Last updated: August 26, 2026
MalwareIntel is a cyber threat intelligence (CTI) aggregation platform. It collects, normalizes, correlates, and presents publicly available threat data from open-source feeds, public APIs, and community-contributed intelligence.
MalwareIntel does not:
Victim names, sectors, and countries displayed on MalwareIntel are derived exclusively from public disclosures already aggregated by third-party platforms such as ransomware.live, ransomlook.io, and ransomwatch.
MalwareIntel does not verify, confirm, or endorse claims made by threat actors. The listing of an organization does not imply that a breach has been confirmed independently.
If you represent an organization listed on MalwareIntel and wish to request removal or correction, contact [email protected]. Requests are evaluated promptly in accordance with our ethical guidelines and applicable data protection regulations (GDPR).
Ransom note artifacts displayed on MalwareIntel are sourced from ransomware.live (Zscaler ThreatLabz and Julien Mousqueton). These are file artifacts (typically .txt, .html, or .hta files) dropped by ransomware on victim systems and published by security researchers for defensive purposes.
Negotiation metadata (demands, outcomes, timelines) is derived from publicly available aggregations. MalwareIntel does not participate in, facilitate, or intercept negotiations between victims and threat actors.
KQL hunting queries, YARA rules, and Sigma detection rules presented on MalwareIntel are sourced from public repositories and community contributions. They are provided as starting points for threat hunting and must be validated against the user's own environment before deployment in production.
MalwareIntel does not guarantee the accuracy, completeness, or fitness for purpose of any detection rule. Use at your own risk.
IOCs published on MalwareIntel (hashes, IPs, domains, URLs, email addresses, cryptocurrency wallets, Tox/Telegram identifiers) are factual data points published by threat intelligence sources for defensive purposes.
IOCs have a limited shelf life. Confidence scores, decay timers, and last-seen dates are provided to help analysts assess timeliness. Blocking decisions based solely on MalwareIntel IOCs without additional validation are not recommended.
All data sources, their respective licenses, and attribution requirements are documented on our Data Sources & Attributions page.
MalwareIntel does not claim ownership of threat intelligence data sourced from third parties. The value provided lies in aggregation, normalization, correlation, and contextual enrichment of publicly available data.
MalwareIntel exists solely for defensive, educational, and research purposes. The platform does not encourage, facilitate, glorify, or provide material support for any form of cybercrime.
Information about threat actors, their tools, and their techniques is presented to help defenders understand and mitigate threats.
Threat intelligence is inherently uncertain. MalwareIntel provides data on a best-effort basis and makes no warranties regarding accuracy, completeness, or timeliness.
Security decisions made using MalwareIntel data are the sole responsibility of the user. MalwareIntel shall not be held liable for any damages arising from the use or inability to use the information provided.
For privacy concerns, removal requests, data corrections, or legal inquiries: