One moment, our live darknet feed is loading
Once the feed arrives, the most active ransomware groups appear here.
By default this layer shows potential victims from the last 3 days. Use search to query the stored history.
Once the feed arrives, the most active ransomware groups appear here.
Choose a daily overview for the last 24 hours or a weekly overview for the previous week. The email explicitly states that these are darknet and feed claims, not confirmed incidents.
We link this email preference to your account, so you can later choose daily, weekly or off yourself.
Not because these are the only relevant actors, but because they show how different motivation, access and impact can be.
Double extortion, supply chain pressure and rapid impact on production and healthcare environments.
Longer dwell time, quiet cloud abuse scenarios and high-value targets.
Social engineering, helpdesk abuse and cloud access through identity bypass.
The live version should show a clear pattern not only per actor, but also per actor family.
The highest visibility is often around ransomware groups, but the real value of actor profiling lies in access patterns, brokers, tooling and the pace at which business pressure is created.
This is less about visible disruption and more about quiet access, long-term presence and targeted information advantage. Executive relevance sits mainly in provability, governance and confidentiality.
Not every actor is the final attacker. Brokers, stealer ecosystems and access resellers create the fuel other campaigns build on. That layer is critical for early warning.