HackerFeeds
Back to ransomware overview

Ransomware IOCs

79 groups with public IOCs · 1,601 total indicators. Click a group to see its hashes, IPs, wallets, and more. Source: ransomware.live.

Groups with published IOCs

#GroupIOC types · countsTotal
1akira
btc 7
md5 320
sha256 37
364
2raworld
ip 1
md5 209
tox 1
211
3bianlian
ip 191
md5 8
199
4trigona
md5 114
114
5qilin
ftp 2
ip 5
md5 54
61
6fog
md5 53
53
7hellokitty
md5 52
52
8cactus
md5 50
50
9anubis
ip 4
md5 25
twitter 1
30
10rhysida
md5 28
28
11blacknevas
sha256 27
27
12lockbit3
ip 10
md5 16
26
13dragonforce
ip 1
md5 22
tox 1
24
14medusa
email 2
md5 18
telegram 1
tox 3
24
15medusalocker
sha256 19
tox 1
20
16interlock
ip 3
md5 9
sha256 3
url 4
19
17lynx
md5 19
19
18sicarii
pgp 18
tox 1
19
19Sorry
ip 15
sha256 2
17
20braincipher
email 3
md5 12
15
21benzona
ip 1
md5 1
pgp 9
sha256 1
tox 1
13
22lockbit5
md5 13
13
23beast
ip 1
mail 8
session 1
sha256 1
tox 1
12
24vanhelsing
btc 2
ip 2
md5 7
tox 1
12
25bert
ip 2
md5 9
11
26Ghostsec
ip 1
sha256 4
url 5
10
27nitrogen
md5 6
tox 4
10
28chaos
ip 3
md5 3
sha256 3
9
29nightspire
email 4
sha256 2
telegram 2
tox 1
9
30termite
ip 2
md5 2
sha-1 2
sha-256 2
8
31bqtlock
telegram 5
twitter 1
xmr 1
7
32datacarry
email 1
ip 2
md5 1
session 1
sha256 2
7
33j
md5 6
6
34promptlock
sha1 6
6
35ralord
ip 1
md5 2
session 1
tox 2
6
36bluelocker
sha256 4
tox 1
5
37devman
ip 3
tox 1
twitter 1
5
38gunra
ip 1
md5 4
5
39shinyhunters
email 1
telegram 4
5
40thegentlemen
sha1 4
tox 1
5
410apt
md5 4
4
42warlock
sha256 1
tox 3
4
43crazyhunter
telegram 2
tox 1
3
44kawa4096
email 1
sha256 1
tox 1
3
45shinysp1d3r
sha256 3
3
46weyhro
ip 2
tox 1
3
47GDLockrSec
tox 1
twitter 1
2
48ailock
md5 1
sha256 1
2
49bluebox
email 1
tox 1
2
50cry0
ip 1
tox 1
2
51crypto24
email 1
ip 1
2
52d4rk4rmy
tox 2
2
53frag
email 2
2
54nova
session 1
tox 1
2
55obscura
sha256 1
tox 1
2
56pear
email 1
tox 1
2
57radar
session 1
tox 1
2
58thegreenbloodgroup
email 1
tox 1
2
59Bashe
ip 1
1
60arkana
session 1
1
61blacklock
md5 1
1
62blackshrantac
tox 1
1
63blacksuit
ip 1
1
64cephalus
ip 1
1
65cloak
md5 1
1
66exitium
tox 1
1
67global
session 1
1
68insomnia
tox 1
1
69lapsus$
sha256 1
1
70lunalock
email 1
1
71minteye
tox 1
1
72ms13089
email 1
1
73payload
sha256 1
1
74payoutsking
tox 1
1
75satanlockv2
tox 1
1
76securotrop
tox 1
1
77skira
session 1
1
78teamxxx
ip 1
1
79toufan
tox 1
1