Connecting to feeds

Global Threat Board

Live ransomware activity around the world, and the software flaws attackers are exploiting right now. Then the tools to clean an infected machine — all checked, all from the vendor direct.

Attack Claims
Countries Hit
Active Groups
Exploited Flaws
Used In Ransomware

Where it is happening

Attack claims by country

Equirectangular · marker area ∝ claim count

Loading…

Statistics

Derived from the same claims as everything above — moves with the range tabs

Loading…

Sectors targeted

Victim sector, where disclosed

Loading…

Claims per hour

Rolling window, UTC

Loading…

Who these groups are

Profiles for the groups currently claiming victims

Aliases, first seen, tooling and MITRE ATT&CK tactics — for the groups on the board above

Loading…

Exploited in the wild right now

Latest additions to the CISA Known Exploited Vulnerabilities catalogue

If you run any of this software, patching it is urgent — these are confirmed under active attack

Loading…

Malware removal tools

Every link checked · vendor pages only, never a direct download

Read this first

  • Only ever download from the vendor's own site. Search results for "free virus removal" are a well-known malware delivery route. Every link below goes to the official page — not to a direct installer, because those move and get mirrored by others.
  • On-demand scanners are safe to stack; real-time antivirus is not. The scanners in the first group run once and exit, so you can use several for a second opinion. Never install two always-on antivirus products together.
  • If the machine is badly infected, scan it from outside. Malware with kernel access can hide from any tool running inside the infected Windows. That is what the rescue media group is for.
  • Back up your files before running an aggressive remover — on a drive you then unplug. Removal can break a system that was limping along, and ransomware can encrypt an attached backup.
  • Never pay a ransom before checking No More Ransom. A free decryptor already exists for many strains. Paying funds the next attack and often gets you nothing.
  • Tools deliberately not listed here: ComboFix (long obsolete and can break modern Windows), anything marketed as a "registry cleaner" (does not remove malware), and Kaspersky's TDSSKiller — discontinued, and its signed driver has been abused by ransomware crews to switch off security software.

1 · Free on-demand scanners

Start here. Each runs once, checks the machine and exits, so several can be used together for a second opinion without conflicting with the antivirus you already have.

Think you have picked something up?

If a machine is behaving oddly, showing pop-ups, running hot, or you have opened something you wish you hadn't — I clean infections properly and recover data where it is recoverable. Based in Taunton, Somerset, remote or in person.

Get it looked at

 

Attack data from ransomware.live, which aggregates public ransomware leak-site postings. Vulnerability data from the CISA Known Exploited Vulnerabilities catalogue (public domain).

Counts only. Attack claims are made by the attackers themselves on their own leak sites and are not independently verified, so this page reports totals by country, group and sector and deliberately does not name any organisation. Figures describe what has been published in the feed window, not every attack that occurred.