Uptime Hamster: 21d 4h 37mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza lead

lead

1 incidentes 1 paises 0 sectores Ultimo: 2026-07-09
Aliases: una reputación de actividad prolongada, "Energy technology", "G20", "NGOs", "Dissident Groups", AdvisorsBot, PoshAdvisor, otros relacionados con empleados de hoteles, restaurantes, reclutadores en telecomunicaciones, actividades criminales, Palmerworm, Phantom of Routers, G0098, PLEAD, Shrouded Crossbow, Waterbear, G0023
Ver en IntelTracker → APTTrail →

Aliases del actor

una reputación de actividad prolongada"Energy technology""G20""NGOs""Dissident Groups"AdvisorsBotPoshAdvisorotros relacionados con empleados de hotelesrestaurantesreclutadores en telecomunicacionesactividades criminalesPalmerwormPhantom of RoutersG0098PLEADShrouded CrossbowWaterbearG0023ELMER backdoorGh0stHTRANUNICATPoison IvyPandoraAPT BLACKGEARAPT BLACKTECHmatadoorAPT SAGUARO

Actores similares

apt-blackgearactor · 1apt-blacktechactor · 1apt-desertfalconactor · 1apt-greyenergyactor · 1apt-poisonneedlesactor · 1apt-saguaroactor · 1apt-stealthfalconactor · 1PhantomControlapt · 0apt-c-01actor · 2apt-c-27actor · 2

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownduckduckgo.comLEAD (China)
DLS / leak siteunknownduckduckgo.comLEAD (China)
DLS / leak siteunknownduckduckgo.comApache ActiveMQ Exploit Leads to LockBit Ransomware
DLS / leak siteunknownduckduckgo.comApache ActiveMQ Exploit Leads to LockBit Ransomware
DLS / leak siteunknownduckduckgo.comKongTuke FileFix Leads to New Interlock RAT Variant
DLS / leak siteunknownduckduckgo.comKongTuke FileFix Leads to New Interlock RAT Variant
DLS / leak siteunknownduckduckgo.comHide Your RDP: Password Spray Leads to RansomHub Deployment
DLS / leak siteunknownduckduckgo.comHide Your RDP: Password Spray Leads to RansomHub Deployment
Forounknownnitter.netDaily Dark Web: Alleged Compromise of Colima State Government Electronic Signature System A threat actor claims to have compromised the Advanced Electronic Signature (Firma Electrónica Avanzada) platform used by the Government of the State of Colima, Mexico. * According to the forum post, the actor alleges they: * Gained administrative access to the portal. * Deleted all user accounts except a single administrator account. * Retained control of the remaining administrative account.
Forounknownx.comDaily Dark Web: Alleged Compromise of Colima State Government Electronic Signature System A threat actor claims to have compromised the Advanced Electronic Signature (Firma Electrónica Avanzada) platform used by the Government of the State of Colima, Mexico. * According to the forum post, the actor alleges they: * Gained administrative access to the portal. * Deleted all user accounts except a single administrator account. * Retained control of the remaining administrative account.
DLS / leak siteunknownnitter.netIdo Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.
X/Twitterunknownx.comIdo Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.
DLS / leak siteunknownnitter.netHackmanac: Cyber Alert ‼ USA - 𝗣𝗼𝗹𝘆𝗺𝗮𝗿𝗸𝗲𝘁 Polymarket confirmed a third-party compromise that enabled attackers to inject malicious code into its website, leading to the theft of user funds. The company contained the incident and will refund affected users. Around the same time, researchers reported a phishing campaign targeting Polymarket users that allegedly stole about US$3 million in cryptocurrency.
X/Twitterunknownx.comHackmanac: Cyber Alert ‼ USA - 𝗣𝗼𝗹𝘆𝗺𝗮𝗿𝗸𝗲𝘁 Polymarket confirmed a third-party compromise that enabled attackers to inject malicious code into its website, leading to the theft of user funds. The company contained the incident and will refund affected users. Around the same time, researchers reported a phishing campaign targeting Polymarket users that allegedly stole about US$3 million in cryptocurrency.
Forounknownwww.breachsense.comsourcelead.com - RaidForums Data Breach
Forounknowngetbootstrap.comsourcelead.com - RaidForums Data Breach
Forounknowngithub.comsourcelead.com - RaidForums Data Breach
Forounknowngithub.comsourcelead.com - RaidForums Data Breach
Forounknowngithub.comsourcelead.com - RaidForums Data Breach
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

China (1)

URLs nuevas detectadas en IntelTracker

duckduckgo.com duckduckgo.com

Victimas (1)

LEAD (China)9 Jul 2026
Reference China
Que es LEAD (China) es un actor APT (Advanced Persistent Threat) vinculado al Umbrella Winnti, conocido por su actividad en múltiples sectores, inclui…