Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.
| Tipo | Estado | Host / enlace | Title / ultimo titulo |
|---|---|---|---|
| Repositorio | unknown | github.com | BushidoUK ToolMatrix ThreatIntel: CISAThreatGroups |
| Repositorio | unknown | github.com | BushidoUK ToolMatrix ThreatIntel: TrendMicroThreatGroups |
| Repositorio | unknown | github.com | BushidoUK ToolMatrix ThreatIntel: TheDFIRReportGroups |
| Repositorio | unknown | github.com | BushidoUK ToolMatrix ThreatIntel: TrendMicroThreatGroups |
| DLS / leak site | unknown | www.breachsense.com | upstatehomecare.com - Pysa Data Breach |
| DLS / leak site | unknown | getbootstrap.com | upstatehomecare.com - Pysa Data Breach |
| Repositorio | unknown | github.com | upstatehomecare.com - Pysa Data Breach |
| DLS / leak site | unknown | www.breachsense.com | tkemlups.ca - Conti Data Breach |
| DLS / leak site | unknown | duckduckgo.com | tkemlups.ca - Conti Data Breach |
| DLS / leak site | unknown | duckduckgo.com | tkemlups.ca - Conti Data Breach |
| DLS / leak site | unknown | nitter.net | Ido Cohen: New Ransomware Group: Settra Settra has entered the ransomware landscape with 10+ published victims already listed on its leak site. Unlike groups that attempt to justify their actions, Settra openly states its motivation is simple: money. The group claims it does not target specific countries or industries—it targets organizations with exploitable security weaknesses. |
| X/Twitter | unknown | x.com | Ido Cohen: New Ransomware Groups Added to DarkFeed Over the past few days, we added two new ransomware/extortion groups to the DarkFeed intelligence platform: SevyWare A newly launched RaaS operation claiming ties to former members of established ransomware groups. The operators are actively recruiting Initial Access Brokers and insiders while promoting an aggressive affiliate-focused model. |
| DLS / leak site | unknown | nitter.net | Ido Cohen: Two ransomware groups are showing a sharp increase in activity during 2026. SafePay Q1 2026: 22 victims Q2 2026: 59 victims (+168%) RALord (Nova) Q1 2026: 14 victims Q2 2026: 60 victims (+329%) Both groups have significantly accelerated their operations in recent months, making them two of the fastest-growing ransomware threats to watch. Track ransomware trends and emerging threat groups with DarkFeed. |
| DLS / leak site | unknown | nitter.net | Ido Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats. |
| DLS / leak site | unknown | nitter.net | Ido Cohen: Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiations. DarkFeed makes it easy to compare a ransomware group's leak site with the victim's public website in one place, helping analysts quickly identify attacks like these. |
| DLS / leak site | up | nitter.net | Ido Cohen: Sector Spotlight: HealthCare Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion groups actively targeting the HealthCare sector. |
| DLS / leak site | up | nitter.net | Ido Cohen: Meet Wallstreet — not the financial market, but the latest ransomware group added to our monitoring platform. The group's leak site currently lists a single victim: a manufacturing company from India. With 1,000+ ransomware and cyber extortion victims already tracked since the beginning of the year, keeping up with the threat landscape is becoming increasingly challenging. |
| DLS / leak site | unknown | nitter.net | Ido Cohen: Threat Group Update Prinz Eugen has launched a newly redesigned leak site and updated its public profile. According to the group's latest statement, it describes itself as a for-profit organization that "specializes in hacking" while claiming it currently does not operate a Ransomware-as-a-Service (RaaS) program. The group also stated that membership intake is currently closed and limited to existing core members. |
| DLS / leak site | up | nitter.net | Ido Cohen: Weekly Ransomware & Cyber Extortion Intelligence Report Our platform continuously monitors ransomware groups and darknet activity worldwide. |
| DLS / leak site | unknown | nitter.net | Ido Cohen: New Ransomware Groups Added to DarkFeed Over the past few days, we added two new ransomware/extortion groups to the DarkFeed intelligence platform: SevyWare A newly launched RaaS operation claiming ties to former members of established ransomware groups. The operators are actively recruiting Initial Access Brokers and insiders while promoting an aggressive affiliate-focused model. |
| DLS / leak site | unknown | nitter.net | Dark Web Informer: ‼ New Ransomware Group: SETTRA htttp://settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd[.]onion |
| Foro | unknown | x.com | Dark Web Informer: Why would a Ransomware affiliate to well known groups use the terminology "pro hacker?" Ransomware recruitment solicitation posted on a forum A Dread user is seeking a “pro hacker” for a project they claim could generate millions. The user claims affiliation with ransomware-related structures and appears to be looking for help compromising or gaining control of server/admin access for a small team. |
| Foro | unknown | nitter.net | Dark Web Informer: Why would a Ransomware affiliate to well known groups use the terminology "pro hacker?" Ransomware recruitment solicitation posted on a forum A Dread user is seeking a “pro hacker” for a project they claim could generate millions. The user claims affiliation with ransomware-related structures and appears to be looking for help compromising or gaining control of server/admin access for a small team. |