🔒 Ransomware theater
Follows ransomware-as-a-service brands, affiliates, and extortion campaigns encrypting and leaking victim data. Prioritized for its operational and economic impact on critical services.
Live indicators
3.7K
in this theater
High severity
0
score ≥ 0.75 (top 60)
Actors tracked
8
documented
Mapped sources
2
in catalog
🏹 Threat Actors
🦠 Malware & Tools
🛡 Exploited Vulnerabilities
| CVE | Vendor / Product | Ransomware | Malware |
|---|---|---|---|
| CVE-2026-15409 | SonicWall SMA1000 Appliances | KNOWN | ransomware (KEV-flagged) |
| CVE-2026-15410 | SonicWall SMA1000 Appliances | KNOWN | ransomware (KEV-flagged) |
| CVE-2026-12569 | PTC Windchill and FlexPLM | KNOWN | ransomware (KEV-flagged) |
| CVE-2026-35273 | Oracle PeopleSoft Enterprise Peo | KNOWN | ransomware (KEV-flagged) |
| CVE-2026-50751 | Check Point Security Gateway | KNOWN | ransomware (KEV-flagged) |
| CVE-2026-0257 | Palo Alto Networks PAN-OS | KNOWN | ransomware (KEV-flagged) |
| CVE-2026-45321 | TanStack TanStack | KNOWN | ransomware (KEV-flagged) |
| CVE-2026-48027 | Nx Nx Console | KNOWN | ransomware (KEV-flagged) |
| CVE-2026-41940 | WebPros cPanel & WHM and WP2 (Word | KNOWN | ransomware (KEV-flagged) |
| CVE-2024-1708 | ConnectWise ScreenConnect | KNOWN | ransomware (KEV-flagged) |
| CVE-2024-57726 | SimpleHelp SimpleHelp | KNOWN | ransomware (KEV-flagged) |
| CVE-2024-57728 | SimpleHelp SimpleHelp | KNOWN | ransomware (KEV-flagged) |
📚 Priority sources & datasets
🔄 Live Datasets & APIs (2 key-free · ingestible)
| Dataset / API | Format | Endpoint | |
|---|---|---|---|
| Ransomwhere export | json | https://api.ransomwhe.re/export | collect |
| Ransomwhere payments | json | https://api.ransomwhe.re/export | collect |
📜 Ransomware Playbook
- Monitor leak sites, StopRansomware alerts, and IR feeds for new ransomware activity and victims.
- Extract encryptor hashes, ransom notes, TOR negotiation portals, and payment wallets.
- Correlate the intrusion to an initial-access CVE or broker and the affiliate program used.
- Attribute to a RaaS brand or affiliate via encryptor lineage, note templates, and infrastructure.
- Publish a victim advisory with decryptor availability and mitigation guidance.
- Block indicators, trace ransom payments on-chain, and patch the exploited entry vector.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
🔗 Cross-domain pivots
🔄 Data Feeds & Datasets
| Feed | Category | Format | Status |
|---|---|---|---|
| Ransomware.live recentvictims | Ransomware | json | enabled |
| Ransomware.live recent victims | Ransomware | json | enabled |
| Ransomware.live groups | Ransomware Actors | json | enabled |
| Ransomware Abuse Domains | Ransomware | text | enabled |
| Ransomwhere | Ransomware | json | enabled |
| Maltrail ransomware | Ransomware | text | off |
| MISP Galaxy Ransomware | Ransomware Actors | json | off |
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron