Uptime Hamster: 10d 6h 32mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza lead

lead

1 incidentes 1 paises 0 sectores Ultimo: 2026-07-09
Aliases: G0023, ELMER backdoor, Gh0st, HTRAN, UNICAT, Poison Ivy, Pandora, APT BLACKGEAR, APT BLACKTECH, matadoor, APT SAGUARO, una reputación de actividad prolongada, "Energy technology", "G20", "NGOs", "Dissident Groups", AdvisorsBot, PoshAdvisor
Ver en IntelTracker → APTTrail →

Aliases del actor

G0023ELMER backdoorGh0stHTRANUNICATPoison IvyPandoraAPT BLACKGEARAPT BLACKTECHmatadoorAPT SAGUAROuna reputación de actividad prolongada"Energy technology""G20""NGOs""Dissident Groups"AdvisorsBotPoshAdvisorotros relacionados con empleados de hotelesrestaurantesreclutadores en telecomunicacionesactividades criminalesPalmerwormPhantom of RoutersG0098PLEADShrouded CrossbowWaterbear

Actores similares

apt-blackgearactor · 1apt-blacktechactor · 1apt-desertfalconactor · 1apt-greyenergyactor · 1apt-poisonneedlesactor · 1apt-saguaroactor · 1apt-stealthfalconactor · 1PhantomControlapt · 0apt-45actor · 2apt-c-27actor · 2

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Forounknownwww.breachsense.comsourcelead.com - RaidForums Data Breach
Forounknowngetbootstrap.comsourcelead.com - RaidForums Data Breach
Forounknowngithub.comsourcelead.com - RaidForums Data Breach
Forounknowngithub.comsourcelead.com - RaidForums Data Breach
Forounknowngithub.comsourcelead.com - RaidForums Data Breach
DLS / leak siteunknownnitter.netIdo Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.
X/Twitterunknownx.comIdo Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.
Forounknownnitter.netDaily Dark Web: Alleged Compromise of Colima State Government Electronic Signature System A threat actor claims to have compromised the Advanced Electronic Signature (Firma Electrónica Avanzada) platform used by the Government of the State of Colima, Mexico. * According to the forum post, the actor alleges they: * Gained administrative access to the portal. * Deleted all user accounts except a single administrator account. * Retained control of the remaining administrative account.
Forounknownx.comDaily Dark Web: Alleged Compromise of Colima State Government Electronic Signature System A threat actor claims to have compromised the Advanced Electronic Signature (Firma Electrónica Avanzada) platform used by the Government of the State of Colima, Mexico. * According to the forum post, the actor alleges they: * Gained administrative access to the portal. * Deleted all user accounts except a single administrator account. * Retained control of the remaining administrative account.
DLS / leak siteunknownnitter.netHackmanac: Cyber Alert ‼ USA - 𝗣𝗼𝗹𝘆𝗺𝗮𝗿𝗸𝗲𝘁 Polymarket confirmed a third-party compromise that enabled attackers to inject malicious code into its website, leading to the theft of user funds. The company contained the incident and will refund affected users. Around the same time, researchers reported a phishing campaign targeting Polymarket users that allegedly stole about US$3 million in cryptocurrency.
X/Twitterunknownx.comHackmanac: Cyber Alert ‼ USA - 𝗣𝗼𝗹𝘆𝗺𝗮𝗿𝗸𝗲𝘁 Polymarket confirmed a third-party compromise that enabled attackers to inject malicious code into its website, leading to the theft of user funds. The company contained the incident and will refund affected users. Around the same time, researchers reported a phishing campaign targeting Polymarket users that allegedly stole about US$3 million in cryptocurrency.
DLS / leak siteunknownduckduckgo.comLEAD (China)
DLS / leak siteunknownduckduckgo.comLEAD (China)
DLS / leak siteunknownduckduckgo.comApache ActiveMQ Exploit Leads to LockBit Ransomware
DLS / leak siteunknownduckduckgo.comApache ActiveMQ Exploit Leads to LockBit Ransomware
DLS / leak siteunknownduckduckgo.comKongTuke FileFix Leads to New Interlock RAT Variant
DLS / leak siteunknownduckduckgo.comKongTuke FileFix Leads to New Interlock RAT Variant
DLS / leak siteunknownduckduckgo.comHide Your RDP: Password Spray Leads to RansomHub Deployment
DLS / leak siteunknownduckduckgo.comHide Your RDP: Password Spray Leads to RansomHub Deployment
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

China (1)

URLs nuevas detectadas en IntelTracker

duckduckgo.com duckduckgo.com

Victimas (1)

LEAD (China)9 Jul 2026
Reference China
Que es LEAD (China) es un actor APT (Advanced Persistent Threat) vinculado al Umbrella Winnti, conocido por su actividad en múltiples sectores, inclui…