Skip to content
PUBLICATION & RESEARCH PLATFORM

About Threxar

Threat intelligence published for defenders. Built to give security teams, SOC analysts, and incident responders raw, unvarnished threat data - zero vendor hype, zero paywalls.

What is Threxar

Threxar is an independent threat intelligence publication and research platform dedicated to tracking cybercrime operations, ransomware leak sites, dark web disclosures, and emerging malware campaigns.

DEFENDER-FIRST DISPATCH

We filter out marketing spin and PR announcements. Every report published on Threxar includes verified breach timelines, technical IOC lists, CVSS impact context, and defensive mitigation steps delivered straight to security teams.

Mission

Threxar was founded in 2024 with a single purpose: to give security teams and individual defenders access to the same threat intelligence that previously required expensive vendor contracts or insider access to closed communities.

We monitor the parts of the internet that are difficult, tedious, or genuinely risky to monitor yourself - and we translate what we find into structured, actionable intelligence. No vendor agenda. No marketing spin. Plain language, published openly.

✓ 100% Open Access
No paywalls, compulsory registrations, or sales calls required to access intelligence.
✓ Human + Machine Verification
Automated crawlers augmented by analyst review before publication.
✓ Actionable Artifacts
Every dispatch includes raw hashes, C2 IPs, YARA rules, or CVE parameters.

What We Monitor

Threxar operates a continuous monitoring programme covering five primary intelligence domains. Our methodology combines automated scraping tooling, structured analyst review, and community-sourced tip submissions.

01

Dark Web & Underground Monitoring

TOR, Forums & Marketplaces

Continuous surveillance across closed cybercrime forums, invite-only dark web portals, initial access broker (IAB) marketplaces, and paste sites. We track exposed corporate databases, employee credentials, and stolen session tokens before they are broadly exploited.

02

Ransomware Group Intelligence

120+ Syndicates Tracked

Comprehensive profiling of active double-extortion ransomware syndicates and affiliate networks. We track TOR leak site announcements, negotiation transcripts, exfiltration claims, victim sector distribution, and underlying payment wallets.

03

Malware & Exploit Payload Analysis

Loaders, Stealers & RATs

Static and dynamic reverse engineering of emerging malware families including info-stealers (Vidar, RedLine, StealCraft), loaders, wipers, and mobile spyware. We extract actionable IOC blocks, C2 IP ranges, and YARA detection rules.

04

Vulnerability Research & EPSS Tracking

CVSS 9.0+ & Zero-Day Alerts

Deep analysis of critical vulnerabilities, public exploit PoCs, EPSS (Exploit Prediction Scoring System) likelihood trends, and affected software footprints. We prioritize flaws actively targeted in the wild so defenders can patch ahead of attacks.

05

Threat Actor Profiling & TTP Mapping

APT Clusters & Cybercrime Groups

Long-term attribution and tracking of state-sponsored APT groups and financially motivated cybercrime collectives. TTPs are mapped directly to MITRE ATT&CK frameworks with operational timelines and targeting intelligence.

What We Don't Do

Threxar does not facilitate access to compromised data, dark web markets, or threat actor infrastructure. We do not publish raw credentials, specific forum access links, or step-by-step instructions that would enable harm.

All findings are described at a level appropriate for defensive security teams - enough to understand the threat landscape and inform protective decisions, without creating a roadmap for exploitation.

NON-FACILITATION POLICY
No stolen database downloads, active exploit binaries, or compromised user credentials are hosted on or linked from Threxar servers.

Responsible Disclosure

When our monitoring surfaces information that could cause harm if published without warning - particularly unremediated vulnerabilities or active data exposures - we follow a structured notification process. Affected organisations are notified before public disclosure where possible.

To submit a tip or report something you believe we should investigate, use the contact form →