Uptime Hamster: 37d 2h 46mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
IntelTracker

Threat Intelligence Monitor

Victimas, actores, TTPs, CVEs, IOCs y referencias verificadas en una interfaz CTI indexable con filtros operativos.

10,901Incidentes
115Filtrados
1,119Actores
410IOCs visibles
Limpiar
Mapa
19
Paises afectados
Alertas
5,893
Amenazas recientes
Brechas
7,163
Filtraciones y victimas
Hackeos
8,853
Incidentes investigables

Actividad filtrada

TTPs principales

T156623

Actores

ido_cohen214
x-cti10
malwrhunterteam7
stealthmole_int4
H4ckmanac3
dragonforce2
thegentlemen2
akira2
deadlock1
ta4591

Paises

United States41
China5
Malaysia3
France3
Mexico2
India2
Canada2
Spain1
North Korea1
Iran1

Acciones rapidas

Mapa globalGraficosBrechasPanel clasico

Mapa de actividad

Abrir mapa completo →
United States41 incidentes China5 incidentes Malaysia3 incidentes France3 incidentes Mexico2 incidentes India2 incidentes Canada2 incidentes Spain1 incidentes North Korea1 incidentes Iran1 incidentes Brazil1 incidentes Japan1 incidentes

Filtros directos

RansomwareBrechasCVEsPhishingIntelTracker
115 resultados · pagina 2/4Exportar CSV
Ido Cohen: Country Spotlight: Canada Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion attacks targeting Canada.2026-06-25
ido_cohen2ransomwareCanadaT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Sector Spotlight: HealthCare Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion groups actively targeting the HealthCare sector.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
StealthMole: RT by @stealthmole_int: Following the Money: Mapping KidBin's Cryptocurrency Infrastructure Across Darkweb Note: When visiting this blog, you may see a "Sensitive Content" warning from Blogger. This warning is automatically generated by Google's systems based on the topics discussed on the site and does not necessarily indicate the presence of graphic or inappropriate material.2026-06-24
stealthmole_intcampaignUnknown
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
Ido Cohen: We continue to monitor additional sources in the darknet. Here are some of the events that were added to our platform in the last week. 1 A major breach exposed over 500GB of sensitive personal information from job seekers, posing a high risk of identity theft and fraud. 2 Remote access to POS systems is being sold, threatening financial data and sensitive customer information across large retail businesses globally.2026-06-24
ido_cohen2breachUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Hackmanac: RT by @H4ckmanac: Cyber Alert ‼ Japan - 𝗞𝗗𝗗𝗜 KDDI warned users to change their passwords after disclosing unauthorised access to its email system used by six internet service providers (ISPs), potentially exposing up to 14.22 million email accounts. The compromised information may include email addresses and passwords.2026-06-24
H4ckmanacbreachJapan
Threat intelligence and cyber alert feed covering data breaches, ransomware incidents and vulnerability disclosures.
Ido Cohen: The Icarus supply chain extortion campaign continues to unfold. The group has now added 5 additional victims, all with their identities partially concealed. The guessing game has officially begun. How many organizations were impacted through this supply chain incident? And are we witnessing the emergence of a serious competitor to CLOP in the supply chain extortion arena? We'll know more soon.2026-06-23
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: APT73 continues to expand its operations. The group has added 3 new victims to its leak site, including a government entity in South America and a major international airport operator in Central Europe serving tens of millions of passengers annually. APT73 was added to the DarkFeed platform in mid-2024 and has since claimed 110+ victims.2026-06-23
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Meet Wallstreet — not the financial market, but the latest ransomware group added to our monitoring platform. The group's leak site currently lists a single victim: a manufacturing company from India. With 1,000+ ransomware and cyber extortion victims already tracked since the beginning of the year, keeping up with the threat landscape is becoming increasingly challenging.2026-06-23
ido_cohen2ransomwareIndiaT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Hackmanac: #HackTuesday Hack Tuesday: Week 17 - 23 Jun 2026 374 cyber attacks across 62 countries The most active threat actor last week was NoName057(16) claiming responsibility for 38 cyber attacks. The USA is the most affected country, accounting for 21.4% of incidents, with 80 cyber attacks. The Gov / Mil / LE sector is the most targeted, accounting for 19.5% of incidents with 73 cyber attacks. The estimated Critical cyber attacks account to 54 (14.4% of the total).2026-06-23
H4ckmanaccampaignUnited States
Threat intelligence and cyber alert feed covering data breaches, ransomware incidents and vulnerability disclosures.
Ido Cohen: Weekly Ransomware & Cyber Extortion Intelligence Report Our platform continuously monitors ransomware groups and darknet activity worldwide.2026-06-22
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: New Ransomware Groups Added to DarkFeed Over the past few days, we added two new ransomware/extortion groups to the DarkFeed intelligence platform: SevyWare A newly launched RaaS operation claiming ties to former members of established ransomware groups. The operators are actively recruiting Initial Access Brokers and insiders while promoting an aggressive affiliate-focused model.2026-06-21
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
RedAlpha2026-06-20
chinareferenceChinaT1566
RedAlpha es un actor APT (Advanced Persistent Threat) asociado al grupo regional de China. Conocido también como DeepCliff, Red Dev 3 y otros alias, este grupo ha sido identificado en fuente...
Etumbot2026-06-20
malware---toolsreferenceUnited States
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Ido Cohen: A new ransomware-linked vulnerability has recently been added to DarkFeed's CISA KEV monitoring. CVE-2026-35273 affects Oracle PeopleSoft Enterprise PeopleTools and allows unauthenticated attackers to potentially gain control over vulnerable systems. The vulnerability is already listed in CISA's Known Exploited Vulnerabilities catalog and has been associated with ransomware activity. Organizations using PeopleSoft should prioritize patching and exposure assessment.2026-06-20
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
FortiBleed: exposición masiva de credenciales Fortinet y guía CTI de respuesta2026-06-19
campaignGlobal
FortiBleed es una campaña/filtración de credenciales contra dispositivos Fortinet FortiGate y pasarelas SSL-VPN expuestas a Internet. La evidencia pública no demuestra un zero-day de Fortine...
StealthMole: RT by @stealthmole_int: Government-Related Darkweb/Deepweb Leak Activity — First Week of June 2026 Observed activity consists of 26 government-related leak or sale postings and 4 ransomware/extortion listings tied to public-sector or government-associated entities. The activity is distributed across multiple underground forums and Tor-hosted leak sites, with visible concentration on darkforums, spear, and craxpro.2026-06-10
stealthmole_intransomwareMexico
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
sphvalue.com2026-05-29
dragonforceransomwareUnited States
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
ElDorado2026-05-25
threat-actorUnknown
El Dorado es un grupo de amenaza conocido por su actividad como ransomware, rebrandado en 2026 como BlackLock. Según datos actualizados hasta el 25 de mayo de 2026, el grupo ha afectado a 11...
pandora2026-05-25
threat-actorUnited States
Pandora es un actor de amenaza asociado al ransomware Pandora, que fue obtenido por vx-underground el 14 de marzo de 2022. Se conocen cinco victimas.
ranstreet2026-05-25
threat-actorUnited States
Ranstreet es un grupo de amenaza de tipo ransomware con una presencia limitada en la comunidad de ciberseguridad. Aunque se incluye en listas de ransoming tracking, no existen reportes detal...
redransomware2026-05-25
threat-actorUnited StatesT1566
Red Ransomware (también conocido como Red CryptoApp) emergió en el primer trimestre de 2024, destacándose por su uso de técnicas de doble extorsión y phishing. El grupo se ha especializado e...
rransom2026-05-25
threat-actorUnited States
RRansom es un grupo de amenaza que opera en el entorno oscuro y tiene una presencia limitada en las redes públicas. Su sitio web de difusión en el dark web ha sido listado como inactivo en d...
Scattered Spider2026-05-25
threat-actorUnited StatesT1566
Scattered Spider is a threat actor identified by MITRE as G1015. This native English-speaking cybercriminal group has been active since at least 2022, with operations expanding in 2023 to ne...
Qilin_Qilin2026-05-25
iocUnited States
Qilin_Loader es un indicador de compromiso (IOC) basado en una regla YARA utilizada para detectar el ransomware Qilin. Esta regla fue desarrollada por el analista ravitna y está asociada a l...
BTC bc1q8t2hjln7manplkcl...2026-05-25
iocUnknown
bc1q8t2hjln7manplkclqe5m63fju3888uhmverzza es un Indicador de Compromiso (IOC) asociado al ransomware LockBit, identificado en el contexto de una actividad de extorsión con moneda blockchain...
BTC bc1qna3lkntltdaylku6...2026-05-25
iocUnknown
Btc bc1qna3lkntltdaylku6... es un indicador de compromiso asociado al ataque de ransomware LockBit. Este tipo de cadena de direcciones Bitcoin se identifica como un patrón específico para de...
BTC bc1qszj958vn26yz0pza...2026-05-25
iocUnknown
bc1qszj958vn26yz0pza7ftq9r5g3edfxayf58d32f es un indicador de compromiso (IOC) asociado a una actividad relacionada con el ciberataque de ransomware LockBit. Este tipo de direcciones BTC se ...
BTC bc1qrh5zhmd9lrauc9l0...2026-05-25
iocUnited States
bc1qrh5zhmd9lrauc9l0cuhmdp58cy0c3wfj79e3y7 es un indicador de compromiso (IOC) asociado a la ransomware LockBit, específicamente relacionado con una transacción de pago en Bitcoin. Este tipo...
BTC bc1q7l5l5ku776c52vum...2026-05-25
iocUnited States
bc1q7l5l5ku776c52vumpj2zmgkj8f6z9xyfc38jt6 es un indicador de compromiso (IOC) asociado a una operación de ransomware en el contexto de LockBit. Este valor representa una dirección de Bitcoi...
BTC bc1qlcrlwfhm4ppfqn0d...2026-05-25
iocUnknown
bc1qlcrlwfhm4ppfqn0dpafq98k5dyj2zefmfntl08 es un Indicador de Compromiso (IOC) relacionado con el ransomware LockBit, específicamente asociado a transacciones en Bitcoin. Este valor represen...
BTC bc1qyuu7sqjtc5r5ve54...2026-05-25
iocUnknown
bc1qyuu7sqjtc5r5ve54xu52tq3c3x3jjspr5j7950 es un indicador de compromiso (IOC) asociado al grupo LockBit, un actor criminal conocido por su actividad en ransomware. Este valor corresponde a ...
BTC bc1qvg32acqgse9uqdq0...2026-05-25
iocUnknown
bc1qvg32acqgse9uqdq037kxllpp6v9m48v0llfrh4 es un indicador de compromiso asociado a la actividad de ransomware LockBit. Este valor corresponde a una dirección Bitcoin utilizada en operacione...
BTC bc1qmkn6vswu0l58qt23...2026-05-25
iocUnited States
bc1qmkn6vswu0l58qt23pltzmndqh3l5xf5dnanvsz es un indicador de compromiso (IOC) relacionado con el ransomware LockBit, un grupo malicioso conocido por extorsionar a organizaciones mediante ci...
BTC bc1qklh7fn9j6gewupjx...2026-05-25
iocUnknown
Btc bc1qklh7fn9j6gewupjx5uq4nnxykaxxt0mq450sgw es un indicador de compromiso (IOC) asociado a la amenaza LockBit, un grupo cibernético conocido por su actividad de ransomware. Este tipo de I...
BTC bc1qx3nfn3mtsjm45xtk...2026-05-25
iocUnknown
Indicador de Compromiso (IOC): x-btc-addr:value = 'bc1qx3nfn3mtsjm45xtkta6eh7xsep5xkce5554l58'
BTC bc1qzpkc45ghgj3jh6c0...2026-05-25
iocUnknown
bc1qzpkc45ghgj3jh6c0t9qr783hv7mreqfvtnk72s es un indicador de compromiso (IOC) asociado a la operación de ransomware LockBit, según los datos proporcionados. Este valor corresponde a una dir...