All APT (189) Breach & Campaigns (7) Exploit Kits (3) MITRE ATT&CK (40) Malware (119) Platform-Specific (11) Ransomware (307) Tools & Frameworks (25) 701 of 701 threats
Ransomware
Emerging ransomware variant targeting enterprise environments
Tools & Frameworks
Modern open-source C2 framework
Malware
Cross-platform Java RAT
Malware
Premium .NET keylogger and stealer
Executive briefing on Akira ransomware, a Conti syndicate successor responsible for over $42 million in damages across 250+ organizations in its first year.
Malware
Lightweight loader and reconnaissance bot
Malware
Japanese-themed loader
Malware
Weaponized remote admin tool
Open-source Android RAT
Platform-Specific
Android banking trojan
Platform-Specific
Android banking trojan
Platform-Specific
Android banking trojan
Analysis of emerging Android threats
Platform-Specific
Android banking trojan
Platform-Specific
Android remote code execution malware
Platform-Specific
Android surveillance RAT
Chinese state-linked group conducting dual espionage and financial cybercrime operations, notorious for supply chain compromises and the ShadowPad backdoor.
Long-running Chinese APT using the custom Bisonal RAT to target military and government organizations across East Asia and Eastern Europe.
South Asian APT targeting government and military organizations in Pakistan, Bangladesh, and China with custom downloaders and RATs via spearphishing.
Iranian IRGC-affiliated APT conducting sophisticated social engineering and credential harvesting campaigns against academics, journalists, and government officials worldwide.
Advanced APT targeting Southeast Asian governments with rootkit-level persistence, kernel-mode implants, and cloud-based exfiltration via Dropbox and OneDrive.
Russian FSB-linked APT from occupied Crimea conducting high-volume, persistent espionage operations against Ukrainian government and military organizations.
Highly sophisticated Chinese APT deploying kernel-level rootkits and advanced anti-forensic techniques to maintain persistent access in telecom and government networks.
Financially motivated APT targeting fintech and cryptocurrency companies using the Golden Chickens MaaS suite and custom JavaScript malware.
North Korean intelligence-gathering APT specializing in social engineering against South Korean policy experts, defectors, and academics with credential harvesting and custom backdoors.
North Korea's most prolific APT group, responsible for the Sony hack, WannaCry, Bangladesh Bank heist, and billions in cryptocurrency theft to fund the DPRK weapons program.
Chinese APT targeting Southeast Asian government and military organizations with custom backdoors, leveraging diplomatic-themed lures and strategic watering hole attacks.
Chinese-linked APT conducting targeted espionage campaigns against Tibetan activists, Japanese aerospace entities, and Indian military organizations.
China MSS-affiliated APT targeting managed service providers to pivot into client networks, conducting massive intellectual property theft across defense, healthcare, and aerospace sectors.
Iranian MOIS-subordinate APT conducting espionage across the Middle East using custom C2 frameworks, heavy PowerShell usage, and living-off-the-land techniques.
Chinese APT targeting European and Asian government organizations and NGOs with PlugX variants and custom backdoors via USB propagation and spearphishing.
North Korean APT conducting dual espionage and ransomware operations against defense, energy, and healthcare sectors using custom implants and opportunistic vulnerability exploitation.
Indian-linked APT targeting Pakistan and China with copy-paste code from multiple sources, known for occasionally infecting their own systems with their own malware.
Lebanon-based, Iran-backed APT exclusively targeting Israeli organizations using OneDrive for C2 and a suite of custom 'Creepy' implants.
Chinese APT targeting ASEAN government ministries using the RoyalRoad RTF weaponizer and custom Soul framework for long-term espionage operations.
Central Asian APT targeting government entities and embassies in the region with PowerShell-based implants and Telegram bot infrastructure for C2.
Russia GRU military intelligence APT responsible for DNC hack, WADA breach, NotPetya, and persistent targeting of NATO governments and elections infrastructure worldwide.
Chinese APT closely related to Mustang Panda, targeting European diplomatic missions and the Vatican with PlugX and custom malware via carefully crafted spearphishing campaigns.
Pakistan-linked APT persistently targeting Indian military and government with CrimsonRAT, fake romance apps, and Android malware for espionage operations.
Threat cluster operating Cuba ransomware with custom loaders and kernel driver exploits, targeting critical infrastructure and government organizations for double extortion.
Chinese-nexus APT exploiting CVE-2023-2868 in Barracuda Email Security Gateway appliances to deploy custom backdoors across government and critical infrastructure globally.
Chinese threat actor blending espionage with cybercrime, exploiting Ivanti, F5, and Atlassian vulnerabilities using open-source C2 frameworks to target defense and research institutions.
Analysis of unattributed advanced persistent threat clusters that don't match known APT groups, featuring novel TTPs and infrastructure that defy conventional classification.
Operator of the Golden Chickens MaaS suite providing more_eggs backdoor to FIN6, Cobalt Group, and Evilnum, targeting corporate HR departments via fake job applications.
Chinese state-sponsored APT conducting espionage against defense, aerospace, and government sectors worldwide using custom backdoors and supply chain attacks.
Breach & Campaigns
Cisco ASA/FTD zero-day exploitation
Malware
Open-source .NET RAT
Malware
Go-based information stealer
Malware
Backdoor malware
Malware
AutoIt-scripted malware family
Commercial .NET RAT
Malware
Information stealer targeting browser data and crypto wallets
Analysis of Bad Rabbit ransomware, a modified variant of Not Petya targeting Ukraine and Russia via drive-by downloads and SMB propagation.
Malware
Clipboard-hijacking banking malware
Malware
Brazilian banking trojan downloader
TrickBot successor loader
Brazilian banking trojan
Ransomware
Go-based ransomware turned data extortion group
Malware
Legacy RAT with modern revival
Malware
Low-cost MaaS RAT
Ransomware group exploiting Exchange/ESXi vulnerabilities
BlackSuit ransomware group analysis — a rebranded Royal ransomware from the Conti gang targeting healthcare, education, and critical infrastructure.
Malware
Information stealer loader
Malware
Commercial adversary simulation framework
Cuba ransomware downloader
Malware
Go-based cross-platform RAT
MTAC threat intelligence report analyzing 22,705 hostile activities from 3,321 Chinese source IPs targeting 4 countries, with attribution to APT10, APT27, Mustang Panda, APT41, and Volt Typhoon.
Exploit Kits
Fake browser update framework
Deep analysis of Cobalt Strike, the commercial red team framework exploited by APT29, APT41, Conti, and LockBit. Covers Beacon payloads, Malleable C2, Operation Morpheus, and defense strategies.
How Lapsus$, ShinyHunters, and Scattered Spider merged into one of the most brazen cybercrime collectives — and what it means for enterprise security.
How APT groups like Imperial Kitten, APT33, and MuddyWater execute sustained cyberattacks, and Mjolnir Security's approach to countering them.
Tools & Frameworks
Open-source .NET C2 framework
Unauthorized cryptocurrency mining
Analysis of CVE-2025-10035, a critical CVSS 10.0 vulnerability in Fortra GoAnywhere MFT, and its strategic implications for Canadian businesses.
Malware
Modular banking trojan
Malware
Emerging downloader malware
Malware
Premium MaaS loader
Analysis of DcRAT (Dark Crystal RAT), the $5-7 .NET MaaS RAT with 34 plugins, dedicated IDE, and usage by threat actors targeting Ukrainian defense. Covers YouTube distribution, plugin ecosystem, and
Tools & Frameworks
Lightweight Go-based C2
Custom APT backdoor
Malware
Dual-payload loader
Malware
Prolific banking trojan
Malware
Classic file infector
Platform-Specific
Linux cryptocurrency mining malware
Platform-Specific
Linux IoT botnet
Emerging Linux threats analysis
Malware
Infamous IoT DDoS botnet
Platform-Specific
Linux reverse SSH backdoor
Platform-Specific
Linux backdoor malware
Script-based loader chain
Malware
Modular botnet and loader
Tools & Frameworks
Adversary-in-the-middle phishing framework
Malware
Fake application malware
Classic credential stealer and downloader
Financially motivated threat group specializing in payment card theft from POS systems and e-commerce platforms, responsible for millions of stolen card numbers across retail and hospitality.
Prolific eCrime group responsible for over $1 billion in theft, evolving from POS malware to ransomware affiliate operations while operating a fake pentesting company (Combi Security, Bastion Secure).
Malware
File infector trojan
Malware
Delphi-based RAT
Malware
Chinese-origin RAT with decades of use
Malware
Go-based brute force tool
Tools & Frameworks
Open-source phishing framework
Malware
LATAM banking trojan
Breach & Campaigns
SAP NetWeaver exploitation campaign
Breach & Campaigns
SolarWinds supply chain compromise
Tools & Frameworks
Hak5 device management platform
Tools & Frameworks
Modern open-source C2 framework
Ransomware
Ransomware-as-a-Service disrupted by FBI infiltration
VBS-based worm RAT
Malware
Banking trojan turned loader
Tools & Frameworks
OOB interaction testing tool
Ransomware targeting FreeBSD and critical infrastructure
Malware
Emerging loader malware
Intelligence update on Iranian cyber threats post-Operation Epic Fury. Expect destructive wipers, ICS/SCADA attacks, and AI-enabled influence operations.
An anthropological and geopolitical analysis of Iranian state-sponsored APT groups weaponizing cyberspace against North American critical infrastructure.
Exploit Kits
Traffic distribution system abused by threat actors
Malware
Banking trojan
Malware
Modular financial trojan
Analysis of Latrodectus, the Windows malware loader succeeding IcedID with advanced sandbox evasion, AES-256 encryption, and ClickFix social engineering. Covers TA577/TA578, Operation Endgame survival
Tools & Frameworks
Tunneling/pivoting tool
Malware
Open-source .NET RAT
Ransomware
Most prolific RaaS operation before Operation Cronos
Malware
AutoIt-based RAT
Malware
Widely distributed information stealer
Tools & Frameworks
Rising MaaS stealer replacing RedLine
E-commerce card skimmer
Ransomware
Emerging ransomware targeting Latin American organizations
Malware
Backdoor trojan
MaaS loader
Persistent RaaS targeting healthcare and education
Malware
RedLine fork with shared infrastructure
Tools & Frameworks
Premier penetration testing framework
Tools & Frameworks
Windows credential extraction tool
Malware
LATAM banking trojan and stealer
Chinese threat group targeting defense and high-tech organizations using spear-phishing and custom backdoors since at least 2008.
Iranian threat actor conducting destructive wiper attacks and ransomware operations primarily against Israeli targets, masking espionage with sabotage.
Iranian threat group active since 2010, targeting defense industrial base and Iranian dissidents using social engineering and custom malware.
Russian threat group targeting electric utility organizations in the US and UK, focused on ICS reconnaissance and maintaining persistent access.
Chinese-speaking APT active since 2013 targeting government, education, and telecom organizations across Southeast Asia and Australia.
North Korean sub-group of Lazarus focused on cryptocurrency theft through trojanized trading applications and supply chain attacks.
Middle Eastern threat group conducting surveillance and espionage against military and government targets across the region since 2012.
Spanish-speaking threat group targeting Colombian and Ecuadorian government, financial, and energy organizations with commodity RATs.
PLA Unit 61398 threat group that systematically stole hundreds of terabytes of data from at least 141 organizations across 20 industries since 2006.
Chinese threat group targeting media organizations, high-tech companies, and government entities since at least 2009.
China-based group targeting Japanese and Taiwanese organizations, particularly media and government entities.
Chinese threat group exploiting zero-day vulnerabilities and using legitimate websites for C2 to target US government and defense organizations.
Chinese group responsible for the massive 2015 healthcare breach stealing 78.8 million patient records, also targeting aerospace and defense.
Chinese group targeting law firms and investment companies, known for using strategic web compromises and zero-day exploits.
Russian SVR intelligence group responsible for the SolarWinds supply chain attack affecting 18,000+ organizations. One of the most sophisticated APTs globally.
Chinese MSS-affiliated group (Boyusec) conducting espionage through zero-day exploits and strategic web compromises, indicted by US DOJ in 2017.
Chinese APT conducting long-running espionage operations since 2005 targeting ASEAN member states and India with air-gapped network infiltration capabilities.
Vietnamese state-sponsored group targeting private sector, foreign governments, and journalists with sophisticated custom malware and social engineering.
Iranian group targeting aerospace and energy sectors globally, linked to destructive attacks using Shamoon wiper and password spraying campaigns.
North Korean group primarily targeting South Korean organizations using zero-day exploits, strategic web compromises, and mobile malware.
North Korean group focused on financial theft, responsible for the $81M Bangladesh Bank heist and attacks on banks across 11+ countries via SWIFT.
Iranian MOIS-affiliated group focused on surveillance of individuals through telecom and travel industry compromise since 2014.
Iranian IRGC-IO group conducting credential harvesting and surveillance against journalists, activists, and Western government officials.
Chinese APT targeting telecommunications and technology organizations, known for exploiting Pulse Secure VPN and Citrix vulnerabilities.
Chinese threat group conducting intelligence collection and industrial espionage using Log4Shell and other vulnerabilities since 2020.
Chinese state-sponsored group conducting large-scale cyber espionage against government and critical infrastructure worldwide since 2008.
Chinese APT targeting ministries of foreign affairs and telecoms in Africa, Middle East, and Central Asia with custom backdoors.
Middle Eastern threat actor using zero-day exploits (particularly Flash) for surveillance against UN officials, journalists, and activists.
Chinese state-sponsored group targeting Japan and Taiwan, known for modifying router firmware to maintain persistent access to networks.
Financially motivated group exploiting web application vulnerabilities to deploy Monero cryptocurrency miners on Windows systems.
Threat group deploying Android surveillance malware targeting military personnel in Middle Eastern countries.
Chinese espionage group conducting intellectual property theft from Japanese defense and technology organizations since 2006.
Financially motivated group that stole over $1 billion from banks worldwide by compromising internal banking systems and manipulating ATMs.
Chinese threat group targeting semiconductor and airline industries for intellectual property theft, using Cobalt Strike and custom DLL loaders.
Chinese group deploying ransomware (HUI Loader, Cobalt Strike) potentially as cover for espionage, cycling through multiple ransomware families.
Iranian group conducting Operation Cleaver targeting critical infrastructure across 16 countries including military, energy, and aviation.
Financially motivated group targeting banks worldwide through ATM jackpotting and SWIFT transaction manipulation using Cobalt Strike.
Indian-origin APT conducting espionage against Pakistani military and government targets using mobile and desktop malware.
North Korean campaign targeting software developers through fake job interviews to deliver malware that steals cryptocurrency and credentials.
Iranian group targeting Israeli and German government and academic organizations using custom malware and strategic web compromises.
Iranian group building elaborate fake social media personas to establish trust with targets before delivering malware over months-long engagements.
IRGC-affiliated group targeting water treatment facilities and industrial control systems, notably hacking Unitronics PLCs in the US.
Chinese APT active since 2012 targeting telecoms and government in Africa and Asia, known for MgBot malware and macOS capabilities.
Lebanese intelligence-linked group conducting global mobile surveillance campaign stealing data from Android devices across 21+ countries.
APT targeting business executives and government officials through hotel Wi-Fi networks, using zero-days and stolen certificates since 2007.
Threat group targeting Middle Eastern government and education with custom tools leveraging open-source offensive frameworks.
Financially motivated group physically planting rogue devices (Raspberry Pi, Bash Bunny) inside bank offices for network penetration.
Chinese group responsible for the 2015 Anthem healthcare breach (80M records) and targeting US government personnel databases.
Russian FSB group targeting Western energy and nuclear facilities since 2011, gaining operational access to ICS/SCADA systems.
Chinese group targeting Japanese and Taiwanese high-tech and manufacturing organizations with commodity and custom malware.
Chinese group blending espionage with financially motivated attacks, targeting government and tech sectors through web-facing server exploitation.
Chinese group behind 2009 Operation Aurora targeting Google and 20+ companies, pioneering zero-day supply chain attacks.
Russian GRU group conducting destructive operations against Ukraine using WhisperGate wiper and defacing government websites before the 2022 invasion.
Highly sophisticated group (attributed to NSA TAO) active since 2001, using HDD firmware implants and air-gap jumping capabilities.
Financially motivated group targeting fintech and cryptocurrency companies with JavaScript-based malware and social engineering.
Initial access broker using elaborate business proposal phishing with custom file-sharing services to deliver BazarLoader and ransomware.
Iranian group targeting domestic dissidents and Persian-speaking individuals with MarkiRAT surveillance malware since 2015.
Financially motivated group extorting Canadian organizations with threats to leak stolen data, active 2013-2016.
Financially motivated group conducting slow, stealthy intrusions in Latin American banks to manipulate financial transactions over months.
Group targeting healthcare and M&A advisory firms to steal insider trading information from corporate email accounts.
Financially motivated group stealing payment card data from hospitality and restaurant point-of-sale systems since 2008.
Financially motivated group conducting POS malware campaigns against retail and hospitality organizations since 2016.
Iranian group acting as initial access broker, exploiting VPN vulnerabilities (Pulse Secure, Fortinet, F5) and selling access to ransomware operators.
Chinese group targeting global telecommunications providers to conduct surveillance, exploiting public-facing web servers for initial access.
Espionage group using living-off-the-land techniques exclusively, avoiding custom malware to target government and military organizations.
Financially motivated group using legitimate penetration testing tools to transfer money from banks, capping at amounts below alert thresholds.
Ransomware group operating the REvil/Sodinokibi Ransomware-as-a-Service, responsible for Kaseya supply chain attack affecting 1,500+ businesses.
Pakistani threat group conducting both espionage and criminal operations using commodity RATs distributed through spear-phishing.
Threat group targeting the Syrian opposition using commercial RATs and social engineering over social media platforms.
Chinese state-sponsored group exploiting Microsoft Exchange ProxyLogon zero-days (CVE-2021-26855) to compromise 30,000+ organizations globally.
Iranian group targeting Middle Eastern and African telecoms and oil companies using DNS tunneling and custom .NET backdoors.
Group targeting North Korean government interests and Chinese organizations using LNK file-based attacks and DLL side-loading.
Ransomware group active since 2023 targeting healthcare and education with double extortion, known for publishing stolen data on leak sites.
Sophisticated group using cloud services for C2 and targeting government organizations in Russia and Central Asia since 2012.
Chinese group targeting Central Asian government entities using Dropbox and other cloud services as C2 infrastructure.
Russian cybercrime group behind Dridex, BitPaymer, WastedLocker, and Hades ransomware. Leader Maksim Yakubets has $5M FBI bounty.
Chinese group targeting diplomatic missions and government organizations worldwide since 2010, known for Ketrican and Okrum backdoors.
Threat group targeting airline industry and IATA members using KOCTOPUS loader and Empire framework since 2018.
Iranian group targeting Middle Eastern government and business organizations using publicly available tools and vulnerability scanning.
Chinese MSS-directed (Hainan province) group targeting maritime, defense, and aviation. Indicted by US DOJ in 2021 for global espionage campaign.
Chinese-speaking group targeting Southeast Asian government entities with USB spreading malware and Zoom installer hijacking.
Spanish-speaking group conducting espionage against Latin American military and government institutions since 2010.
Brazilian threat group distributing banking trojans targeting Latin American financial institutions through malspam campaigns.
Ransomware group operating Medusa RaaS since 2022, using double extortion and a public Tor-based leak site for victim data.
Highly sophisticated group targeting telecoms and ISPs using multi-layered malware platforms with years-long persistence.
Chinese group associated with military interests targeting US defense organizations with custom malware.
Chinese espionage group targeting government and critical infrastructure in Myanmar and other countries using ShimRat malware.
Palestinian group conducting espionage against Israeli and Middle Eastern targets using social engineering and commodity RATs since 2012.
North Korean group using fake companies, trojanized software, and custom ransomware (FakePenny) to fund DPRK operations.
Iranian group conducting destructive attacks against Israeli organizations, encrypting systems without providing decryption capability.
Belarusian group targeting foreign embassies in Belarus using ISP-level adversary-in-the-middle attacks for malware delivery.
Initial access broker distributing SocGholish fake browser updates to deliver ransomware and other payloads to compromised websites.
Chinese PLA-linked group conducting espionage against Southeast Asian government and military targets since 2005.
Group using zero-day exploits and FinFisher surveillance software to target individuals in Turkey.
Group targeting Central Asian diplomatic and government entities using custom Android and Windows malware.
Iranian MOIS group conducting espionage across the Middle East since 2014 using DNS tunneling, custom tools, and social engineering.
Group targeting healthcare organizations and their supply chain to access patient data and medical device information.
Chinese group targeting defense and telecom sectors using Gh0st RAT and Troj/Reader-AJ since 2011.
Sophisticated group using hotpatching for fileless execution and targeting South Asian government and ISP organizations.
Ransomware group active since 2022 using double extortion, known for exploiting FortiOS and Microsoft Exchange vulnerabilities.
Brazilian group conducting targeted attacks to steal proprietary information and blackmail victims into hiring them as security consultants.
Turkish-linked group targeting Kurdish and opposition groups by trojanizing legitimate software installers with surveillance capabilities.
Chinese PLA Unit 61486 group targeting US defense and space sectors to steal satellite and aerospace technology.
Chinese group targeting Southeast Asian government entities using PLAINTEE and DDKONG malware families.
Group conducting stealthy corporate espionage targeting HR and legal departments to steal internal documents and business intelligence.
Chinese group targeting Indian power grid infrastructure with ShadowPad malware, potentially pre-positioning for disruptive operations.
Chinese group deploying cryptocurrency miners at scale on compromised Linux and cloud servers, evading detection by killing competing miners.
Russian cybercrime group targeting Russian banking organizations to steal funds through manipulated accounting software transactions.
Russian group targeting Ukrainian and Georgian government organizations with destructive payloads during the Russia-Ukraine conflict.
Russian GRU Unit 74455 responsible for NotPetya ($10B damage), BlackEnergy grid attacks, Olympic Destroyer, and ongoing Ukraine cyber operations.
Chinese group targeting Uyghur and Tibetan minority activists using mobile and desktop surveillance malware.
Group conducting DNS hijacking campaigns targeting government and telecom organizations across the Middle East and North Africa.
Pakistani group mimicking Sidewinder TTPs to target Indian military and defense organizations with custom RATs.
Indian APT targeting Pakistan and China military and government since 2012, one of the most active APTs by volume of operations.
Russian-speaking group targeting financial organizations and ATM systems primarily in CIS countries, stealing millions via ATM jackpotting.
Iranian group conducting credential harvesting campaigns against 300+ universities in 30+ countries to steal academic research and IP.
Nigerian cybercrime group conducting business email compromise (BEC) campaigns responsible for billions in global losses.
Espionage group targeting South American and Southeast Asian foreign affairs ministries using Felismus backdoor.
Russian FSB group conducting credential phishing against academics, defense officials, and NGOs to collect intelligence since 2017.
UAE-linked group conducting surveillance against dissidents, journalists, and activists using sophisticated spyware.
Financially motivated group pivoting from on-premises to cloud, deploying Embargo ransomware against US organizations.
Financially motivated group abusing Microsoft Quick Assist remote support tool for social engineering to deploy Black Basta ransomware.
Highly sophisticated group using air-gap-defeating modular malware platform active since 2011, discovered by Kaspersky in 2016.
Chinese group using stolen code signing certificates to attack Indian government and commercial organizations.
Persistent threat group targeting aviation and defense industries since 2017 using commodity RATs via large-scale phishing campaigns.
Chinese group targeting Central Asian military and government using exploits for Microsoft Office vulnerabilities.
Major cybercrime group distributing Dridex, Locky, Clop ransomware, and FlawedAmmyy at massive scale via Necurs botnet.
Malware distribution group using thread-hijacked email campaigns to deliver IcedID, QakBot, and Ursnif banking trojans.
Prolific initial access broker distributing QakBot and Pikabot via thread-hijacked email campaigns at high volume.
Initial access broker using contact form and callback phishing to deliver BazarLoader, Bumblebee, and Latrodectus.
Cloud-focused group targeting misconfigured Docker and Kubernetes environments to deploy cryptocurrency miners and steal credentials.
Russian group behind TRITON/TRISIS malware targeting Schneider Electric Triconex safety systems, capable of causing physical destruction.
Sophisticated group targeting Pakistani military and nuclear program with malware designed to evade 8+ antivirus products.
Threat group targeting financial organizations using SWIFT manipulation techniques to conduct fraudulent transactions.
Chinese group targeting satellite operators, telecoms, and defense organizations in Southeast Asia and the US.
Sophisticated Chinese APT targeting government and military in Asia and Europe since 2020, using custom loaders and passive backdoors.
Chinese group targeting military and government organizations in Russia, South Korea, and Japan using Bisonal and ShadowPad.
Chinese group targeting Taiwanese and Philippine government and military organizations with custom USB-spreading malware since 2011.
Russian FSB group active since 1996, one of the most sophisticated APTs using satellite-based C2 and hijacking other APT infrastructure.
Chinese group exploiting zero-days in VMware and Fortinet appliances to maintain persistent access to hypervisors and network edge devices.
Iranian group conducting espionage operations against Middle Eastern government and telecommunications organizations.
Chinese group maintaining years-long persistence in F5 BIG-IP and other network appliances, demonstrating exceptional operational stealth.
Lebanese group targeting military and telecom organizations across the Middle East and beyond using Explosive RAT since 2012.
Chinese state-sponsored group pre-positioning in US critical infrastructure (energy, water, telecom, ports) for potential disruption during geopolitical crisis.
Group targeting Philippine government organizations using spear-phishing and custom malware since 2022.
Group responsible for the 2018 SingHealth breach stealing 1.5 million patient records including the Singapore Prime Minister's data.
Operation Windigo compromised 25,000+ Linux servers for spam distribution, click fraud, and malware delivery since 2011.
Group conducting surveillance against specific individuals in the Middle East using macOS and mobile malware.
Russia-aligned group exploiting Zimbra and Roundcube zero-days to target European government and NATO-aligned diplomatic entities.
Middle Eastern group linked to Gaza Cybergang conducting espionage against government and diplomatic entities in the region.
Russian cybercrime group behind TrickBot, Conti, Ryuk, and BazarLoader - one of the most prolific ransomware operations generating $200M+ in revenue.
Chinese MSS-affiliated group (Wuhan Xiaoruizhi) targeting government and technology organizations worldwide, indicted by US DOJ in 2024.
Tools & Frameworks
Extensible multi-platform C2 framework
Malware
Widely-used .NET RAT
Tools & Frameworks
Weaponized remote admin tool
Malware
Cross-platform commercial RAT
Tools & Frameworks
Commercial advanced C2 platform
Tools & Frameworks
Emerging C2 framework
Analysis of NjRAT (Bladabindi), the leaked-source .NET RAT active since 2012 with keylogging, MBR wiping, USB worm, and DDoS capabilities. Covers Group5, SideCopy, Dev Tunnels abuse, and defense strat
Malware
Excessive failed DNS resolution abuse
Malware
Information-gathering RAT
Malware
Surveillance-focused RAT
TOR-based ransomware
Malware
Commercial RAT disguised as admin tool
Malware
JavaScript-based loader
macOS information stealer
Platform-Specific
Rust-based macOS backdoor
Malware
Emerging backdoor
Malware
Emerging MaaS RAT
Malware
IRC-based Perl backdoor
Tools & Frameworks
MuddyWater custom C2
Malware
Chinese APT backdoor
Malware
Classic Chinese APT RAT
PowerShell-based malware delivery
Malware
Open-source Python RAT
Budget information stealer
Tools & Frameworks
Evasion-focused C2 framework
Python-based malware delivery
Malware
Long-running banking botnet
Malware
Proxy backdoor
Deep dive into Qilin ransomware — a Russian-origin RaaS operation targeting healthcare, manufacturing, and critical infrastructure with double extortion.
Malware
Open-source .NET RAT
Malware
MaaS information stealer
Threat analysis of RansomHub — from ALPHV's exit scam to the most prolific RaaS operation of 2024, and its hostile takeover by DragonForce.
Breach & Campaigns
Mass exploitation campaign
Malware
Java-based open-source RAT
Analysis of RedLine Stealer, the MaaS infostealer responsible for 51% of all infostealer infections, its Operation Magnus takedown, and defense strategies.
Malware
Commercial surveillance RAT
Tools & Frameworks
LLMNR/NBT-NS/mDNS poisoner
Tools & Frameworks
Retro-themed C2 RAT
Malware
Free .NET RAT
Advanced C++ information stealer
Ransomware
Ransomware group targeting healthcare and government
Malware
PrivateLoader-distributed stealer
Malware
Weaponized Remote Utilities
Malware
DNS hijacking and manipulation
0Apt is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
0Mega is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
8Base is a prolific double extortion group active since 2022 with a Tor-based leak site. This profile covers the group's operations, tactics, known campaigns, a
Abrahams Ax is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Abyss is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Adminlocker is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Againstthewest is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics,
Agl0Bgvycg is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Ailock is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Ako is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known campa
Alphalocker is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Alphv is a also known as BlackCat, first Rust-based RaaS, FBI seized infrastructure in Dec 2023. This profile covers the group's operations, tactics, known camp
Anubis is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Apos is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
Apt73 is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Arcusmedia is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Argonauts is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Arkana is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Arvinclub is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Atomsilo is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Avaddon is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Avos is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
Avoslocker is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Aware is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Aztroteam is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Babuk is a leaked source code spawned dozens of variants, targeted DC Metropolitan Police. This profile covers the group's operations, tactics, known campaigns,
Babuk2 is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Babyduck is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Beast is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Benzona is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Black Basta is a emerged from Conti dissolution, over 500 victims worldwide since Apr 2022. This profile covers the group's operations, tactics, known campaigns
BlackCat is a also known as ALPHV, Rust-based RaaS with triple extortion, FBI disrupted Dec 2023. This profile covers the group's operations, tactics, known cam
Blacklock is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Blackmatter is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Blacknevas is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Blackout is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Blackshadow is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Blackshrantac is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, k
Blacktor is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Bluebox is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Bluelocker is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Bluesky is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Bonacigroup is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Bqtlock is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Braincipher is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Bravox is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Brotherhood is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Cactus is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Cephalus is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Cheers is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Chilelocker is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Chort is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Cicada3301 is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Ciphbit is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Cipherforce is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Cl0p is a exploited MOVEit, GoAnywhere, Accellion for mass data theft affecting 2,500+ orgs. This profile covers the group's operations, tactics, known campaign
Cloak is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Coinbasecartel is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics,
Contfr is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Conti is a Russian-linked RaaS generating $180M+ before dissolution in 2022, leaked internal chats. This profile covers the group's operations, tactics, known c
Cooming is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Crazyhunter is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Crosslock is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Cry0 is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
Crylock is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Cryp70N1C0D3 is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kn
Cryptbb is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Cryptnet is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Crypto24 is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Cuba is a exploited Veeam and Microsoft Exchange, linked to COLDDRAW threat actor. This profile covers the group's operations, tactics, known campaigns, and def
Cyclops is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
D4Rk4Rmy is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Dagonlocker is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Daixin is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Dan0N is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Darkangels is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Darkbit is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Darkleakmarket is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics,
Darkpower is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Darkrace is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Darkside is a responsible for Colonial Pipeline attack, caused US fuel supply disruption. This profile covers the group's operations, tactics, known campaigns,
Darkvault is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Datacarry is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Datakeeper is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Dataleak is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Desolator is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Devman is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Diavol is a linked to Wizard Spider/TrickBot operators. This profile covers the group's operations, tactics, known campaigns, and defensive recommendations.
Direwolf is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Dispossessor is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kn
Donex is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Donutleaks is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Doppelpaymer is a evolved from BitPaymer, targeted critical infrastructure. This profile covers the group's operations, tactics, known campaigns, and defensive
Dragonforce is a Malaysian hacktivist-turned-ransomware group. This profile covers the group's operations, tactics, known campaigns, and defensive recommendatio
Dragonransomware is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics
Dread is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Dunghill is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Ech0Raix is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Eldorado is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Embargo is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Entropy is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Ep918 is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Everest is a data extortion group that also sells initial access. This profile covers the group's operations, tactics, known campaigns, and defensive recommenda
Exorcist is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Fletchen is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Flocker is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Fog is a targets education and recreation sectors via compromised VPN credentials. This profile covers the group's operations, tactics, known campaigns, and def
Frag is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
Freecivilian is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kn
Fsteam is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Funksec is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Gdlockersec is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Genesis is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Grief is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Groove is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Gunra is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Hades is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Handala is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Haron is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Hellcat is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Helldown is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Hellogookie is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Hellokitty is a cross-platform ransomware that targeted CD Projekt Red and others. This profile covers the group's operations, tactics, known campaigns, and def
Holyghost is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Hotarus is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Hunters is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Icefire is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Imncrew is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Insane is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Insomnia is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Kairos is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Karakurt is a data extortion without encryption, linked to Conti. This profile covers the group's operations, tactics, known campaigns, and defensive recommenda
Karma is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Kawa4096 is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Kazu is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
Kelvinsecurity is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics,
Killsec is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Kittykatkrew is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kn
Knight is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Kraken is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Kryptos is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Kyber is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
La Piovra is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Lapsus$ is a teenage extortion group that breached Microsoft, Nvidia, Samsung, Uber. This profile covers the group's operations, tactics, known campaigns, and d
Leaktheanalyst is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics,
Lilith is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Linkc is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Lockdata is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Lolnek is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Lorenz is a exploits Mitel VoIP vulnerabilities for initial access. This profile covers the group's operations, tactics, known campaigns, and defensive recommen
Losttrust is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Lunalock is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Madcat is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Madliberator is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kn
Malas is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Malekteam is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Mallox is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Marketo is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Maze is a pioneered double extortion model in 2019. This profile covers the group's operations, tactics, known campaigns, and defensive recommendations.
Meow is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
Metaencryptor is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, k
Midas is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Mindware is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Minteye is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Mogilevich is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Moneymessage is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kn
Monti is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Morpheus is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Mountlocker is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Ms13089 is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Mydecryptor is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
N3Tworm is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Nasirsecurity is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, k
Nefilim is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Nemty is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Netwalker is a RaaS disrupted by FBI in Jan 2021, operator sentenced. This profile covers the group's operations, tactics, known campaigns, and defensive recomm
Nevada is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Nightsky is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Nightspire is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Nitrogen is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Noescape is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Nokoyawa is a exploited Windows CLFS zero-day CVE-2023-28252. This profile covers the group's operations, tactics, known campaigns, and defensive recommendation
Noname is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Nova is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
Obscura is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Onepercent is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Orion is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Osiris is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Pandora is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Pay2Key is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Payload is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Payloadbin is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Payoutsking is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Pear is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
Projectrelic is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kn
Prolock is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Prometheus is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Promptlock is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Pysa is a also known as Mespinoza, targets education and healthcare. This profile covers the group's operations, tactics, known campaigns, and defensive recomme
Qiulong is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Qlocker is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Quantum is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Rabbithole is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Radar is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Radiant is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Ragnarlocker is a law enforcement seized infrastructure Oct 2023. This profile covers the group's operations, tactics, known campaigns, and defensive recommenda
Ragnarok is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Ralord is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Ramp is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
Rancoz is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Ranion is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Ransombay is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Ransomcartel is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kn
Ransomcortex is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kn
Ransomed is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Ransomexx is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Ransomhouse is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Ranstreet is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Ranzy is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Raworld is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Raznatovic is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Rebornvc is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Redalert is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Redransomware is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, k
Revil is a also known as Sodinokibi, attacked Kaseya and JBS, multiple arrests. This profile covers the group's operations, tactics, known campaigns, and defens
Reynolds is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Robinhood is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Rook is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
Royal is a evolved into BlackSuit, linked to former Conti members. This profile covers the group's operations, tactics, known campaigns, and defensive recommend
Runsomewares is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kn
Sabbath is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Safepay is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Sarcoma is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Satanlockv2 is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Secp0 is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Securotrop is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Sensayq is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Shadow is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Shadowbyt3$ is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Shaoleaks is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Shinyhunters is a data breach and extortion group that hit AT&T, Ticketmaster via Snowflake. This profile covers the group's operations, tactics, known campaign
Shinysp1D3R is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Sicarii is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Siegedsec is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Silentransomgroup is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactic
Sinobi is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Slug is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
Solidbit is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Spacebears is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Sparta is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Spook is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Stormous is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Sugar is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Suncrypt is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Synack is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Teamxxx is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Tengu is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Termite is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Thegentlemen is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kn
Thegreenbloodgroup is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tacti
Threeam is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Toufan is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Tridentlocker is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, k
Trigona is a exploited MSSQL servers for initial access. This profile covers the group's operations, tactics, known campaigns, and defensive recommendations.
Trinity is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Trisec is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
U-Bomb is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Underground is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, kno
Unknown is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Unsafe is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Valencialeaks is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, k
Vanhelsing is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Vanirgroup is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Vect is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
Vendetta is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Vfokx is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Vicesociety is a heavily targeted education sector. This profile covers the group's operations, tactics, known campaigns, and defensive recommendations.
Walocker is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known
Wannacry is a North Korean-linked worm that infected 230,000+ systems in 150 countries in 2017. This profile covers the group's operations, tactics, known campa
Warlock is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known c
Werewolves is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Weyhro is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Worldleaks is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
X001Xs is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known ca
Xinglocker is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, know
Xinof is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Yanluowang is a targeted Cisco in 2022, member data later leaked. This profile covers the group's operations, tactics, known campaigns, and defensive recommenda
Yurei is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known cam
Zeon is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, known camp
Zerolockersec is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, k
Zerotolerance is a ransomware/extortion group operating a dark web leak site for victim data publication. This profile covers the group's operations, tactics, k
Ransomware
Big game hunting ransomware from Wizard Spider
Small downloader
Deconstructing Salt Typhoon, one of China's most sophisticated state-sponsored APT groups targeting telecommunications and critical infrastructure worldwide.
Analysis of SANDWORM_MODE — the first documented cross-modal supply chain worm designed to subvert AI coding assistants and MCP servers via malicious npm packages.
Malware
Legacy IRC-based botnet
Information stealer RAT
Tools & Frameworks
BishopFox open-source C2
Ransomware
Ransomware using Safe Mode reboot to evade detection
JavaScript-based fake update framework
Multi-component malware suite
Adware and crypto-mining botnet
Malware
Stealthy cross-platform malware
Malware
Java-based RAT with fake ransomware
Tools & Frameworks
Chinese-origin web-based C2
Malware
Lightweight information stealer
Cryptomining botnet
Analysis of SystemBC, the SOCKS5 proxy backdoor with TOR integration used by Ryuk, Conti, DarkSide, and Black Basta ransomware operations. Covers RC4 encryption, DroxiDat variant, and detection strate
Malware
Emerging loader malware
Threat actor distributing platform-specific payloads via web injects and fake browser updates, delivering FrigidStealer on macOS, Marcher on Android, and Lumma on Windows.
The adversary is trying to get into your network.
MITRE ATT&CK
The adversary is trying to run malicious code.
MITRE ATT&CK
The adversary is trying to maintain their foothold.
The adversary is trying to gain higher-level permissions.
The adversary is trying to avoid being detected.
The adversary is trying to steal account names and passwords.
MITRE ATT&CK
The adversary is trying to figure out your environment.
The adversary is trying to move through your environment.
MITRE ATT&CK
The adversary is trying to gather data of interest to their goal.
MITRE ATT&CK
The adversary is trying to steal data.
The adversary is trying to communicate with compromised systems to control them.
The adversary is trying to get into your device.
MITRE ATT&CK
The adversary is trying to maintain their foothold.
The adversary is trying to gain higher-level permissions.
The adversary is trying to avoid being detected.
The adversary is trying to steal account names, passwords, or other secrets.
MITRE ATT&CK
The adversary is trying to figure out your environment.
The adversary is trying to move through your environment.
MITRE ATT&CK
The adversary is trying to manipulate, interrupt, or destroy your devices and data.
MITRE ATT&CK
The adversary is trying to gather data of interest to their goal.
MITRE ATT&CK
The adversary is trying to steal data.
The adversary is trying to communicate with compromised devices to control them.
The adversary is trying to intercept or manipulate network traffic to or from a device.
The adversary is trying to control or monitor the device using remote services.
MITRE ATT&CK
The adversary is trying to manipulate, interrupt, or destroy your systems and data.
MITRE ATT&CK
The adversary is trying to run malicious code.
The adversary is trying to establish resources they can use to support operations.
The adversary is trying to gather information they can use to plan future operations.
MITRE ATT&CK
The adversary is trying to gather data of interest and domain knowledge on your ICS environment.
The adversary is trying to communicate with and control compromised systems, controllers, and platforms.
MITRE ATT&CK
The adversary is locating information to assess and identify their targets in your environment.
MITRE ATT&CK
The adversary is trying to avoid security defenses.
MITRE ATT&CK
The adversary is trying to run code or manipulate system functions, parameters, and data in an unauthorized way.
MITRE ATT&CK
The adversary is trying to manipulate, interrupt, or destroy your ICS systems, data, and their surrounding environment.
The adversary is trying to manipulate, disable, or damage physical control processes.
The adversary is trying to prevent your safety, protection, quality assurance, and operator intervention functions from responding.
The adversary is trying to get into your ICS environment.
The adversary is trying to move through your ICS environment.
MITRE ATT&CK
The adversary is trying to maintain their foothold in your ICS environment.
The adversary is trying to gain higher-level permissions.
Malware
Point-of-sale malware
Analysis of Tofsee (Gheg), the modular spam botnet active since 2013 with crypto mining, DDoS, social media spreading, and proxy modules. Covers DGA cracking, PrivateLoader distribution, and defense s
Malware
Modular banking trojan turned loader
Emerging malware family
Analysis of emerging unclassified RATs
Malware
Classic small downloader
Long-running banking trojan
Malware
Chinese-origin RAT targeting Chinese speakers
Malware
Arkei-derived information stealer
Tools & Frameworks
Chinese-language C2 platform
Malware
JavaScript worm/RAT hybrid
Malware
USB propagation worm
SonicWall VPN zero-day vulnerability enables threat actors to sell unauthorized corporate network access on dark web forums across North America.
Tools & Frameworks
Go-based cross-platform C2
MaaS information stealer
Modular backdoor framework used by multiple Chinese APT groups for persistent access and supply chain compromises across gaming, technology, and telecom sectors.
Malware
Open-source C# RAT
Breach & Campaigns
Kuwait-focused espionage campaign
Tools & Frameworks
Chinese C2 framework
Malware
Legacy RAT still in use
Malware
Rising MaaS RAT
Exploit Kits
PHP-based exploit kit