Uptime Hamster: 23d 22h 45mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
IntelTracker

Threat Intelligence Monitor

Victimas, actores, TTPs, CVEs, IOCs y referencias verificadas en una interfaz CTI indexable con filtros operativos.

10,901Incidentes
4,136Filtrados
1,119Actores
6,937IOCs visibles
Limpiar
Mapa
111
Paises afectados
Alertas
5,893
Amenazas recientes
Brechas
7,163
Filtraciones y victimas
Hackeos
8,853
Incidentes investigables

Actividad filtrada

TTPs principales

T1566886
T10037
T10595
T15623
T10783
T11103
T14862
T11902

Actores

qilin296
nightspire198
thegentlemen193
akira130
dragonforce119
incransom101
lockbit589
play69
shinyhunters58
clop53

Paises

United States1821
China190
United Kingdom128
Germany104
Canada84
France75
India68
Russia67
Iran61
Brazil54

Acciones rapidas

Mapa globalGraficosBrechasPanel clasico

Mapa de actividad

Abrir mapa completo →
United States1821 incidentes China190 incidentes United Kingdom128 incidentes Germany104 incidentes Canada84 incidentes France75 incidentes India68 incidentes Russia67 incidentes Iran61 incidentes Brazil54 incidentes Spain49 incidentes Italy48 incidentes

Filtros directos

RansomwareBrechasCVEsPhishingIntelTracker
4,136 resultados · pagina 15/115Exportar CSV
Villea Hotels in AttanaHo2026-06-29
ransomwareUnknown
Una empresa de turismo denominada Villea Hotels in AttanaHo ha sido afectada por un ataque cibernético que se originó en el año 2026. El incidente, relacionado con una amenaza de ransomware,...
ccic.com.tw2026-06-29
blackfieldransomwareTaiwan
El 29 de junio de 2026 se reportó un incidente de ciberataque relacionado con ransomware contra la empresa Nidec Chaun-Choung Technology Corporation (CCIC), una empresa basada en Taiwán. El ...
Ransomware Victim: Fidelity Security Group (cmdorganization)2026-06-28
cmdorganizationransomwareUnknown
Victima de ransomware reportada en el dashboard de cmdorganization.
Ido Cohen: The attackers never rest... and neither do we. Meet RedAct, a newly tracked ransomware group. The group has already published 2 victims and states that it is driven purely by financial gain—not politics or hacktivism. According to its public message, organizations that refuse to negotiate or fail to meet ransom demands should expect their stolen data to be published. Another emerging threat worth keeping on your radar.2026-06-28
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Daily Dark Web: Major International Anti-Piracy Operation Seizes Pirate Streaming Infrastructure Law enforcement agencies from multiple countries have seized domains and infrastructure associated with large-scale piracy services as part of **Operation Offside**. * The seizure banner identifies participation from agencies including: * U.S.2026-06-28
x-cticampaignUnknown
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: Pinned: New Linux "pedit COW" Privilege Escalation Exploit Published Security researcher Massimiliano Oldani has released a public proof-of-concept (PoC) exploit, **packet_edit_meme**, for the Linux kernel vulnerability **CVE-2026-46331**, nicknamed **pedit COW**. * The flaw resides in Linux's **net/sched act_pedit** traffic control subsystem and allows an unprivileged local user to escalate privileges to **root** by corrupting shared page-cache memory.2026-06-28
x-ctivulnerabilityUnited States
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: Alleged Compromise of Colima State Government Electronic Signature System A threat actor claims to have compromised the Advanced Electronic Signature (Firma Electrónica Avanzada) platform used by the Government of the State of Colima, Mexico. * According to the forum post, the actor alleges they: * Gained administrative access to the portal. * Deleted all user accounts except a single administrator account. * Retained control of the remaining administrative account.2026-06-28
x-cticampaignMexico
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: French Municipal Police Data Allegedly Leaked A threat actor claims to have leaked approximately 4,900 "mains courantes" (police incident reports/logs) belonging to the Municipal Police of Joinville-le-Pont, France. * According to the listing, the actor states the dataset was personally extracted and is offering access through a paid forum.2026-06-28
x-cticampaignFrance
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: Croatian Student Database Allegedly Shared on Dark Web Forum A threat actor has published what they claim is a database containing approximately 954,000 records related to students from Croatian primary and secondary schools.2026-06-28
x-ctibreachCroatiaT1566
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: French Hospital Patient Database Allegedly Repackaged and Shared A threat actor has published what they claim is a reformatted dataset originating from the 2024 Blackout ransomware leak targeting Centre Hospitalier d'Armentières in France. According to the post, the dataset contains information on approximately 203,928 patients, covering records from 2004 through March 2018.2026-06-28
x-ctiransomwareFranceT1566
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Ransomware Victim: Mosaic Partners (payload)2026-06-26
anggipradanaransomwareUnknown
Victima de ransomware reportada en el dashboard de payload.
ingerman.com2026-06-26
chaosransomwareGermany
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Ido Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ransomware Monitor: Actor: #nightspire Victim: Grupo Riquelme Date: 2026-06-26 03:15:53 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#nightspire” Ransomware group has added Grupo Riquelme to its victims.2026-06-26
x-ctiransomwareUnknown
Ransomware monitoring feed tracking new victim disclosures, data leaks and group activity.
Clínica La Sabana2026-06-26
ransomwareCosta Rica
Una institución médica en Bogotá, Colombia, Clínica La Sabana, ha sido afectada por un ataque cibernético relacionado con ransomware. El incidento ocurrió el 26 de junio de 2026 y se atribuy...
Mosaic Partners2026-06-26
ransomwareSwitzerland
El 26 de junio de 2026, la empresa suiza Mosaic Partners fue objeto de un ataque cibernético que se presume es un ransomware. La organización, especializada en servicios IT, desarrollo de so...
Ransomware News: Noticis kiberuzbrukums Latvijas Valsts mežiem; drošības apsvērumu dēļ slēgts LVM GEO, karšu sistēma un "Mednis" [papildināts]2026-06-25
anggipradanareportUnited Kingdom
Noticis kiberuzbrukums Latvijas Valsts mežiem; drošības apsvērumu dēļ slēgts LVM GEO, karšu sistēma un "Mednis" [papildināts] Noticia sobre ransomware publicada en . Extracto Sin e...
Nachlass Nord2026-06-25
anubisransomwareGermany
Nachlass Nord, una organización dedicada a la gestión de patrimonios y registros familiares, fue objeto de un ataque cibernético atribuido al grupo anubis. El incidente ocurrió el 2026-06-25...
roofdepot.com2026-06-25
chaosransomwareUnited States
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Ido Cohen: Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiations. DarkFeed makes it easy to compare a ransomware group's leak site with the victim's public website in one place, helping analysts quickly identify attacks like these.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Sector Spotlight: HealthCare Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion groups actively targeting the HealthCare sector.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Group-IB Threat Intelligence: The Y2K Operators threat actor is using sophisticated #socialengineering lures, disguising payloads as legitimate software, cracked applications, gaming cheat tools (e.g., Roblox), and used PDF decoy documents.2026-06-25
x-cticampaignUnknown
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
Group-IB Threat Intelligence: Group-IB telemetry has identified over 62,000 compromised endpoints across more than 160 countries infected with #MilleniumRAT (4.x). The infection velocity is alarming, with over 39,000 of these detections occurring in Q1 2026 alone, representing 64% of all infections. This demonstrates a rapidly accelerating global campaign.2026-06-25
x-cticampaignUnknown
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
Group-IB Threat Intelligence: Pinned: #MilleniumRAT (v4.x) marks a significant evolution in the threat landscape. The #malware has been completely rewritten from .NET to a native C++ application, removing .NET dependencies. This architectural shift enables greater stealth and resilience, making detection more challenging. The #Telegram Bot API remains the core C2 mechanism.2026-06-25
x-ctimalwareUnknown
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
lorenzoni-store.com2026-06-24
stormousransomwareItaly
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
lpgroup2026-06-24
novaransomwareUnknown
Una alerta de ransomware ha afectado a la empresa LP Group, una organización con un perfil de datos complejo y proyectos de gran envergadura en sectores comerciales, logísticos y de servicio...
alejandria2026-06-24
novaransomwareUnited States
El grupo "nova" ha llevado a cabo un ataque de ransomware contra la plataforma "alejandria", una herramienta que facilita el desarrollo de sistemas de teleinformación basados en la arquitect...
transvill2026-06-24
novaransomwareUnited States
Una alerta de ransomware ha sido reportada contra Transvill SRL, una empresa especializada en transporte y logística de carga. El grupo atacante identificado es "nova", y la violación ocurri...
transvill.com.pe2026-06-24
novaransomwarePeru
Una empresa de logística y transporte nacional e internacional, Transvill SRL, ha sido afectada por un ataque cibernético atribuido al grupo malicioso nova. La alerta se publicó el 24 de jun...
Miami Machine2026-06-24
akiraransomwareUnited States
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Cash Canada2026-06-24
qilinransomwareCanada
El 24 de junio de 2026 se registró un incidente de ciberataque que afectó a la organización Cash Canada, una empresa financiera canadiense. El ataque fue atribuido al grupo cibernético denom...
StealthMole: RT by @stealthmole_int: Following the Money: Mapping KidBin's Cryptocurrency Infrastructure Across Darkweb Note: When visiting this blog, you may see a "Sensitive Content" warning from Blogger. This warning is automatically generated by Google's systems based on the topics discussed on the site and does not necessarily indicate the presence of graphic or inappropriate material.2026-06-24
stealthmole_intcampaignUnknown
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
Ido Cohen: We continue to monitor additional sources in the darknet. Here are some of the events that were added to our platform in the last week. 1 A major breach exposed over 500GB of sensitive personal information from job seekers, posing a high risk of identity theft and fraud. 2 Remote access to POS systems is being sold, threatening financial data and sensitive customer information across large retail businesses globally.2026-06-24
ido_cohen2breachUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Frosty Acres Brands2026-06-24
booba-projectransomwareUnited States
Una alerta de ransomware fue publicada el día 24 de junio de 2026 relacionada con la empresa Frosty Acres Brands. El ataque fue atribuido al grupo cibernético Booba Project, quien logró roba...
Meccanica Gn2026-06-24
thegentlemenransomwareItaly
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Al Dhow Group2026-06-24
thegentlemenransomwareUnited Arab Emirates
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.