What a July for ransomware.live 🔥 Quick recap: first the new search engine with its "Splunk-style" query language. Then the real-time map, the famous "pew pew map" 😄. And now, third gift of the month: ransomware.live now includes KQL Hunting Queries. 👉 https://lnkd.in/eSRJ-_bh This one wasn't my idea. It came from a long-time user of the platform, someone who's been using ransomware.live for a while and reached out with something like: 💬 "Hey Julien, One more request if possible for ransomware.live - there is a Yara section but are we able to add a KQL section? ". Fair point. Here's the answer. Threat hunting queries for Microsoft Sentinel / Defender based on each ransomware operation's known tooling and associated MITRE ATT&CK techniques. Each query is tagged by tactic and by ATT&CK technique, with a direct link from the corresponding group's page. ⚠️ One important point: these are starting points for hunting, not ready-made alert rules. Validate table and column names against your own workspace schema before turning any of them into a production alert. The goal is to save you research time, not to replace your own judgment. This project remains what it's always been: free. If a request makes sense for the community, it eventually lands on the platform. This is proof of that. 🙏🏻 Thanks to the person who suggested this one, you'll recognize yourself. And as always: if you've got a need, a gap, or an idea for a query on a group that isn't covered yet, contact us... #RansomwareLive #ThreatHunting #KQL #MicrosoftSentinel #CyberThreatIntelligence #MITREATTACK #CyberResilience
ransomware.live
Information Services
Ransomware.live tracks and monitors the victims of ransomware groups and their activity. Contact : Julien Mousqueton
About us
Ransomware.live is a leading platform dedicated to the monitoring, analysis, and prevention of ransomware attacks on a global scale. Our mission is to provide real-time information on emerging threats, helping businesses and individuals understand the risks associated with ransomware and equipping them with the tools needed to protect themselves effectively. With our expertise and cutting-edge technology, we continuously monitor malicious activities across the web, offering detailed analyses and up-to-date reports on trends and new ransomware variants. Ransomware.live is committed to raising public awareness and supporting cybersecurity efforts by providing educational resources, early alerts, and practical advice to minimize the potential impact of these attacks.
- Website
-
https://www.Ransomware.live
External link for ransomware.live
- Industry
- Information Services
- Company size
- 1 employee
- Type
- Nonprofit
- Founded
- 2022
- Specialties
- Cybersecurity, ThreatIntel, ThreatHunting, and CTI
Employees at ransomware.live
Updates
-
Watch ransomware happen, live We just wanted to share something we've been building on ransomware.live: a real-time attack map at map.ransomware.live 🗺️ It plots ransomware victim claims as they get published on leak sites. Every dot on the map is a real claim. A few things we designed it to do: 🎬 Live feed: group, victim, sector, country, timestamp, as they land 🏆 Top groups & top countries — who's most active right now, not last quarter ⏪ Replay mode — rewind 24h / 7d / 30d to see how an attack wave built up It's free and powered by the same data pipeline behind https://ransomware.live built and maintained to support defenders, journalists, and researchers. 👉 https://lnkd.in/ej5erz4w Great for SOC dashboards, conference/booth displays, or just keeping an eye on activity trends during customer conversations. Same data pipeline as ransomware.live, just visualized differently. #Ransomware #ThreatIntelligence #CyberSecurity #CTI #InfoSec
-
-
ransomware.live reposted this
🔍 Shipped: a new search engine on https://ransomware.live: a real query language for the database. Instead of basic keyword matching, you now get a command-bar search with operators: +country:us → only US victims -group:lockbit3 → exclude a group +sector:healthcare → filter by sector +infostealer / -infostealer → has/doesn't have infostealer data before:2026-01-01 / after:2025-01-01 → date range Mix free text with operators and they all combine with AND. Repeat a `+` on the same field and it's OR'd (+country:us +country:ca = US or Canada). Example: hospital +country:us -group:lockbit3 +sector:healthcare before:2026-01-01 Built for the researchers, journalists, and law enforcement who use ransomware.live daily. Try it: https://lnkd.in/e9ht4Xdz #threatintelligence #ransomware #cybersecurity #opensource
-
-
🔍 Shipped: a new search engine on https://ransomware.live: a real query language for the database. Instead of basic keyword matching, you now get a command-bar search with operators: +country:us → only US victims -group:lockbit3 → exclude a group +sector:healthcare → filter by sector +infostealer / -infostealer → has/doesn't have infostealer data before:2026-01-01 / after:2025-01-01 → date range Mix free text with operators and they all combine with AND. Repeat a `+` on the same field and it's OR'd (+country:us +country:ca = US or Canada). Example: hospital +country:us -group:lockbit3 +sector:healthcare before:2026-01-01 Built for the researchers, journalists, and law enforcement who use ransomware.live daily. Try it: https://lnkd.in/e9ht4Xdz #threatintelligence #ransomware #cybersecurity #opensource
-
-
More and more “cyber news” sites and aggregators are publishing our ransomware victim data with no credit, no mention, no link. Just our work, repackaged as their content. How do we know? Two things don’t lie. First, the presumed attack dates we publish are exclusive to ransomware.live, or sourced directly from Valery Rieß-Marchive’s research. When those exact dates appear elsewhere with zero attribution, the conclusion writes itself. Second, the discovery timestamps. Identical. Down to the millisecond. You can’t independently discover the same victim at the exact same time. That’s not a coincidence. That’s a copy. This isn’t just about us. It’s a pattern we see across the cybersecurity community. Researchers, analysts, and open-source contributors doing the hard work, while others monetize the traffic. Running ransomware.live is not free. It costs us time, infrastructure, and legal headaches. We don’t ask for much, but attribution is the bare minimum. If you’re building a product, a newsletter, or a news site on top of open-source threat intelligence, cite your sources. It’s not optional. It’s integrity. To the community that does credit us, thank you. You know who you are.
-
🎙️ http://ransomware.live now includes exclusive interviews with ransomware group operators, directly on each group's profile page. Understanding how ransomware groups think, communicate, and justify their actions has always been one of the hardest parts of threat intelligence. Ransom notes, negotiation chats and leak site posts tell part of the story, direct interviews tell a different one. Thanks to the work of CyberSecurityIL, a collection of exclusive interviews with ransomware gang operators is now integrated into ransomware.live. When an interview exists for a group, a banner appears directly on their profile page, linking straight to the interview on https://lnkd.in/ewfn24vw. No searching, no context-switching. Everything in one place. For threat intel analysts, incident responders, and researchers: this is rare primary source material on how these groups position themselves, what they claim, and how they respond under questioning. #ThreatIntelligence #Ransomware #RansomwareLive #CyberSecurity #OSINT
-
-
ransomware.live reposted this
My Stickers have arrived from one of my favorites Threat-intelligence platforms, ransomware.live 😍 Im Immediately slapping it on my laptop 😁
-
-
🚨 Before ransomware hits, infostealers knock on the door. 🚪 Today Ransomware.live is launching a new page: Infostealer Intelligence. The idea is simple but powerful: cross-reference the credential leaks from infostealer malware with the ransomware victims already tracked on the platform. The result? A clear picture of how stolen credentials, harvested silently from infected machines and sold on underground markets, pave the way for ransomware intrusions. In numbers: 📊 16,095 domains tracked 👤 218,649 employees exposed 🌍 18,585,019 users exposed 🦠 19 stealer families identified Data is sourced from Hudson Rock's Cavalier threat intelligence platform. This is free and available now: 🔗 https://lnkd.in/eWcU9wNf If you work in threat intel, incident response, or just want to understand the ransomware kill chain better: this one's for you.
-
-
🔧 Big updates on Ransomware.live: here's what's been happening behind the scenes. 📦 JSON → PostgreSQL We've migrated the entire backend from flat JSON files to a proper PostgreSQL database. Faster queries, better structure, and a solid foundation for everything coming next. 🔍 Victim enrichment in progress We're updating most victim records with their associated domains, and cross-referencing with the Hudson Rock database to surface infostealer intelligence directly linked to ransomware victims. This is ongoing, but coverage is growing every day. 🌍 Geolocation, announced at RISE Dublin organized by Team Cymru We have finalized the dataset of geolocation of ransomware victims. Thanks to Commandement du ministère de l’Intérieur dans le cyberespace (COMCYBER-MI) to "push" me to develop it :) And more to come... 💡 Originally, https://ransomware.live was developed for the needs of its creator Julien Mousqueton but since it's been shared with the community, don't hesitate to request features! Ransomware.live keeps evolving. Stay tuned. 👀
-
-
ransomware.live reposted this
🚨 100+ companies hacked - we just found how one of the most active ransomware groups hacked 100+ companies using the same easily avoidable technique (tl;dr + blog below) ⬇️ Short blog that goes over everything we found - https://lnkd.in/gvcYm6zG tl;dr - Coinbase Cartel became a top 10 ransomware group by relying on data theft + extortion tactics to blackmail global brands. Turns out their breaches rely on years old credentials from Infostealer infections that if were monitored would destroy this group's entire business model. In the blog we go over specific victim examples and how breaches were performed, and we show how ransomware.live's partnership with Hudson Rock allowed us to see the high percentage of Coinbase Cartel victims with Infostealer infections to begin this investigation. This is one of the highest victim counts attributed to a single actor utilizing infostealers data we were able to find (100+), we also recently discovered a 50+ one, and Snowflake was like 150+. In any case it's evident Infostealers are the lowest hanging fruits for cybercriminals trying to make a name for themselves or make some $$.