Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
critical threatRansomwareMalware Family
Historical
Play
Critical severity
10.1k
IOCs Tracked
—
First Seen
—
Last Seen
0
YARA Rules
Associated IOCs10,132 total · showing 50
IP49
91.202.233.2142026-10-09High
15.204.95.2282026-10-09High
221.207.101.1752026-10-09High
162.248.225.1652026-10-09High
67.219.102.2442026-10-09High
109.73.193.2422026-10-01High
46.151.182.2052026-10-09High
101.200.193.2112026-10-09High
5.101.86.982026-07-04High
5.101.86.1052026-07-06High
178.16.54.2482026-06-23High
88.119.167.1432026-08-17High
84.21.189.2252026-06-20High
107.175.148.682026-07-09High
163.181.208.792026-10-09High
137.184.163.272026-10-09High
139.159.203.442026-10-09High
195.123.240.2362026-09-15High
8.152.2.862026-09-13High
158.247.194.1442026-08-19High
SHA2561
1b39f9b2b96a6586c4a11ab2fdbff8fdf16ba5a0ac7603149023d73f33b844982026-10-09High
Related Reports30 shown
PhishTank (500 entries)
PhishTank
The GlorySprout or a Failed Clone of Taurus Stealer
RussianPandaMar 16, 2024
Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
Rapid7Sep 25, 2026
Metasploit Wrap Up: A Collection of What Can Only Be Called Eclectic Modules
Rapid7Oct 9, 2026
SubQuery Ecosystem Compromise: Hidden Credential Theft and Backdoors
Step SecurityOct 5, 2026
Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes
Step SecuritySep 30, 2026
Runtime Security for AWS CodeBuild-Hosted GitHub Actions Runners
Step SecuritySep 2, 2026
@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow
Step SecurityAug 28, 2026
Tensorlake npm Package Compromised: A Worm With a Hostage Token That Wipes Your Machine If You Revoke It
Step SecurityOct 8, 2026
Return of Shai-Hulud: The “Second Coming” of the NPM Supply Chain Compromise
PulsediveNov 26, 2025
2025 In Review
PulsediveDec 18, 2025
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket SecurityOct 7, 2026
Malicious npm campaign targets developers integrating Twilio
ReversingLabsSep 22, 2026
SpectrePaste
Walmart Global TechJul 6, 2026
Botnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoria
XLabJul 29, 2026
Scattered Spider: Social Engineering Meets Cloud Ransomware Tactics
Secure BlinkMay 20, 2025
Necro Trojan’s Return: Infiltrating Google Play to Target Android Users
Secure BlinkSep 25, 2024
Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
The DFIR ReportSep 8, 2025
PhishTank (500 entries)
PhishTank
Qbot: A Deep Dive into the Banking Trojan
Aziz FarghlyJun 26, 2023
PhishTank (500 entries)
PhishTank
China and the Cyber Arms Race for AI Supremacy
PolySwarmSep 21, 2026
FamousSparrow Takes Flight with New SparroWocky Backdoor
PolySwarmSep 25, 2026
Gamers Get Played: Fake GTA6 Leaks Deliver a Grab Bag of Malware
PolySwarmSep 14, 2026
BlueMoon Exploit Kit Rapidly Targets Key Verticals Across Multiple Espionage Campaigns
PolySwarmSep 21, 2026
BraZetsu: AI-Enhanced Reconnaissance Fuels Exilware’s Access Marketplace
PolySwarmSep 11, 2026
Lunex Uses BYOVD to Disable Security Monitoring and Deploy Persistent Stealer
PolySwarmOct 2, 2026
Targeting the Systems Behind the Mission: OT Threats to US Critical Infrastructure and Military Operations
PolySwarmOct 5, 2026
CLOSEDQUORUM: Malware Puts AI in the C2 Loop
PolySwarmSep 28, 2026
The Job Offer Has Claws: Mirage Kitten Deploys NodeRabbit and PollCat
PolySwarmSep 8, 2026
Threat Profile
TypeRansomware
StatusHistorical
IOCs tracked10,132