Global Threat Board
Live ransomware activity around the world, and the software flaws attackers are exploiting right now. Then the tools to clean an infected machine — all checked, all from the vendor direct.
Where it is happening
Attack claims by country
Equirectangular · marker area ∝ claim count
Statistics
Derived from the same claims as everything above — moves with the range tabs
Sectors targeted
Victim sector, where disclosed
Claims per hour
Rolling window, UTC
Who these groups are
Profiles for the groups currently claiming victims
Aliases, first seen, tooling and MITRE ATT&CK tactics — for the groups on the board above
Exploited in the wild right now
Latest additions to the CISA Known Exploited Vulnerabilities catalogue
If you run any of this software, patching it is urgent — these are confirmed under active attack
Malware removal tools
Every link checked · vendor pages only, never a direct downloadRead this first
- Only ever download from the vendor's own site. Search results for "free virus removal" are a well-known malware delivery route. Every link below goes to the official page — not to a direct installer, because those move and get mirrored by others.
- On-demand scanners are safe to stack; real-time antivirus is not. The scanners in the first group run once and exit, so you can use several for a second opinion. Never install two always-on antivirus products together.
- If the machine is badly infected, scan it from outside. Malware with kernel access can hide from any tool running inside the infected Windows. That is what the rescue media group is for.
- Back up your files before running an aggressive remover — on a drive you then unplug. Removal can break a system that was limping along, and ransomware can encrypt an attached backup.
- Never pay a ransom before checking No More Ransom. A free decryptor already exists for many strains. Paying funds the next attack and often gets you nothing.
- Tools deliberately not listed here: ComboFix (long obsolete and can break modern Windows), anything marketed as a "registry cleaner" (does not remove malware), and Kaspersky's TDSSKiller — discontinued, and its signed driver has been abused by ransomware crews to switch off security software.
1 · Free on-demand scanners
Start here. Each runs once, checks the machine and exits, so several can be used together for a second opinion without conflicting with the antivirus you already have.
2 · Bootable rescue media
For when Windows will not start, a scanner is being killed as it launches, or a rootkit is suspected. These boot the machine from a USB stick and scan the drive while the infection is not running — the only reliable way to deal with malware that has kernel access. Prepare them on a clean computer.
3 · Hit by ransomware
Identify the strain before doing anything else — free decryptors exist for a great many of them, and law enforcement releases new keys regularly. Keep the encrypted files even if no decryptor exists today; one may appear later. Do not reformat in a hurry.
4 · Technician tools
These diagnose and expose; they do not clean up after themselves, and a wrong move can leave a machine unbootable. Included for completeness — if you are not confident reading their output, stop here and get help rather than guessing.
5 · Leave one of these running
Once the machine is clean, one always-on product — and only one. Windows' own is genuinely competent now and needs no licence, no renewal and no upselling.
Think you have picked something up?
If a machine is behaving oddly, showing pop-ups, running hot, or you have opened something you wish you hadn't — I clean infections properly and recover data where it is recoverable. Based in Taunton, Somerset, remote or in person.
Get it looked at
Attack data from ransomware.live, which aggregates public ransomware leak-site postings. Vulnerability data from the CISA Known Exploited Vulnerabilities catalogue (public domain).
Counts only. Attack claims are made by the attackers themselves on their own leak sites and are not independently verified, so this page reports totals by country, group and sector and deliberately does not name any organisation. Figures describe what has been published in the feed window, not every attack that occurred.