THREAT INTELLIGENCE

Know the adversary
before they reach you.

Curated, machine-readable intelligence on the actors targeting your sector — fused into detections so you're defended against tomorrow's campaign, not last year's.

ADVERSARY TRACKING240 ACTORS
Specter Wolf
ransomware · finance
ACTIVE
Cobalt Heron
espionage · public sector
TRACKING
Iron Tide
supply chain · tech
TRACKING
Pale Lantern
hacktivist · energy
DORMANT
FUSED INTO LIVE DETECTIONS
SOURCES & OUTPUTS

Intelligence that does something.

Curated by humans

A dedicated research team, not a scraped feed.

STIX / TAXII

Machine-readable, standards-based delivery.

Sector-specific

Only the actors that actually target you.

Auto-fused

Becomes detection logic without a ticket.

ACTOR PROFILE

A dossier on everyone hunting you.

Aliases, tradecraft, infrastructure, and live campaign activity — mapped to ATT&CK and tied to your own exposure.

Specter WolfACTIVE
APT-SW · TD-INTEL
ALIASES
Grey Syndicate, TA-559
MOTIVATION
Financial · extortion
FIRST SEEN
2021 · ransomware-as-a-service
ORIGIN
Suspected E. Europe
TARGETED SECTORS
FinanceInsuranceLegalHealthcare
Your exposure: elevated
3 TTPs match your environment
TRADECRAFT · MITRE ATT&CK
T1566 PhishingT1078 Valid AccountsT1486 EncryptT1567 Exfil
RECENT CAMPAIGNS
MAY '26
"Ledger Frost" — invoice-fraud wave
42 victims · financial sector
FEB '26
VPN-appliance exploitation
CVE-2026-2148 · 0-day
NOV '25
Double-extortion leak site relaunch
new infrastructure cluster
INDICATOR FEED · LIVE

Fresh indicators, already blocking.

INDICATORTYPEACTORCONFSTATE
185.220.101.42IPV4 · C2Specter Wolf0.96BLOCKING
ledger-frost-secure.comDOMAINSpecter Wolf0.88BLOCKING
a3f9c1··· (ransomware.dll)SHA-256Specter Wolf0.99BLOCKING
cobalt-heron-relay[.]netDOMAINCobalt Heron0.79WATCH
// THREAT INTELLIGENCE

Know the adversary
before they reach you.

Curated, machine-readable intelligence on the actors targeting your sector — fused into detections so you're defended against tomorrow's campaign, not last year's.

ADVERSARY TRACKING240 ACTORS
Specter Wolf
ransomware · finance
ACTIVE
Cobalt Heron
espionage · public sector
TRACKING
Iron Tide
supply chain · tech
TRACKING
Pale Lantern
hacktivist · energy
DORMANT
FUSED INTO LIVE DETECTIONS
// SOURCES & OUTPUTS

Intelligence that does something.

Curated by humans

A dedicated research team, not a scraped feed.

STIX / TAXII

Machine-readable, standards-based delivery.

Sector-specific

Only the actors that actually target you.

Auto-fused

Becomes detection logic without a ticket.

// ACTOR PROFILE

A dossier on everyone hunting you.

Specter WolfACTIVE
APT-SW · TD-INTEL
ALIASES
Grey Syndicate, TA-559
MOTIVATION
Financial · extortion
FIRST SEEN
2021 · RaaS
ORIGIN
Suspected E. Europe
TARGETED SECTORS
FinanceInsuranceLegalHealthcare
Your exposure: elevated
3 TTPs match your environment
TRADECRAFT · MITRE ATT&CK
T1566 PhishingT1078 Valid AccountsT1486 EncryptT1567 Exfil
RECENT CAMPAIGNS
MAY '26
"Ledger Frost" — invoice-fraud wave
42 victims · financial sector
FEB '26
VPN-appliance exploitation
CVE-2026-2148 · 0-day
NOV '25
Double-extortion leak site relaunch
new infrastructure cluster
// INDICATOR FEED · LIVE

Fresh indicators, already blocking.

INDICATORTYPEACTORCONFSTATE
185.220.101.42IPV4 · C2Specter Wolf0.96BLOCKING
ledger-frost-secure.comDOMAINSpecter Wolf0.88BLOCKING
a3f9c1··· (ransomware.dll)SHA-256Specter Wolf0.99BLOCKING
cobalt-heron-relay[.]netDOMAINCobalt Heron0.79WATCH