Uptime Hamster: 10d 5h 58mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
IntelTracker

Threat Intelligence Monitor

Victimas, actores, TTPs, CVEs, IOCs y referencias verificadas en una interfaz CTI indexable con filtros operativos.

11,126Incidentes
116Filtrados
1,127Actores
410IOCs visibles
Limpiar
Mapa
19
Paises afectados
Alertas
6,108
Amenazas recientes
Brechas
7,383
Filtraciones y victimas
Hackeos
9,074
Incidentes investigables

Actividad filtrada

TTPs principales

T156623

Actores

ido_cohen214
malwrhunterteam7
DarkWebInformer6
stealthmole_int4
DailyDarkWeb4
H4ckmanac3
dragonforce2
thegentlemen2
akira2
qilin1

Paises

United States42
China5
Malaysia3
France3
Mexico2
India2
Canada2
Spain1
North Korea1
Iran1

Acciones rapidas

Mapa globalGraficosBrechasPanel clasico

Mapa de actividad

Abrir mapa completo →
United States42 incidentes China5 incidentes Malaysia3 incidentes France3 incidentes Mexico2 incidentes India2 incidentes Canada2 incidentes Spain1 incidentes North Korea1 incidentes Iran1 incidentes Brazil1 incidentes Japan1 incidentes

Filtros directos

RansomwareBrechasCVEsPhishingIntelTracker
116 resultados · pagina 1/4Exportar CSV
Don Tortaco Mexican Grill2026-07-19
qilinransomwareUnited States
El 19 de julio de 2026, la empresa Don Tortaco Mexican Grill fue afectada por un ataque cibernético relacionado con ransomware. Según los registros de seguridad compartidos, el grupo malicio...
ADM Value Barcelona2026-07-10
deadlockransomwareSpain
Una alerta de ransomware ha afectado a ADM Value Barcelona, una empresa internacional especializada en gestión de relaciones con clientes (CRM) y outsourcing de procesos comerciales (BPO). E...
TA459 (China)2026-07-09
ta459referenceChina
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Iron Group (China)2026-07-09
iron-groupreferenceChina
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Eloquent Panda (China)2026-07-09
eloquent-pandareferenceChina
Eloquent Panda es un grupo de ciberataques asociado a China, reconocido como un Actor APT (Advanced Persistent Threat). Este actor se ha destacado por su actividad en el ámbito de la ciberse...
Night Dragon (China)2026-07-09
night-dragonreferenceChinaT1566
Night Dragon es un actor APT (Advanced Persistent Threat) originario de China, conocido por su actividad en el sector energético y petrolero. Se le conoce también como G0014, y se ha asociad...
OnionDog (North Korea)2026-07-09
oniondogreferenceNorth Korea
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Smoke Sandstorm,Cuboid Sandstorm,Yellow Liderc,TA456,APT35,ImperialKitten (Iran)2026-07-09
smoke-sandstorm-cuboid-sareferenceIran
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
ROKRAT (Malware / Tools)2026-07-09
rokratreferenceUnknown
ROKRAT es un actor APT (Advanced Persistent Threat) asociado a actividades de ciberataque, con enfoque en malware y herramientas maliciosas. Se identifica como una organización basada en Cor...
orion4value.com2026-07-03
settraransomwareUnknown
Resumen no disponible. Abre la ficha para ver los detalles normalizados del incidente.
Ransomware Group: ransomhub2026-06-29
ransomhubthreat-actorUnited States
Perfil del grupo segun ransomware.anggipradana.com.
StealthMole: RT by @stealthmole_int: We traced the threat actor behind the defacement of Malaysia's Ministry of Health (MOH) website. Our investigation found that the actor has been active on Telegram since 2024, participating in multiple channels related to hacking forums, web shells, spam, hacking tools, and data leaks.2026-06-29
stealthmole_intbreachMalaysia
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
StealthMole: We traced the threat actor behind the defacement of Malaysia's Ministry of Health (MOH) website. Our investigation found that the actor has been active on Telegram since 2024, participating in multiple channels related to hacking forums, web shells, spam, hacking tools, and data leaks.2026-06-29
stealthmole_intbreachMalaysia
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
Ido Cohen: The attackers never rest... and neither do we. Meet RedAct, a newly tracked ransomware group. The group has already published 2 victims and states that it is driven purely by financial gain—not politics or hacktivism. According to its public message, organizations that refuse to negotiate or fail to meet ransom demands should expect their stolen data to be published. Another emerging threat worth keeping on your radar.2026-06-28
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Dark Web Informer: RT by @DarkWebInformer: ‼ CVE-2026-48907: Joomla! JCE extension 2.9.99.5 - unauthenticated Remote Code Execution Video Credit: @0xgh057r3c0n2026-06-28
DarkWebInformervulnerabilityUnknown
Dark web monitoring and threat intelligence feed on ransomware groups and data leak sites.
Dark Web Informer: Ugh, you may want to fix your auto posts mate.2026-06-28
DarkWebInformercampaignUnited States
Dark web monitoring and threat intelligence feed on ransomware groups and data leak sites.
Dark Web Informer: Amigo Tech patient dataset claim posted on a forum Amigo Tech is a Brazilian healthtech company connected to healthcare scheduling and patient management services. A forum user claims a partial breach tied to Amigo Tech, allegedly containing 121,678 patient records from March 2026.2026-06-28
DarkWebInformerbreachUnited States
Dark web monitoring and threat intelligence feed on ransomware groups and data leak sites.
Dark Web Informer: ‼ New Ransomware Group: SETTRA htttp://settra5ldqwgtw5q7z5awbsvlksakyfojuc5slgrz5lvapune4fantqd[.]onion2026-06-28
DarkWebInformerransomwareUnknown
Dark web monitoring and threat intelligence feed on ransomware groups and data leak sites.
Dark Web Informer: Why would a Ransomware affiliate to well known groups use the terminology "pro hacker?" Ransomware recruitment solicitation posted on a forum A Dread user is seeking a “pro hacker” for a project they claim could generate millions. The user claims affiliation with ransomware-related structures and appears to be looking for help compromising or gaining control of server/admin access for a small team.2026-06-28
DarkWebInformerransomwareFrance
Dark web monitoring and threat intelligence feed on ransomware groups and data leak sites.
Dark Web Informer: VRI Portal de Conteúdo dataset claim posted on a forum VRI Portal de Conteúdo is a Brazilian content portal focused on technical material in accounting, corporate, labor, and tax law areas. A forum user claims a dataset tied to VRI Portal de Conteúdo was exposed, allegedly containing 40K rows.2026-06-28
DarkWebInformerbreachBrazil
Dark web monitoring and threat intelligence feed on ransomware groups and data leak sites.
Daily Dark Web: Pinned: New Linux "pedit COW" Privilege Escalation Exploit Published Security researcher Massimiliano Oldani has released a public proof-of-concept (PoC) exploit, **packet_edit_meme**, for the Linux kernel vulnerability **CVE-2026-46331**, nicknamed **pedit COW**. * The flaw resides in Linux's **net/sched act_pedit** traffic control subsystem and allows an unprivileged local user to escalate privileges to **root** by corrupting shared page-cache memory.2026-06-28
DailyDarkWebvulnerabilityUnited States
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: Alleged Compromise of Colima State Government Electronic Signature System A threat actor claims to have compromised the Advanced Electronic Signature (Firma Electrónica Avanzada) platform used by the Government of the State of Colima, Mexico. * According to the forum post, the actor alleges they: * Gained administrative access to the portal. * Deleted all user accounts except a single administrator account. * Retained control of the remaining administrative account.2026-06-28
DailyDarkWebcampaignMexico
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: Call of Duty: Mobile Internal Offsets Allegedly Released A forum user has shared what they claim is an internal `offsets dump.cs` file for the global version of Call of Duty: Mobile (package: `com.activision.callofduty.shooter`). The post includes a public download link and states the file will be reposted if the original link becomes unavailable.2026-06-28
DailyDarkWebbreachUnited States
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: French Hospital Patient Database Allegedly Repackaged and Shared A threat actor has published what they claim is a reformatted dataset originating from the 2024 Blackout ransomware leak targeting Centre Hospitalier d'Armentières in France. According to the post, the dataset contains information on approximately 203,928 patients, covering records from 2004 through March 2018.2026-06-28
DailyDarkWebransomwareFranceT1566
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Ido Cohen: New Ransomware Group: Settra Settra has entered the ransomware landscape with 10+ published victims already listed on its leak site. Unlike groups that attempt to justify their actions, Settra openly states its motivation is simple: money. The group claims it does not target specific countries or industries—it targets organizations with exploitable security weaknesses.2026-06-27
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Two ransomware groups are showing a sharp increase in activity during 2026. SafePay Q1 2026: 22 victims Q2 2026: 59 victims (+168%) RALord (Nova) Q1 2026: 14 victims Q2 2026: 60 victims (+329%) Both groups have significantly accelerated their operations in recent months, making them two of the fastest-growing ransomware threats to watch. Track ransomware trends and emerging threat groups with DarkFeed.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.2026-06-26
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
MalwareHunterTeam: And @smica83 uploaded the sample to Bazaar:2026-06-26
malwrhunterteamcampaignUnknown
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
MalwareHunterTeam: List of names: "CamScanner 19-06-2026 16.49.accdr" "Adv Int Course (Rome).accdr" "Expression of Interest (EOI).accdr" "Security Orientation Course-41.accdr" "001210.accdr" "Proposal for Area Admin Meeting - SLNS Barana.accdr" "UN-System-wide-Strategy-on-SSC-2026-2029.accdr" ‍2026-06-26
malwrhunterteamcampaignUnknown
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
MalwareHunterTeam: 51.79.138[.]177 ‍2026-06-26
malwrhunterteamcampaignUnknown
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
MalwareHunterTeam: And @smica83 uploaded a realted sample to Bazaar:2026-06-26
malwrhunterteamcampaignUnknown
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
MalwareHunterTeam: Both domains are on 202.1.31[.]73... ‍2026-06-26
malwrhunterteamcampaignUnknown
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
MalwareHunterTeam: And the mentioned sample is now on Bazaar thanks to @smica83:2026-06-26
malwrhunterteamcampaignUnknown
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
MalwareHunterTeam: 67.43.50[.]11 ‍2026-06-26
malwrhunterteamcampaignUnknown
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.
Hackmanac: Cyber Alert ‼ USA - 𝗣𝗼𝗹𝘆𝗺𝗮𝗿𝗸𝗲𝘁 Polymarket confirmed a third-party compromise that enabled attackers to inject malicious code into its website, leading to the theft of user funds. The company contained the incident and will refund affected users. Around the same time, researchers reported a phishing campaign targeting Polymarket users that allegedly stole about US$3 million in cryptocurrency.2026-06-26
H4ckmanacphishingUnited StatesT1566
Threat intelligence and cyber alert feed covering data breaches, ransomware incidents and vulnerability disclosures.
GSP Crop Science Pvt2026-06-25
incransomransomwareIndia
La empresa GSP Crop Science Pvt ha sido objeto de un ataque cibernético relacionado con ransomware, atribuido al grupo malicioso "incransom". Este incidente afecta a una empresa líder en inn...