransomware appends the extension '.ryshida' to encrypted files.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 rhysidafohrhyy2aszi7…🔗 rhysidafohrhyy2aszi7…🔗 rhysidafohrhyy2aszi7…+4 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
Sodinokibi ransomware group also known as REvil (Ransomware Evil) operates as a ransomware-as-a-service (RaaS) model. After the group compromised his victims, they would threaten to publish the victim's sensitive data on their darknet blog named 'Happy Blog', unless the ransom is paid. The ransomware malware code used by REvil is pretty similar to the ransomware code used by DarkSide - a different threat actor. REvil group claims to steal information after a successful attack on the supplier of the tech giant Apple and stole confidential schematics of their upcoming products.
Infra: 🔗 dnpscnbaix6nkwvystl3…💬 aplebzu47wgazapdqks6…🔗 blogxxu75w63ujqarv47…+7 more
RLUpdated: N/A
View profile →APT GROUPfinancial
RedAlert (also called N13V) is a ransomware group first observed in July 2022 that targets both Windows and Linux VMware ESXi servers, encrypting virtual machine files using the NTRUEncrypt algorithm and accepting only Monero for payment, conducting double-extortion attacks against corporate networks.
Infra: 🔗 blog2hkbm6gogpv2b3uy…📁 qrcxhs4x2n4a65rk3zbw…📁 ocsmkribkmoij3uhvhxl…+2 more
RLUpdated: N/A
View profile →APT GROUPfinancial
The group emerged in mid-February 2024 and has already listed several organizations as alleged victims of their attacks, resulting from extortion through encryption and data leaks.<br> <br> The announcement of the sale of the new Ransomware-as-a-Service (RaaS) by RansomHub was published on one of the Russian-origin forums used by cybercrime to advertise malicious services, known as RAMP4U (or RAMP). A user with the nickname and persona of 'koley' announced the affiliate program on February 2, 2024.<br> <br> In the new RaaS announcement, it was mentioned that the money laundering operation of the paid ransoms is the responsibility of the affiliate. This means that all communication and sending of the decryptor to the victim are done through chat. The split of this RaaS would be 90% of the value for the affiliate and 10% for the developer, who in this case would be the persona of Koley.<br> <br> Furthermore, according to the publication, the ransomware payload is written in Golang language, uses the asymmetric algorithm based on x25519, and encryption algorithms AES256, ChaCha20, and xChaCha20, standing out for its speed. The encryption is obfuscated using AST.<br> <br> The payload would support network propagation and encryption of data both in secure and local mode. According to Koley, the ransomware is designed to operate on platforms such as Windows, Linux, and ESXi, as well as other architectures such as ARM and MIPS.<br> <br> As pointed out by the panel and already highlighted by the intelligence team, Koley stated that the panel uses a .onion domain, allowing the affiliate to organize and manage targets and chat rooms, view access logs, automatically respond when offline, and create private blog pages.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 ransomxifxwc5eteopdo…📁 mjmru3yz65o5szsp4rmk…📁 an2ce4pqpf2ipvba2dju…+43 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777.
Infra: 🔗 rnsm777cdsjrsdlbs4v5…🔗 zubllg7o774lgc4rdxmf…💬 jbdg4buq6jd7ed3rd6cy…+1 more
RLUpdated: N/A
View profile →APT GROUPfinancial
Ranion is a ransomware-as-a-service operation first observed in April 2017 that offers a low-barrier, pay-upfront model where affiliates keep 100% of ransom payments, with packages ranging from $150 to $1,900, making it a popular entry point for less experienced attackers.
Infra: 🔗 ranionv3j2o7wrn3um6d…🔗 ssg3qvvuilseciagm4ni…
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
RALord is a ransomware group identified in March 2025 operating within the NOVA RaaS platform, targeting healthcare, education, hospitality, and IT sectors across multiple continents, using a Rust-based payload with an 85/15 affiliate revenue split; it later rebranded as "Nova."
Infra: 🔗 ralordqe33mpufkpsr6z…🔗 ralord3htj7v2dkavss2…🔗 ralordt7gywtkkkkq2su…+1 more
RLUpdated: 2026-08-03
View profile →APT GROUPfinancial
According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes Russian and Chinese targets using the system's Language ID for filtering. It also tries to disable Windows Defender and has a number of UNIX filepath references in its strings. Encryption method is AES using a dynamically generated key, then bundling this key up via RSA.
Infra: 🔗 wobpitin77vdsdiswr43…🔗 sushlnty2j7qdzy64qnv…
RLUpdated: N/A
View profile →APT GROUPfinancial
Ragnar Locker was an elite ransomware group active from December 2019 to October 2023 that targeted large enterprises and critical infrastructure — including Capcom and Campari — claiming at least 168 victims before being taken down by a Europol-led international law enforcement operation in October 2023.
Infra: 🔗 rgleak7op734elep.oni…🔗 rgleaktxuey67yrgspmh…📁 p6o7m73ujalhgkiv.oni…+7 more
RLUpdated: N/A
View profile →APT GROUPfinancial
First known AI-powered ransomware. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly
RLUpdated: N/A
View profile →APT GROUPfinancial
Ransomware written in .NET, apparently derived from the codebase of win.hakbit (Thanos) ransomware.
Infra: 🔗 promethw27cbrcot.oni…💬 promethw27cbrcot.oni…
RLUpdated: N/A
View profile →