#ransomware

Ransomware infrastructure (URLs, domains, IPs, hashes) extracted from public security researchers

Subscribe (RSS)


#ransomware

Ransomware infrastructure (URLs, domains, IPs, hashes)

Subscribe (RSS)


IOCs by window

Today

0

IOCs tagged #ransomware

Week

15

IOCs tagged #ransomware

Month

53

IOCs tagged #ransomware

Year

620

IOCs tagged #ransomware

Counts as of 2026-08-09. Regenerated daily.

About #ransomware

  • Definition: malware that encrypts victim data and demands payment for decryption, typically combined with data-theft extortion ("double extortion"). Encryption itself maps to MITRE ATT&CK T1486 (Data Encrypted for Impact).
  • Common operators / families: LockBit, BlackCat (ALPHV), Akira, Play, Royal, Hive, Conti (legacy), Clop, BianLian. The #ransomware tag covers infrastructure linked to any of these (intrusion C2, data-leak sites, ESXi-targeting components).
  • Detection: EDR rules on file-encryption velocity, OS-vendor anti-tamper protections, immutable backups + air-gapped restore, and infrastructure blocklists for the C2/staging URLs and IPs that precede the encryption phase.
  • References: MITRE ATT&CK T1486 · CISA #StopRansomware · No More Ransom (decryptors).

Recent IOCs tagged #ransomware

Latest 10 IOCs from the past 30 days. Live JSON: api.tweetfeed.live/v1/month/ransomware.

Date Type Value Source
Aug 08, 10:02 sha256 8a05758bf149bc80368a74d9bff47bea03be779f1013816aafe6886dcdfa... @akudryk007
Aug 06, 16:40 domain yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd.oni... @fbgwls245
Aug 06, 16:40 url http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbh... @fbgwls245
Aug 05, 16:27 domain pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4nyd.oni... @DarkWebInformer
Aug 05, 16:27 url http://pnzruro7syvwvefx5mpo2fhzi4jftgquynsqf3vy5x3no57yp2iz4... @DarkWebInformer
Aug 05, 13:29 domain darkprn3d3udnhpuxknsrhft3376lrz5tenhgkrxge5hxqe46pkbrwid.oni... @fbgwls245
Aug 05, 13:29 url http://darkprn3d3udnhpuxknsrhft3376lrz5tenhgkrxge5hxqe46pkbr... @fbgwls245
Aug 04, 13:52 domain mll5ddmdzgiq2siv3qnocmmqyiigfpajtc663xtf32qtp6weycyx2hyd.oni... @fbgwls245
Aug 04, 13:52 url http://mll5ddmdzgiq2siv3qnocmmqyiigfpajtc663xtf32qtp6weycyx2... @fbgwls245
Aug 04, 13:52 domain ns7y6bxawualjj5rpo5num6syejd7hgaowrndk3r4duxu2iyinzv6hid.oni... @fbgwls245

Related tags

Tags that frequently co-occur with #ransomware.

See all tags on the Dashboard or browse the full IOC feed.

Frequently asked questions

What is ransomware?

Ransomware is malware that encrypts a victim's data and demands payment - usually in cryptocurrency - for the decryption key. Modern operators add data-theft and public leaks ("double extortion") even if the victim restores from backups. Initial access is typically via phishing, exposed RDP, vulnerable VPN appliances or compromised credentials.

Which ransomware operators produce the most IOCs in this feed?

Volume tracks active researcher coverage rather than pure operator output, so high-profile crews (LockBit while active, BlackCat/ALPHV, Akira, Play) tend to dominate. Affiliate-driven RaaS programmes generate more diverse infrastructure than single-team operations, which produces more URLs/IPs to tag.

How is this list updated?

Every 15 minutes. The TweetFeed pipeline scrapes RSS feeds from public Twitter/X security researcher accounts and lists, extracts IOCs, tags them with the relevant malware family or threat actor, and republishes the result in CSV, JSON and RSS. Ransomware-tagged IOCs are surfaced on this page within the next 15-minute tick. The page itself is regenerated daily by a GitHub Action.

What is the license? Can I use this commercially?

All TweetFeed IOC data, including this Ransomware subset, is released under CC0 1.0 Universal (Public Domain Dedication). No attribution required, no warranty. Commercial use is allowed. The TweetFeed website code and branding are not covered by CC0.

License

Ransomware IOC data: CC0 1.0 Public Domain. No attribution required, no warranty. Source code for the pipeline: github.com/0xDanielLopez/TweetFeed (MIT).