Uptime Hamster: 39d 1h 31mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
IntelTracker

Threat Intelligence Monitor

Victimas, actores, TTPs, CVEs, IOCs y referencias verificadas en una interfaz CTI indexable con filtros operativos.

10,901Incidentes
870Filtrados
1,119Actores
7,540IOCs visibles
Limpiar
Mapa
47
Paises afectados
Alertas
5,893
Amenazas recientes
Brechas
7,163
Filtraciones y victimas
Hackeos
8,853
Incidentes investigables

Actividad filtrada

TTPs principales

T1566182
T15621

Actores

x-cti38
lockbit518
bushidouk16
ido_cohen214
qilin9
stealthmole_int4
china4
clop4
leakbazaar3
coinbasecartel3

Paises

United States456
United Kingdom36
Brazil19
France18
Canada13
Germany12
Italy11
China10
Russia8
India8

Acciones rapidas

Mapa globalGraficosBrechasPanel clasico

Mapa de actividad

Abrir mapa completo →
United States456 incidentes United Kingdom36 incidentes Brazil19 incidentes France18 incidentes Canada13 incidentes Germany12 incidentes Italy11 incidentes China10 incidentes Russia8 incidentes India8 incidentes Australia8 incidentes Mexico7 incidentes

Filtros directos

RansomwareBrechasCVEsPhishingIntelTracker
870 resultados · pagina 3/25Exportar CSV
Daily Dark Web: Call of Duty: Mobile Internal Offsets Allegedly Released A forum user has shared what they claim is an internal `offsets dump.cs` file for the global version of Call of Duty: Mobile (package: `com.activision.callofduty.shooter`). The post includes a public download link and states the file will be reposted if the original link becomes unavailable.2026-06-28
x-ctibreachUnited States
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: Croatian Student Database Allegedly Shared on Dark Web Forum A threat actor has published what they claim is a database containing approximately 954,000 records related to students from Croatian primary and secondary schools.2026-06-28
x-ctibreachCroatiaT1566
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: French Hospital Patient Database Allegedly Repackaged and Shared A threat actor has published what they claim is a reformatted dataset originating from the 2024 Blackout ransomware leak targeting Centre Hospitalier d'Armentières in France. According to the post, the dataset contains information on approximately 203,928 patients, covering records from 2004 through March 2018.2026-06-28
x-ctiransomwareFranceT1566
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Ido Cohen: New Ransomware Group: Settra Settra has entered the ransomware landscape with 10+ published victims already listed on its leak site. Unlike groups that attempt to justify their actions, Settra openly states its motivation is simple: money. The group claims it does not target specific countries or industries—it targets organizations with exploitable security weaknesses.2026-06-27
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Two ransomware groups are showing a sharp increase in activity during 2026. SafePay Q1 2026: 22 victims Q2 2026: 59 victims (+168%) RALord (Nova) Q1 2026: 14 victims Q2 2026: 60 victims (+329%) Both groups have significantly accelerated their operations in recent months, making them two of the fastest-growing ransomware threats to watch. Track ransomware trends and emerging threat groups with DarkFeed.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ransomware Monitor: Actor: #akira Victim: Precise Forms Date: 2026-06-26 19:01:44 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#akira” Ransomware group has added Precise Forms to its victims.2026-06-26
x-ctiransomwareUnknown
Ransomware monitoring feed tracking new victim disclosures, data leaks and group activity.
Ransomware Monitor: Actor: #nova Victim: NSW Rural Fire Service Date: 2026-06-26 17:15:21 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#nova” Ransomware group has added NSW Rural Fire Service to its victims.2026-06-26
x-ctiransomwareUnknown
Ransomware monitoring feed tracking new victim disclosures, data leaks and group activity.
Ransomware Monitor: Actor: #payload Victim: Software Arge Date: 2026-06-26 17:19:44 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#payload” Ransomware group has added Software Arge to its victims.2026-06-26
x-ctiransomwareUnknown
Ransomware monitoring feed tracking new victim disclosures, data leaks and group activity.
Ransomware Monitor: Actor: #payload Victim: Clínica La Sabana Date: 2026-06-26 17:19:50 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#payload” Ransomware group has added Clínica La Sabana to its victims.2026-06-26
x-ctiransomwareUnknown
Ransomware monitoring feed tracking new victim disclosures, data leaks and group activity.
Ransomware Monitor: Actor: #nova Victim: vslmarine Date: 2026-06-26 14:13:51 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#nova” Ransomware group has added vslmarine to its victims.2026-06-26
x-ctiransomwareUnknown
Ransomware monitoring feed tracking new victim disclosures, data leaks and group activity.
Ransomware Monitor: Actor: #payload Victim: Mosaic Partners Date: 2026-06-26 16:17:54 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#payload” Ransomware group has added Mosaic Partners to its victims.2026-06-26
x-ctiransomwareUnknown
Ransomware monitoring feed tracking new victim disclosures, data leaks and group activity.
Ransomware Monitor: Actor: #ailock Victim: Hokua Date: 2026-06-26 14:38:35 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#ailock” Ransomware group has added Hokua to its victims.2026-06-26
x-ctiransomwareUnknown
Ransomware monitoring feed tracking new victim disclosures, data leaks and group activity.
Ransomware Monitor: Actor: #incransom Victim: GSP Crop Science Pvt Date: 2026-06-26 07:10:34 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#incransom” Ransomware group has added GSP Crop Science Pvt to its victims.2026-06-26
x-ctiransomwareUnknown
Ransomware monitoring feed tracking new victim disclosures, data leaks and group activity.
Ransomware Monitor: Actor: #incransom Victim: Life Bridges Date: 2026-06-26 05:08:35 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#incransom” Ransomware group has added Life Bridges to its victims.2026-06-26
x-ctiransomwareUnknown
Ransomware monitoring feed tracking new victim disclosures, data leaks and group activity.
Ransomware Monitor: Actor: #nightspire Victim: Grupo Riquelme Date: 2026-06-26 03:15:53 UTC+3 According to #DarkWeb #Ransomware activity detected by the ThreatMon Threat Intelligence Team. The “#nightspire” Ransomware group has added Grupo Riquelme to its victims.2026-06-26
x-ctiransomwareUnknown
Ransomware monitoring feed tracking new victim disclosures, data leaks and group activity.
MalwareHunterTeam: A possible interesting, low detected sample that was seen from Italy has @ET_Labs "ET MALWARE Win32/Darkme Trojan Checkin M1" traffic match to that IP address. In case correct, that IP can be related to Evilnum APT... ‍ As soon as @smica83 has time, the sample will be uploaded to Bazaar and then anyone can look. cc @marsomx_ @G609309532026-06-26
malwrhunterteammalwareItaly
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
StealthMole: 𝗗𝗮𝘆 𝟮 𝗶𝘀 𝗶𝗻 𝗳𝘂𝗹𝗹 𝘀𝘄𝗶𝗻𝗴 𝗮𝘁 𝗜𝗻𝘁𝗲𝗿𝗻𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗣𝗼𝗹𝗶𝗰𝗲 𝗘𝘅𝗽𝗼 𝟮𝟬𝟮𝟲! The best part of an event isn't the presentations. It's the conversations happening in between. Day 2 has been full of great discussions, new connections, and live demos at the StealthMole booth. Thank you to everyone who's stopped by so far! If you're at the expo today, come visit us at 𝗕𝗼𝗼𝘁𝗵 𝗔𝟮𝟯. There's still plenty of time to connect, exchange ideas, and see StealthMole in action.2026-06-25
stealthmole_intcampaignUnited States
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
Ido Cohen: Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiations. DarkFeed makes it easy to compare a ransomware group's leak site with the victim's public website in one place, helping analysts quickly identify attacks like these.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Country Spotlight: Canada Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion attacks targeting Canada.2026-06-25
ido_cohen2ransomwareCanadaT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Sector Spotlight: HealthCare Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion groups actively targeting the HealthCare sector.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
StealthMole: RT by @stealthmole_int: Following the Money: Mapping KidBin's Cryptocurrency Infrastructure Across Darkweb Note: When visiting this blog, you may see a "Sensitive Content" warning from Blogger. This warning is automatically generated by Google's systems based on the topics discussed on the site and does not necessarily indicate the presence of graphic or inappropriate material.2026-06-24
stealthmole_intcampaignUnknown
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
Ido Cohen: We continue to monitor additional sources in the darknet. Here are some of the events that were added to our platform in the last week. 1 A major breach exposed over 500GB of sensitive personal information from job seekers, posing a high risk of identity theft and fraud. 2 Remote access to POS systems is being sold, threatening financial data and sensitive customer information across large retail businesses globally.2026-06-24
ido_cohen2breachUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: The Icarus supply chain extortion campaign continues to unfold. The group has now added 5 additional victims, all with their identities partially concealed. The guessing game has officially begun. How many organizations were impacted through this supply chain incident? And are we witnessing the emergence of a serious competitor to CLOP in the supply chain extortion arena? We'll know more soon.2026-06-23
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: APT73 continues to expand its operations. The group has added 3 new victims to its leak site, including a government entity in South America and a major international airport operator in Central Europe serving tens of millions of passengers annually. APT73 was added to the DarkFeed platform in mid-2024 and has since claimed 110+ victims.2026-06-23
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Meet Wallstreet — not the financial market, but the latest ransomware group added to our monitoring platform. The group's leak site currently lists a single victim: a manufacturing company from India. With 1,000+ ransomware and cyber extortion victims already tracked since the beginning of the year, keeping up with the threat landscape is becoming increasingly challenging.2026-06-23
ido_cohen2ransomwareIndiaT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Weekly Ransomware & Cyber Extortion Intelligence Report Our platform continuously monitors ransomware groups and darknet activity worldwide.2026-06-22
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: New Ransomware Groups Added to DarkFeed Over the past few days, we added two new ransomware/extortion groups to the DarkFeed intelligence platform: SevyWare A newly launched RaaS operation claiming ties to former members of established ransomware groups. The operators are actively recruiting Initial Access Brokers and insiders while promoting an aggressive affiliate-focused model.2026-06-21
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Big Panda2026-06-20
chinareferenceChina
Big Panda es un actor APT (Advanced Persistent Threat) vinculado al grupo regional de China. Este grupo ha sido identificado en fuentes OSINT como objetivo de ataques cibernéticos contra emp...
DarkUniverse2026-06-20
chinareferenceChinaT1566
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Returned Libra2026-06-20
chinareferenceChina
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Dark PInk2026-06-20
chinareferenceChina
Dark Pink es un actor APT (Advanced Persistent Threat) asociado al grupo regional de China. Con alias como Saaiwc Group, ASEAN, y otros países asiáticos, este grupo se ha identificado en est...
UNC24522026-06-20
russiareferenceRussia
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Anonymous Sudan2026-06-20
russiareferenceRussia
Anonymous Sudan es un grupo de ciberataques asociado al sector regional: Russia, identificado con alias como storm-1359. Este actor APT (Advanced Persistent Threat) ha sido vinculado a activ...
SilverTerrier2026-06-20
other-actorsreferenceUnited States
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Dark Power2026-06-20
unknown---unmapped-actorsreferenceUnited States
Dark Power representa un riesgo para organizaciones que dependen de sistemas críticos. La presencia de dominios y URLs asociados a este actor sugiere una posible actividad de espionaje ciber...