Uptime Hamster: 21d 2h 14mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
IntelTracker

Threat Intelligence Monitor

Victimas, actores, TTPs, CVEs, IOCs y referencias verificadas en una interfaz CTI indexable con filtros operativos.

10,901Incidentes
878Filtrados
1,119Actores
645IOCs visibles
Limpiar
Mapa
76
Paises afectados
Alertas
5,893
Amenazas recientes
Brechas
7,163
Filtraciones y victimas
Hackeos
8,853
Incidentes investigables

Actividad filtrada

TTPs principales

T1566240
T10401
T15551

Actores

qilin118
thegentlemen59
akira51
dragonforce46
incransom40
play34
nightspire23
lockbit521
clop19
sinobi15

Paises

United States396
United Kingdom35
Germany29
France25
Canada24
Spain16
Brazil16
Italy15
India14
China13

Acciones rapidas

Mapa globalGraficosBrechasPanel clasico

Mapa de actividad

Abrir mapa completo →
United States396 incidentes United Kingdom35 incidentes Germany29 incidentes France25 incidentes Canada24 incidentes Spain16 incidentes Brazil16 incidentes Italy15 incidentes India14 incidentes China13 incidentes Japan13 incidentes Thailand12 incidentes

Filtros directos

RansomwareBrechasCVEsPhishingIntelTracker
878 resultados · pagina 3/25Exportar CSV
Ido Cohen: Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiations. DarkFeed makes it easy to compare a ransomware group's leak site with the victim's public website in one place, helping analysts quickly identify attacks like these.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Country Spotlight: Canada Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion attacks targeting Canada.2026-06-25
ido_cohen2ransomwareCanadaT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Sector Spotlight: HealthCare Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion groups actively targeting the HealthCare sector.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Quest Health Solutions2026-06-24
anubisransomwareUnited States
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Jit Ex2026-06-24
akiraransomwareUnited States
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
kliknklik.com2026-06-23
apt73ransomwareIndonesia
El 23 de junio de 2026 se registró un ataque de ransomware contra la empresa kliknklik.com, una empresa indonesa que opera como distribuidor y retailer de equipos informáticos. El incidente ...
Ido Cohen: Meet Wallstreet — not the financial market, but the latest ransomware group added to our monitoring platform. The group's leak site currently lists a single victim: a manufacturing company from India. With 1,000+ ransomware and cyber extortion victims already tracked since the beginning of the year, keeping up with the threat landscape is becoming increasingly challenging.2026-06-23
ido_cohen2ransomwareIndiaT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Weekly Ransomware & Cyber Extortion Intelligence Report Our platform continuously monitors ransomware groups and darknet activity worldwide.2026-06-22
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Rowley Properties2026-06-22
thegentlemenransomwareUnited Kingdom
Una empresa de propiedad inmobiliaria basada en Washington, Rowley Properties, ha sido afectada por un ataque de ransomware atribuido al grupo "thegentlemen". La empresa, fundada en 1954 y e...
Sivatel Bangkok2026-06-21
qilinransomwareThailand
El 21 de junio de 2026, la empresa Sivatel Bangkok fue objeto de un ataque cibernético atribuido al grupo cybercriminal "qilin". Este incidente se clasifica como un ataque de ransomware, don...
Wall ISD2026-06-21
cmdorganizationransomwareUnited States
El 21 de junio de 2026, la institución educativa Wall ISD en Texas fue afectada por un ataque cibernético de tipo ransomware atribuido al grupo cmdorganization. Este incidente representa una...
Ido Cohen: New Ransomware Groups Added to DarkFeed Over the past few days, we added two new ransomware/extortion groups to the DarkFeed intelligence platform: SevyWare A newly launched RaaS operation claiming ties to former members of established ransomware groups. The operators are actively recruiting Initial Access Brokers and insiders while promoting an aggressive affiliate-focused model.2026-06-21
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
jaggroup.com UPDATE-FULL DATA DUMP2026-06-20
stormousransomwareUnited States
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
UPS2026-06-20
chinareferenceChina
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Poisonous Panda2026-06-20
chinareferenceChina
Poisonous Panda es un actor APT (Advanced Persistent Threat) asociado al grupo regional de China, con alias como Energy technology, G20, NGOs y Dissident Groups. Este grupo ha sido documenta...
Toxic Panda2026-06-20
chinareferenceChina
Toxic Panda es un actor APT (Advanced Persistent Threat) asociado al grupo regional de China. Conocido también como Umbrella Revolution, Dissident Groups y Listed slide 4, este grupo ha sido...
Magic Kitten appears to be among the oldest and most elaborate threat actors originating in Iran. It is also distinct from other groups because of its apparent relationship with the Iranian Ministry of Intelligence rather than the IRGC. However2026-06-20
iranreferenceIran
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Dosab2026-06-20
novaransomwareSaudi Arabia
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Pinnacle Re-Tec2026-06-20
cmdorganizationransomwareUnited States
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
FortiBleed: exposición masiva de credenciales Fortinet y guía CTI de respuesta2026-06-19
campaignGlobal
FortiBleed es una campaña/filtración de credenciales contra dispositivos Fortinet FortiGate y pasarelas SSL-VPN expuestas a Internet. La evidencia pública no demuestra un zero-day de Fortine...
Cofaq2026-06-18
thegentlemenransomwareFrance
Una alerta de ransomware afectó a Cofaq, una importante cooperativa francesa especializada en distribución de herramientas industriales y equipos agrícolas. El ataque, atribuido al grupo the...
Horizon Family Medical Group2026-06-18
incransomransomwareUnited States
Horizon Family Medical Group ha sido objeto de un ataque de ransomware grave que comprometió 7 terabytes de datos críticos, incluyendo registros médicos y bases de datos financieras. La empr...
www.wolfconstruction.net2026-06-18
lynxransomwareUnited States
La empresa Wolf Construction Services, Inc., especializada en servicios de construcción y tejas inclinadas, ha sido afectada por un ataque de ransomware atribuido al grupo cibernético lynx. ...
www.eastersealsia.org2026-06-18
lynxransomwareSingapore
www.eastersealsia.org ha sido identificada como un objetivo potencial de ataque cibernético según la alerta de ransomware del grupo lynx. La organización, que proporciona servicios de tecnol...
apt-c-60 indicators and references2026-06-18
apt-c-60iocUnknown
APTTrail mantiene indicadores publicos asociados a apt-c-60. Aliases observados: apt-c-60, apt-q-12, spyglace. Conteo por tipo: domain: 4, ipv4: 5, url: 5.
aa22-264a indicators and references2026-06-18
aa22-264aiocIran
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
bisonal indicators and references2026-06-18
bisonaliocUnited States
APTTrail mantiene indicadores publicos asociados a bisonal. Aliases observados: bisonal, tonto, tontoteam. Conteo por tipo: domain: 232, file_path: 5, ipv4: 5, url: 4.
apt-c-3 indicators and references2026-06-18
apt-c-3iocUnknown
APTTrail mantiene indicadores publicos asociados a apt-c-3. Aliases observados: apt-c-3, apt3, ups. Conteo por tipo: domain: 10.
danbot indicators and references2026-06-18
danbotiocRussia
APTTrail mantiene indicadores publicos asociados a danbot. Aliases observados: danbot, hexane, lyceum. Conteo por tipo: domain: 45, ipv4: 7.
apt-c-43 indicators and references2026-06-18
apt-c-43iocRussia
APTTrail mantiene indicadores publicos asociados a apt-c-43. Aliases observados: apt-c-43, apt43. Conteo por tipo: domain: 34, ipv4: 2, url: 1.
APT PEGASUS indicators and references2026-06-18
apt-pegasusiocCanada
APTTrail mantiene indicadores publicos asociados a APT PEGASUS. Aliases observados: APT PEGASUS. Conteo por tipo: domain: 1523.
APT RAMPANTKITTEN indicators and references2026-06-18
apt-rampantkitteniocIran
APTTrail mantiene indicadores publicos asociados a APT RAMPANTKITTEN. Aliases observados: APT RAMPANTKITTEN. Conteo por tipo: domain: 19.
APT REAPER indicators and references2026-06-18
apt-reaperiocUnknown
APTTrail mantiene indicadores publicos asociados a APT REAPER. Aliases observados: APT REAPER. Conteo por tipo: domain: 19, file_path: 1.
APT REDFOXTROT indicators and references2026-06-18
apt-redfoxtrotiocUnknown
APTTrail mantiene indicadores publicos asociados a APT REDFOXTROT. Aliases observados: APT REDFOXTROT. Conteo por tipo: domain: 144, ipv4: 4.
APT TIBET indicators and references2026-06-18
apt-tibetiocUnknown
APTTrail mantiene indicadores publicos asociados a APT TIBET. Aliases observados: APT TIBET. Conteo por tipo: domain: 48, ipv4: 3.
BushidoUK ToolMatrix Tools: DiscoveryEnum2026-06-18
bushidoukreportUnited States
Recurso del BushidoUK Ransomware Tool Matrix - Tools.