Ransomware-group threat brief and tracking — victim patterns, TTPs, ransom economics, and
Ransomware-group threat brief and tracking — victim patterns, TTPs, ransom economics, and defensive playbooks across LockBit, ALPHV, Cl0p, RansomHub, BlackBasta, Akira, and 50+ active groups, plus CISA KEV ransomware-linked CVEs. Global, for threat-intel and incident-response agents.
200000 (raw units)
price
1
calls / 30d
1
unique payers
2026-08-20
updated
Provider
cyberpulse.theaslangroupllc.com · discovered, not yet claimed by its owner
Payment (x402 accepts[])
[
{
"scheme": "exact",
"network": "eip155:8453",
"payTo": "0x50ab2018c06c6E4eAA9BA52057Eb55eD284912fc",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"amount": "200000",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "eip155:8453",
"payTo": "0x50ab2018c06c6E4eAA9BA52057Eb55eD284912fc",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"amount": "200000",
"maxTimeoutSeconds": 604900
},
{
"scheme": "exact",
"network": "solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp",
"payTo": "985iFjbnGQ3dJcwXnfRCMSrH4Jnc3kW1N6msR64B5KX1",
"asset": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
"amount": "200000",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "eip155:137",
"payTo": "0x50ab2018c06c6E4eAA9BA52057Eb55eD284912fc",
"asset": "0x3c499c542cEF5E3811e1192ce70d8cC03d5c3359",
"amount": "200000",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "eip155:42161",
"payTo": "0x50ab2018c06c6E4eAA9BA52057Eb55eD284912fc",
"asset": "0xaf88d065e77c8cC2239327C5EDb3A432268e5831",
"amount": "200000",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "eip155:480",
"payTo": "0x50ab2018c06c6E4eAA9BA52057Eb55eD284912fc",
"asset": "0x79A02482A880bCe3F13E09da970dC34dB4cD24D1",
"amount": "200000",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "eip155:143",
"payTo": "0x50ab2018c06c6E4eAA9BA52057Eb55eD284912fc",
"asset": "0x754704Bc059F8C67012fEd69BC8A327a5aafb603",
"amount": "200000",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "eip155:196",
"payTo": "0x50ab2018c06c6E4eAA9BA52057Eb55eD284912fc",
"asset": "0x779ded0c9e1022225f8e0630b35a9b54be713736",
"amount": "200000",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "eip155:999",
"payTo": "0x50ab2018c06c6E4eAA9BA52057Eb55eD284912fc",
"asset": "0xb88339CB7199b77E23DB6E890353E22632Ba630f",
"amount": "200000",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "algorand:wGHE2Pwdvd7S12BL5FaOP20EGYesN73k",
"payTo": "62A253YPATFNJCPRKID3FKD77MYJFNTVRYRP4B4JWG36EGLPY7UXFWGI7I",
"asset": "31566704",
"amount": "200000",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "xrpl:0",
"payTo": "rMnHeutYALco8RYFVcmuU4BCgSzBpPEh32",
"asset": "XRP",
"amount": "200000",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "xrpl:0",
"payTo": "rMnHeutYALco8RYFVcmuU4BCgSzBpPEh32",
"asset": "524C555344000000000000000000000000000000",
"amount": "0.2",
"maxTimeoutSeconds": 300
},
{
"scheme": "exact",
"network": "eip155:56",
"payTo": "0x50ab2018c06c6E4eAA9BA52057Eb55eD284912fc",
"asset": "0x8d0D000Ee44948FC98c9B98A4FA4921476f08B0d",
"amount": "200000000000000000",
"maxTimeoutSeconds": 300
}
]Output schema
{
"bazaar": {
"info": {
"input": {
"method": "GET",
"queryParams": {
"group": "LockBit",
"lang": "en"
},
"type": "http"
},
"output": {
"example": {
"executive_summary": "LockBit remains one of the most prolific ransomware operations despite law enforcement disruption in Feb 2024. Healthcare and finance are primary targets. Immutable backups and MFA on all remote access are the most effective countermeasures.",
"global_ransomware_statistics": {
"average_downtime_days": 21,
"average_ransom_demand_usd": 1500000,
"percentage_paying_ransom": "34%"
},
"groups_analyzed": [
{
"activity_level": "moderate",
"name": "LockBit",
"primary_targets": {
"countries": [
"USA",
"UK",
"Germany",
"Australia"
],
"sectors": [
"Finance",
"Healthcare",
"Government"
]
},
"ransomware_as_a_service": true,
"status": "disrupted (Operation Cronos Feb 2024) — partially active under LockBit 3.0",
"typical_ransom_range_usd": "$1,000,000 - $50,000,000"
}
],
"query": "LockBit"
},
"type": "json"
}
},
"schema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"method": {
"enum": [
"GET",
"HEAD",
"DELETE"
],
"type": "string"
},
"queryParams": {
"properties": {
"group": {
"description": "Ransomware group name — e.g. \"LockBit\" | \"ALPHV\" | \"Cl0p\" | \"RansomHub\" | \"BlackBasta\" | \"Akira\" | \"Play\" | omit for landscape overview",
"type": "string"
},
"lang": {
"description": "en | es | fr | de | ja | zh | ko | pt | ar | hi (default: en)",
"type": "string"
}
},
"type": "object"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}
},
"builder-code": {
"info": {
"a": "bc_gxy6qn5p"
},
"schema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"additionalProperties": false,
"properties": {
"a": {
"description": "App builder code",
"pattern": "^[a-z0-9_]{1,32}$",
"type": "string"
},
"s": {
"description": "Service builder codes",
"items": {
"pattern": "^[a-z0-9_]{1,32}$",
"type": "string"
},
"type": "array"
},
"w": {
"description": "Wallet builder code",
"pattern": "^[a-z0-9_]{1,32}$",
"type": "string"
}
},
"type": "object"
}
}
}Use it
curl
curl "https://cyberpulse.theaslangroupllc.com/api/cyber/ransomware-intel" # -> 402 Payment Required, accepts[] lists how to pay # retry with a PAYMENT-SIGNATURE (or PAYMENT header) once paid
JavaScript
const res = await fetch("https://cyberpulse.theaslangroupllc.com/api/cyber/ransomware-intel");
if (res.status === 402) {
const { accepts } = await res.json();
// pay one of accepts[] via an x402 client, then retry with the payment header
}Python
import httpx
res = httpx.get("https://cyberpulse.theaslangroupllc.com/api/cyber/ransomware-intel")
if res.status_code == 402:
accepts = res.json()["accepts"]
# pay one of accepts[] via an x402 client, then retry with the payment headerMachine-readable
Everything on this page is also available as clean JSON at /resources/4781.json, and this resource appears in /discovery/resources and /discovery/search.