Black Basta
A ransomware-as-a-service operation active since 2022 that affected more than 500 organisations across North America, Europe and Australia by May 2024.
Structured threat intelligence
A curated collection of deeply sourced threat-actor dossiers and their related campaigns, malware, targeting and attribution.
Coverage: selected deep profiles, not an exhaustive actor directory. Actor dossiers are the editorial product; Knowledge records support them, and only procedure-backed links enter Relationships. Review the methodology and publication boundaries.
A ransomware-as-a-service operation active since 2022 that affected more than 500 organisations across North America, Europe and Australia by May 2024.
A financially motivated extortion and ransomware brand associated with repeated mass exploitation of managed file-transfer and enterprise applications affecting organisations across Europe and beyond.
A Russian financially motivated cybercriminal organisation linked by UK and US authorities to Dridex-enabled theft, ransomware operations and extensive harm in the United Kingdom and Europe.
A Russian state-sponsored espionage actor associated with FSB Centre 18 and sustained, high-volume targeting of Ukrainian government and defence organisations.
A ransomware-as-a-service ecosystem whose administrators supplied malware and infrastructure to affiliates responsible for thousands of intrusions, including extensive European targeting.
Read source-specific identity, attribution, chronology, targeting, capabilities and procedure evidence.
Browse 20 dossiers →Supporting intelligenceKnowledge explorerInspect campaigns, software, techniques and references in context without losing your place.
Search 166 records →Evidence layerSourced relationshipsReview the bounded actor-to-technique links that carry an explicit procedure statement and reference.
Inspect 59 relationships →Published the initial dossier, service campaign and remote-access relationship.
Published the initial dossier, campaign, vulnerability record and exploitation relationship.
Published the initial dossier, Dridex campaign and spearphishing relationship.
Published the initial actor dossier, campaign record and one campaign-scoped procedure relationship.
Published the initial service dossier, mass-operation campaign and exploitation relationship.