Uptime Hamster: 35d 18h 39mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
IntelTracker

Threat Intelligence Monitor

Victimas, actores, TTPs, CVEs, IOCs y referencias verificadas en una interfaz CTI indexable con filtros operativos.

10,901Incidentes
2,074Filtrados
1,119Actores
3,550IOCs visibles
Limpiar
Mapa
87
Paises afectados
Alertas
5,893
Amenazas recientes
Brechas
7,163
Filtraciones y victimas
Hackeos
8,853
Incidentes investigables

Actividad filtrada

TTPs principales

T15662072

Actores

qilin210
thegentlemen80
akira65
dragonforce60
lockbit553
clop48
nightspire42
incransom41
coinbasecartel29
krybit25

Paises

United States1018
United Kingdom60
China59
Germany55
France45
Canada42
Spain35
Australia33
Italy27
India24

Acciones rapidas

Mapa globalGraficosBrechasPanel clasico

Mapa de actividad

Abrir mapa completo →
United States1018 incidentes United Kingdom60 incidentes China59 incidentes Germany55 incidentes France45 incidentes Canada42 incidentes Spain35 incidentes Australia33 incidentes Italy27 incidentes India24 incidentes Brazil22 incidentes Mexico17 incidentes

Filtros directos

RansomwareBrechasCVEsPhishingIntelTracker
2,074 resultados · pagina 3/58Exportar CSV
Ransomware Group: sparta2026-06-29
spartathreat-actorSpainT1566
Perfil del grupo segun ransomware.anggipradana.com.
Ransomware Group: u-bomb2026-06-29
u-bombthreat-actorUnknownT1566
Perfil del grupo segun ransomware.anggipradana.com.
Ido Cohen: The attackers never rest... and neither do we. Meet RedAct, a newly tracked ransomware group. The group has already published 2 victims and states that it is driven purely by financial gain—not politics or hacktivism. According to its public message, organizations that refuse to negotiate or fail to meet ransom demands should expect their stolen data to be published. Another emerging threat worth keeping on your radar.2026-06-28
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Daily Dark Web: Clearcover Customer Data Allegedly Offered for Sale A threat actor claims to be selling a database allegedly belonging to U.S. auto insurer Clearcover. * According to the forum post, the dataset is dated **25 June 2026** and allegedly contains **448,603** records.2026-06-28
x-ctibreachUnknownT1566
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: Croatian Student Database Allegedly Shared on Dark Web Forum A threat actor has published what they claim is a database containing approximately 954,000 records related to students from Croatian primary and secondary schools.2026-06-28
x-ctibreachCroatiaT1566
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: French Hospital Patient Database Allegedly Repackaged and Shared A threat actor has published what they claim is a reformatted dataset originating from the 2024 Blackout ransomware leak targeting Centre Hospitalier d'Armentières in France. According to the post, the dataset contains information on approximately 203,928 patients, covering records from 2004 through March 2018.2026-06-28
x-ctiransomwareFranceT1566
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Hackmanac: #PollResults Turns out what worries you most for H2 2026 is 𝐒𝐮𝐩𝐩𝐥𝐲 𝐂𝐡𝐚𝐢𝐧 𝐚𝐭𝐭𝐚𝐜𝐤𝐬 (𝟑𝟒%). Thanks to everyone who voted and see you at next #MondayPoll!2026-06-28
H4ckmanacransomwareUnknownT1566
Threat intelligence and cyber alert feed covering data breaches, ransomware incidents and vulnerability disclosures.
Ido Cohen: New Ransomware Group: Settra Settra has entered the ransomware landscape with 10+ published victims already listed on its leak site. Unlike groups that attempt to justify their actions, Settra openly states its motivation is simple: money. The group claims it does not target specific countries or industries—it targets organizations with exploitable security weaknesses.2026-06-27
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Two ransomware groups are showing a sharp increase in activity during 2026. SafePay Q1 2026: 22 victims Q2 2026: 59 victims (+168%) RALord (Nova) Q1 2026: 14 victims Q2 2026: 60 victims (+329%) Both groups have significantly accelerated their operations in recent months, making them two of the fastest-growing ransomware threats to watch. Track ransomware trends and emerging threat groups with DarkFeed.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Hackmanac: Cyber Alert ‼ USA - 𝗣𝗼𝗹𝘆𝗺𝗮𝗿𝗸𝗲𝘁 Polymarket confirmed a third-party compromise that enabled attackers to inject malicious code into its website, leading to the theft of user funds. The company contained the incident and will refund affected users. Around the same time, researchers reported a phishing campaign targeting Polymarket users that allegedly stole about US$3 million in cryptocurrency.2026-06-26
H4ckmanacphishingUnited StatesT1566
Threat intelligence and cyber alert feed covering data breaches, ransomware incidents and vulnerability disclosures.
Ido Cohen: Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiations. DarkFeed makes it easy to compare a ransomware group's leak site with the victim's public website in one place, helping analysts quickly identify attacks like these.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Country Spotlight: Canada Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion attacks targeting Canada.2026-06-25
ido_cohen2ransomwareCanadaT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Sector Spotlight: HealthCare Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion groups actively targeting the HealthCare sector.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: We continue to monitor additional sources in the darknet. Here are some of the events that were added to our platform in the last week. 1 A major breach exposed over 500GB of sensitive personal information from job seekers, posing a high risk of identity theft and fraud. 2 Remote access to POS systems is being sold, threatening financial data and sensitive customer information across large retail businesses globally.2026-06-24
ido_cohen2breachUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Beran Concrete2026-06-24
thegentlemenransomwareCzech RepublicT1566
Una empresa de construcción y mezcla in situ en Wichita, Kansas, ha sido afectada por un ataque de ransomware. La organización, Beran Concrete, se especializa en proyectos comerciales y resi...
Reynella East College2026-06-23
interlockransomwareAustraliaT1566
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Ido Cohen: The Icarus supply chain extortion campaign continues to unfold. The group has now added 5 additional victims, all with their identities partially concealed. The guessing game has officially begun. How many organizations were impacted through this supply chain incident? And are we witnessing the emergence of a serious competitor to CLOP in the supply chain extortion arena? We'll know more soon.2026-06-23
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: APT73 continues to expand its operations. The group has added 3 new victims to its leak site, including a government entity in South America and a major international airport operator in Central Europe serving tens of millions of passengers annually. APT73 was added to the DarkFeed platform in mid-2024 and has since claimed 110+ victims.2026-06-23
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Meet Wallstreet — not the financial market, but the latest ransomware group added to our monitoring platform. The group's leak site currently lists a single victim: a manufacturing company from India. With 1,000+ ransomware and cyber extortion victims already tracked since the beginning of the year, keeping up with the threat landscape is becoming increasingly challenging.2026-06-23
ido_cohen2ransomwareIndiaT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
NationsBuilders Insurance Services2026-06-22
auroraransomwareUnknownT1566
Una alerta de ransomware ha afectado a NationsBuilders Insurance Services, una empresa especializada en seguros para industrias específicas como la construcción y el transporte pesado. El at...
Ido Cohen: Threat Group Update Prinz Eugen has launched a newly redesigned leak site and updated its public profile. According to the group's latest statement, it describes itself as a for-profit organization that "specializes in hacking" while claiming it currently does not operate a Ransomware-as-a-Service (RaaS) program. The group also stated that membership intake is currently closed and limited to existing core members.2026-06-22
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Weekly Ransomware & Cyber Extortion Intelligence Report Our platform continuously monitors ransomware groups and darknet activity worldwide.2026-06-22
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Hackmanac: RT by @H4ckmanac: #MondayPoll: What worries you most for H2 2026?2026-06-22
H4ckmanacransomwareUnknownT1566
Threat intelligence and cyber alert feed covering data breaches, ransomware incidents and vulnerability disclosures.
Hooke Laboratories2026-06-22
thegentlemenransomwareUnited StatesT1566
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Ido Cohen: Supply Chain Extortion Alert The Icarus ransomware group has escalated pressure tactics against a major Canadian consulting and competitive intelligence provider. After initially naming the organization, the group is now threatening to release data belonging to the company's clients, giving them a deadline to make contact before publication begins.2026-06-21
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: New Ransomware Groups Added to DarkFeed Over the past few days, we added two new ransomware/extortion groups to the DarkFeed intelligence platform: SevyWare A newly launched RaaS operation claiming ties to former members of established ransomware groups. The operators are actively recruiting Initial Access Brokers and insiders while promoting an aggressive affiliate-focused model.2026-06-21
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
APT22026-06-20
chinareferenceChinaT1566
APT2 es un grupo de actores maliciosos asociado al sector regional de China, conocido por sus operaciones de espionaje dirigidas a sectores críticos en Estados Unidos. Con alias como Putter ...
IXESHE2026-06-20
chinareferenceChinaT1566
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
APT162026-06-20
chinareferenceChinaT1566
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Impersonating Panda2026-06-20
chinareferenceChinaT1566
Impersonating Panda es un actor APT (Advanced Persistent Threat) vinculado al grupo regional de China, conocido por su enfoque en el sector financiero. Este grupo, también llamado Financial ...
Judgement Panda2026-06-20
chinareferenceChinaT1566
Judgement Panda es un actor APT (Advanced Persistent Threat) asociado al grupo regional de China. Conocido también como Umbrella Revolution, este grupo se ha enfocado en actividades de spear...
DarkUniverse2026-06-20
chinareferenceChinaT1566
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Storm Cloud2026-06-20
chinareferenceChinaT1566
Storm Cloud es un actor APT (Advanced Persistent Threat) asociado al grupo regional de China, con aliases como Holy Water, Godlike12, SweetAlerts y Strategic web compromise (watering hole). ...
TA4102026-06-20
chinareferenceChinaT1566
Ta410 es un actor APT (Advanced Persistent Threat) vinculado al grupo regional de China. Este grupo, conocido por sus alias como Witchetty, FlowingFrog, LookingFrog, entre otros, ha sido ide...
Earth Berberoka2026-06-20
chinareferenceChinaT1566
Earth Berberoka es un actor APT (Advanced Persistent Threat) vinculado al grupo regional de China. Conocido también como GamblingPuppet , este grupo está asociado a organizaciones gubernamen...