33,702 ransomware posts.
Tracked in the open.

Open-source intelligence on 613 ransomware groups, markets and threat actors. Updated live since 2022.

Activity · last 30 days vs prev 7d ▼ -11.9%
2026-07-18 — 21 posts 2026-07-19 — 8 posts 2026-07-20 — 21 posts 2026-07-21 — 11 posts 2026-07-22 — 40 posts 2026-07-23 — 53 posts 2026-07-24 — 18 posts 2026-07-25 — 19 posts 2026-07-26 — 42 posts 2026-07-27 — 39 posts 2026-07-28 — 26 posts 2026-07-29 — 16 posts 2026-07-30 — 54 posts 2026-07-31 — 63 posts 2026-08-01 — 3 posts 2026-08-02 — 24 posts 2026-08-03 — 26 posts 2026-08-04 — 34 posts 2026-08-05 — 96 posts 2026-08-06 — 43 posts 2026-08-07 — 76 posts 2026-08-08 — 23 posts 2026-08-09 — 20 posts 2026-08-10 — 49 posts 2026-08-11 — 31 posts 2026-08-12 — 99 posts 2026-08-13 — 16 posts 2026-08-14 — 41 posts 2026-08-15 — 9 posts 2026-08-16 — 35 posts

This week

280
posts · last 7 days
▼ -11.9%
45
active groups
▲ +7.1%
5
new groups this week
NEW
Clop
top group
43 posts · 15.4%

Top movers

7d vs prev 7d

Latest posts

see more →
  • Coface Qilin
  • Spoonful of Comfort Qilin
  • Teikoku USA Qilin
  • AGUNSA Qilin
  • Moscord Eclipse

Torrent intelligence

passive swarm scan · IP/ASN pivot · BEP-48 tracker scrape · webseed mirrors
1341
swarms tracked
286
alive
59
seeders total
1043
cross-group IPs
pivot signal
613 groups · 145 markets · 31 actors · 4769 leaks · 934 ransom notes · 11192 crypto addrs · 18 in-house analyses