Threat Theaters

🔒 Ransomware theater

Follows ransomware-as-a-service brands, affiliates, and extortion campaigns encrypting and leaking victim data. Prioritized for its operational and economic impact on critical services.

Live indicators

3.7K
in this theater

High severity

0
score ≥ 0.75 (top 60)

Actors tracked

8
documented

Mapped sources

2
in catalog

🛡 Exploited Vulnerabilities

CVEVendor / ProductRansomwareMalware
CVE-2026-15409SonicWall SMA1000 AppliancesKNOWNransomware (KEV-flagged)
CVE-2026-15410SonicWall SMA1000 AppliancesKNOWNransomware (KEV-flagged)
CVE-2026-12569PTC Windchill and FlexPLMKNOWNransomware (KEV-flagged)
CVE-2026-35273Oracle PeopleSoft Enterprise PeoKNOWNransomware (KEV-flagged)
CVE-2026-50751Check Point Security GatewayKNOWNransomware (KEV-flagged)
CVE-2026-0257Palo Alto Networks PAN-OSKNOWNransomware (KEV-flagged)
CVE-2026-45321TanStack TanStackKNOWNransomware (KEV-flagged)
CVE-2026-48027Nx Nx ConsoleKNOWNransomware (KEV-flagged)
CVE-2026-41940WebPros cPanel & WHM and WP2 (WordKNOWNransomware (KEV-flagged)
CVE-2024-1708ConnectWise ScreenConnectKNOWNransomware (KEV-flagged)
CVE-2024-57726SimpleHelp SimpleHelpKNOWNransomware (KEV-flagged)
CVE-2024-57728SimpleHelp SimpleHelpKNOWNransomware (KEV-flagged)

🧭 Intelligence disciplines

CYBINT →FININT →OSINT →

📜 Ransomware Playbook

  1. Monitor leak sites, StopRansomware alerts, and IR feeds for new ransomware activity and victims.
  2. Extract encryptor hashes, ransom notes, TOR negotiation portals, and payment wallets.
  3. Correlate the intrusion to an initial-access CVE or broker and the affiliate program used.
  4. Attribute to a RaaS brand or affiliate via encryptor lineage, note templates, and infrastructure.
  5. Publish a victim advisory with decryptor availability and mitigation guidance.
  6. Block indicators, trace ransom payments on-chain, and patch the exploited entry vector.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🔄 Data Feeds & Datasets

FeedCategoryFormatStatus
Ransomware.live recentvictimsRansomwarejsonenabled
Ransomware.live recent victimsRansomwarejsonenabled
Ransomware.live groupsRansomware Actorsjsonenabled
Ransomware Abuse DomainsRansomwaretextenabled
RansomwhereRansomwarejsonenabled
Maltrail ransomwareRansomwaretextoff
MISP Galaxy RansomwareRansomware Actorsjsonoff
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php