🏹 Threat Actor Profile
Unified dossier across APT, nation-state, ransomware & malware actors: aliases, MITRE ATT&CK, live leak-site victims, associated indicators & pivots.
Actors / Families in Local Intel
| Actor / Family | Associated indicators | |
|---|---|---|
| IP Blocklists | 444.8K | dossier → |
| Phishing | 125.8K | dossier → |
| Cryptocurrency | 98.4K | dossier → |
| Malware Domains | 59.3K | dossier → |
| Scam | 54.1K | dossier → |
| Domains/URLs | 49.9K | dossier → |
| Ransomware | 49.7K | dossier → |
| Malware URLs | 16.1K | dossier → |
| C2 Certificates | 10.3K | dossier → |
| Ransomware Actors | 9.3K | dossier → |
| Vulnerabilities | 7.9K | dossier → |
| Malware Attribution | 7.4K | dossier → |
| ATT&CK | 7.1K | dossier → |
| Threat Actors | 2.7K | dossier → |
| Sanctions | 2.4K | dossier → |
| APT/IoC | 2.3K | dossier → |
| Mobile ATT&CK | 1.5K | dossier → |
| Malware Hashes | 1.3K | dossier → |
| ICS ATT&CK | 804 | dossier → |
| C2 Attribution | 795 | dossier → |
| Malware Families | 433 | dossier → |
| Threat Reports | 379 | dossier → |
| CERT Advisories | 90 | dossier → |
| Aviation | 81 | dossier → |
| IP Reputation | 81 | dossier → |
| Environmental | 76 | dossier → |
| Court Cases | 47 | dossier → |
| Vuln Mapping | 13 | dossier → |
| ATT&CK Actors | 8 | dossier → |
| Adverse Media | 6 | dossier → |
| Nation State | 5 | dossier → |
| Tor | 1 | dossier → |
Tracked Ransomware Groups (Ransomware.live)
| Group | Description | |
|---|---|---|
| 0apt | The group appears unreliable. Most, if not all, of its alleged victims cannot be verified and appear to be randomly sele | dossier |
| 0day Syndicate | dossier | |
| 0mega | 0mega is a double-extortion ransomware group that emerged in May 2022, targeting businesses across multiple sectors worl | dossier |
| 8base | The 8base Ransomware group made its first appearance in early March 2022, remaining somewhat quiet after the attacks. Th | dossier |
| ALP-001 | ⚠️ The group appears unreliable. Most, if not all, of its alleged victims cannot be verified. WE HAVE DECIDED TO REMOVE | dossier |
| Abrahams_Ax | Abraham's Ax is an Iranian-linked hacktivist persona tied to Moses Staff that emerged in November 2022, primarily target | dossier |
| AiLock | AiLock is a ransomware operation that emerged in early 2025, marketing itself as AI-assisted ransomware using a hybrid C | dossier |
| Aptlock | dossier | |
| AuditTeam | AuditTeam is a small ransomware group with approximately 5 known victims, primarily targeting organizations in East and | dossier |
| Barracuda | dossier | |
| Black X | dossier | |
| Blackfield | dossier | |
| Booba Project | Booba | dossier |
| BrainCipher | Brain Cipher emerged in July 2024. Both Windows and Linux variants are available. Brain Cipher using the leaked build of | dossier |
| CMDOrganization | CMD is a new kind of company that specializes in corporate system security and in identifying vulnerabilities across all | dossier |
| CRPxO | CRPxO is actively recruiting affiliates, offering: 🔹 70% revenue share 🔹 XMR/BTC payouts 🔹 Claimed payouts within 24 hou | dossier |
| ContFR | RAAS - Ransomware intégré à un fichier PDF, à faire ouvrir à vos victimes ou à insérer vous-même, Windows et Mac, ne fon | dossier |
| D1R | D1R Claims Synopsys and Bosch Breaches, but Synopsys Disputes Intrusion | dossier |
| Dark Project | Dark Project is a newly emerged ransomware leak operation active as of August 2026. The group utilizes a double extortio | dossier |
| DarkMatter | dossier | |
| Deadlock | dossier | |
| Doommageddon | Direct Extortion Double Extortion | dossier |
| ElDorado | In September The El Dorado ransomware group have been rebrand as BlackLock | dossier |
| ExfilSquad | Only exfiltration | dossier |
| GDLockerSec | Our team members are from different countries and we are not interested in anything else, we are only interested in doll | dossier |
| Gammax | dossier | |
| Global Secret Group | dossier | |
| GodDamn ransomwhere | dossier | |
| IMNCrew | IMN Crew is a data extortion and ransomware group that emerged in late March 2025, primarily targeting financial service | dossier |
| Icarus | dossier | |
| J | J is an emerging ransomware group that launched its leak site in May 2025, claiming over 41 victims by late 2025 includi | dossier |
| LeakBazaar | dossier | |
| Loki | dossier | |
| NotPetya | dossier | |
| Orova | First seen 2026-07-07 | dossier |
| Panzer | dossier | |
| Payday | dossier | |
| PrinzEugen | dossier | |
| Redact | dossier | |
| RunSomeWares | RunSomeWares is an emerging ransomware group that surfaced in February 2025 with initial victims across supply-chain ser | dossier |
| Section9 | 🚨 This is a fake group with fake victims. | dossier |
| SenSayQ | SenSayQ is an emerging ransomware actor that appeared in mid-2024 using a leaked LockBit 3.0 builder for double-extortio | dossier |
| SevyWare | Direct Extortion Double Extortion | dossier |
| ShadowByt3$ | ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communic | dossier |
| Shiba | dossier | |
| ShinySp1d3r | Likely associated with the cybercrime group BlingLibra (ShinyHunters) | dossier |
| SilentRansomGroup | a former Conti team | dossier |
| The Green Blood Group | dossier | |
| The Syndicate | Data Broker | dossier |
| TiMc | TiMc is a ransomware group that emerged in early 2026, claiming high-impact attacks against Spanish IT services leader S | dossier |
| Tommyleaks | dossier | |
| Triple X | dossier | |
| ULose | dossier | |
| ValenciaLeaks | ValenciaLeaks is a data-extortion group that surfaced in August–September 2024, focused on exfiltrating large volumes of | dossier |
| VanHelsing | VanHelsing is a multi-platform RaaS operation that launched on March 7, 2025, requiring a $5,000 affiliate deposit and s | dossier |
| Wallstreet | dossier | |
| aGl0bGVyCg | "aGl0bGVyCg" (Base64 for "hitler") is a reference to the Hitler-Ransomware (2016), a German-origin proof-of-concept that | dossier |
| abyss | Abyss (also known as Abyss Locker) is a ransomware operation first identified in March 2023, derived from the Babuk sour | dossier |
| adminlocker | AdminLocker is a relatively low-profile ransomware strain first observed around December 2021, encrypting victim files a | dossier |
| againstthewest | AgainstTheWest (ATW) is a hacktivist group active since October 2021 that targets governments and corporations perceived | dossier |
| akira | The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the for | dossier |
| ako | A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker | dossier |
| alphalocker | AlphaLocker is a low-cost ransomware operation built on the EDA2 open-source project that sells affiliates an admin pane | dossier |
| alphv | The operators of the ALPHV/BlackCat ransomware began their activity in December 2021, making posts on Dark Web forums to | dossier |
| anubis | Anubis is a ransomware-as-a-service group active since December 2024 that targets healthcare, engineering, construction, | dossier |
| apos | Apos is a data-broker extortion group that surfaced in April 2024, focusing on data exfiltration and threatening to publ | dossier |
| apt73 | A new ransomware group is said to have emerged in mid-April 2024, under the name 'APT73.' It's worth noting that the gro | dossier |
| arcusmedia | Arcus Media is a ransomware-as-a-service group that emerged in May 2024, employing double extortion with ChaCha20 + RSA- | dossier |
| argonauts | Argonauts is a ransomware group that emerged in September 2024, operating a double-extortion model targeting logistics, | dossier |
| arkana | Arkana is a ransomware group that emerged in early 2025 and gained attention by claiming an attack on U.S. broadband pro | dossier |
| arvinclub | Arvin Club is a threat actor with hacktivist leanings that first appeared in May 2021, primarily publishing stolen data | dossier |
| atomsilo | AtomSilo is a double-extortion ransomware group that emerged in September 2021, exploiting the Atlassian Confluence vuln | dossier |
| aurora | Aurora is a ransomware group associated with a multi-purpose Go-based malware distributed by multiple criminal teams fro | dossier |
| avaddon | Avaddon is a ransomware malware targeting Windows systems often spread via malicious spam. The first known attack where | dossier |
| avos | Avos is the threat actor group behind AvosLocker ransomware, a RaaS operation active since June 2021 that recruited affi | dossier |
| avoslocker | AvosLocker is the ransomware payload of the Avos RaaS group, active from July 2021 to approximately May 2023, targeting | dossier |
| aware | Aware is a recently emerged ransomware group that operates a Tor-based data leak site with very limited public documenta | dossier |
| aztroteam | AztroTeam is a ransomware group with very limited public documentation and no confirmed victims, listed as offline on ra | dossier |
| babuk | Babuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most us | dossier |
| babuk2 | Babuk Locker 2.0, also known as Bjorka or SkyWave, after failing to make any profit from selling public databases on for | dossier |
| babyduck | BabyDuck is a ransomware group tracked on ransomware.live with approximately 180 claimed victims, appending the .babyduc | dossier |
| beast | Beast is a Ransomware-as-a-service (RaaS) product which provides functionality such as SMB scanning, file encryption, se | dossier |
| benzona | Benzona is a financially motivated ransomware group that emerged in late 2024, targeting small to mid-sized organization | dossier |
| bert | BERT is a newly emerged ransomware group first identified in mid-2025, targeting Windows and Linux platforms across heal | dossier |
| bianlian | BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a | dossier |
| blackbasta | "Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 | dossier |
| blackbyte | Ransomware. Uses dropper written in JavaScript to deploy a .NET payload. | dossier |
| blacklock | BlackLock is a rebranded version of another ransomware group known as Eldorado. It has since become one of the most acti | dossier |
| blackmatter | Ransomware-as-a-Service | dossier |
| blacknevas | BlackNevas is a ransomware group first observed in November 2024, believed to be derived from the Trigona ransomware fam | dossier |
| blackout | Blackout is a ransomware group that first appeared in early 2024, initially claiming attacks against healthcare entities | dossier |
| blackshadow | BlackShadow is an Iranian-linked hack-and-leak group (linked to the Agrius APT) that targeted Israeli companies includin | dossier |
| blackshrantac | BlackShrantac is a ransomware group that emerged in late 2025, targeting organizations in manufacturing, financial servi | dossier |
| blacksuit | According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware. | dossier |
| blacktor | Blacktor is a low-profile data breach and extortion group active around 2021 with a Tor-based leak site, claiming victim | dossier |
| blackwater | Blackwater is a ransomware group that first surfaced in early 2026, combining file encryption with data theft and target | dossier |
| bluebox | Bluebox is a data extortion group that emerged in December 2024, employing double-extortion tactics against victims prim | dossier |
| bluelocker | Blue Locker targets Pakistan’s vital energy sector, particularly Pakistan Petroleum | dossier |
| bluesky | BlueSky is a financially motivated ransomware group active from mid-2022 into early 2023, using multi-threaded ChaCha20/ | dossier |
| bonacigroup | Bonaci Group is a small, short-lived ransomware group that was active in 2021 with only 3 known victims before going off | dossier |
| bqtlock | BQTLock is a ransomware-as-a-service operation that emerged in 2025, using AES-256/RSA-4096 encryption with Monero payme | dossier |
| bravox | BravoX is a selective ransomware-as-a-service operation that surfaced publicly in January 2026 after advertising on the | dossier |
| brotherhood | Brotherhood is a ransomware group that emerged in late 2025, targeting organizations in the US, Canada, and Australia ac | dossier |
| cactus | The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities t | dossier |
| cephalus | Cephalus is a ransomware group active from mid-2025 that leverages stolen RDP credentials to deploy a Go-based ransomwar | dossier |
| chaos | Chaos is a ransomware-as-a-service operation that emerged in early 2025, likely formed by former BlackSuit/Royal members | dossier |
| cheers | Cheers is a Linux-based ransomware group that emerged in 2022, built on leaked Babuk source code and specializing in att | dossier |
| chilelocker | ChileLocker (also known as ARCrypter) first appeared in August 2022 after attacking a Chilean government agency and quic | dossier |
| chort | Chort is a double-extortion ransomware group (whose name means "Devil" in Russian) that emerged in October 2024, primari | dossier |
| cicada3301 | Cicada3301 is a ransomware-as-a-service group (tracked as Repellent Scorpius by Palo Alto) that emerged in mid-2024 usin | dossier |
| ciphbit | CiphBit is a ransomware-as-a-service group active since April 2023, targeting small-to-mid-sized businesses across the U | dossier |
| cipherforce | CipherForce is a newly emerged ransomware group first detected in early 2026, operating a dark web leak site and targeti | dossier |
| cloak | Cloak is a ransomware-as-a-service operation active since late 2022, primarily targeting small-to-medium enterprises in | dossier |
| clop | The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that t | dossier |
| coinbasecartel | CoinbaseCartel specializes in data acquisition through system access and strategic partnerships. It focus exclusively on | dossier |
| conti | Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It | dossier |
| cooming | CoomingProject is a ransomware group that emerged around 2021 and operated a double-extortion scheme with multiple Tor-b | dossier |
| crazyhunter | CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, ex | dossier |
| crosslock | CrossLock is a short-lived Go-based ransomware group that appeared in April 2023 and went dark by July 2023, using Curve | dossier |
| cry0 | Cry0 is a ransomware-as-a-service operation that recruits affiliates via underground forums, using a Rust-written payloa | dossier |
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron