Threat Actors Intelligence
Structured intelligence profiles on active ransomware syndicates, APT espionage clusters, initial access brokers, and cybercrime operators monitored by Threxar.
Ransomware Gang● Active
NocturnLock Syndicate
Aliases: NocturnLock, UNC-4921, GHOST_LOCKER
Targeted Sectors:
HealthcareEducationRegional GovernmentManufacturing
Observed Tooling & TTPs:
Cobalt StrikePrintSpooler Privilege EscalationMimikatzChisel SOCKS Proxy
Data Extractor● Active
GhostIntel Group
Aliases: GHOST_INTEL, DataBroker_X, ShadowIntel
Targeted Sectors:
HealthcareFinancial ServicesTelecommunications
Observed Tooling & TTPs:
sqlmapCustom Python Exfiltration ScriptsResidential Proxy MeshTor Mirror Uploaders
Infostealer Operator● Active
StealCraft Operators
Aliases: StealCraft, TA-STEALER-99
Targeted Sectors:
TechnologyE-CommerceFinancial Services
Observed Tooling & TTPs:
StealCraft LoaderProcess Hollowing InjectionEncrypted C2 ProtocolTelegram Bot Exfil
APT Cluster● Active
IronVault Apex
Aliases: IronVault, APT-74, VanguardSpider
Targeted Sectors:
Defense & Government ContractingAerospaceEnergy
Observed Tooling & TTPs:
Custom DLL SideloadingEncrypted TLS TunnelingWebShell BackdoorsPowerSploit
Initial Access Broker● Active
CodeVault Broker
Aliases: CodeVault_Seller, IAB_Alpha
Targeted Sectors:
Software & TechnologySaaS VendorsConsulting
Observed Tooling & TTPs:
MasscanHydra SSH/RDP BruteCookie Stealer ParsersVPN Profile Dumper
Ransomware Gang● Active
BlackByte Syndicate
Aliases: BlackByte, DEV-0882
Targeted Sectors:
ManufacturingLogisticsRetail
Observed Tooling & TTPs:
BYOVD Kernel Driver AbuseAnyDesk Remote AccessNetScanWinRAR Exfil Archives
APT Cluster● Active
KryptonNet Network
Aliases: KryptonGroup, APT-89
Targeted Sectors:
GovernmentDefenseDiplomatic Missions
Observed Tooling & TTPs:
Custom RATPDF ExploitsChisel ProxyPowerShell Empire
Initial Access Broker● Active
ViperAccess Crew
Aliases: ViperAccess, IAB_Viper
Targeted Sectors:
EducationHealthcareEnergy
Observed Tooling & TTPs:
VPN HarvesterCredential DumpersAutomated Scanners
Ransomware Gang● Active
ShadowLocker Gang
Aliases: ShadowLocker, UNC-3310
Targeted Sectors:
Financial ServicesLegalReal Estate
Observed Tooling & TTPs:
ESXi EncryptorCobalt StrikePsExec
Infostealer Operator● Active
AetherStealer Group
Aliases: AetherCrew, TG_Stealers
Targeted Sectors:
E-CommerceCrypto ServicesSaaS
Observed Tooling & TTPs:
AetherStealerTelegram BotsLog Parsers
Have telemetry or findings on a monitored threat actor?
Submit anonymous C2 telemetry, YARA signatures, or ransom note samples to the Threxar threat research team.
Submit Intel →