Threat actors
Ransomware victim watch

Live overview of groups and claimed victims

By default this layer shows potential victims from the last 3 days. Use search to query the stored history.

Loading

One moment, our live darknet feed is loading

Once the feed arrives, the most active ransomware groups appear here.

Victim Group Country / sector Claim date
Feed loading ... ... ...
Victim digest

Receive new victim claims by email

Choose a daily overview for the last 24 hours or a weekly overview for the previous week. The email explicitly states that these are darknet and feed claims, not confirmed incidents.

Account required

Log in or create a free account

We link this email preference to your account, so you can later choose daily, weekly or off yourself.

Featured dossiers

Actor profiles that belong here first

Not because these are the only relevant actors, but because they show how different motivation, access and impact can be.

Ransomware · High

Qilin / ransomware clusters

Double extortion, supply chain pressure and rapid impact on production and healthcare environments.

  • Access: Edge exposure, brokers, misconfigurations and stolen credentials.
  • Watch for: Privilege escalation, data theft tooling and pressure on business continuity.
Espionage · Targeted

APT29 / diplomatic espionage

Longer dwell time, quiet cloud abuse scenarios and high-value targets.

  • Access: Phishing, OAuth abuse, trusted cloud channels and stealthy persistence.
  • Watch for: Identity hygiene, mailbox rules, delegated grants and admin activity.
Identity abuse · Accelerating

Scattered Spider-like operators

Social engineering, helpdesk abuse and cloud access through identity bypass.

  • Access: SIM swap, helpdesk routes, MFA fatigue and privilege abuse.
  • Watch for: Conditional Access, admin separation and recovery accounts.
Actor families

Which main groups matter most for organisations

The live version should show a clear pattern not only per actor, but also per actor family.

Ransomware operators

The highest visibility is often around ransomware groups, but the real value of actor profiling lies in access patterns, brokers, tooling and the pace at which business pressure is created.

  • Strong focus on impact, public pressure and recovery cost
  • Often dependent on IABs, exposed edge or identity abuse
  • Highly relevant to leadership, continuity and insurability

Espionage and state-linked actors

This is less about visible disruption and more about quiet access, long-term presence and targeted information advantage. Executive relevance sits mainly in provability, governance and confidentiality.

  • More stealth, longer dwell time and more cloud-focused tradecraft
  • Strong emphasis on identities, mail and app access
  • More relevant to government, semi-public and diplomatic chains

Ecosystem actors and brokers

Not every actor is the final attacker. Brokers, stealer ecosystems and access resellers create the fuel other campaigns build on. That layer is critical for early warning.

  • Credentials and sessions are the core issue
  • Strong overlap with infostealers, phishing and dark web resale
  • Highly relevant for monitoring and access hygiene prioritisation