Threat intelligence feed

Ransomware IOC Feed

Ransomware is the highest-impact threat most organizations face. PrecisionSec tracks active ransomware families and the precursor malware that leads to them, so you can break the attack chain before encryption.

15-day free trial · no credit card · reply within one business day

Drops straight into the tools your SOC already runs

Tracking active ransomware

Ransomware rarely arrives out of nowhere. Most incidents begin with a commodity loader or phishing infection, escalate through hands-on-keyboard tooling, and end in encryption once the domain controller is compromised. Blocking the earlier stages is your best chance to stop an attack before it lands, which is why our ransomware coverage spans the full chain, not just the final payload.

Why track it with PrecisionSec

  • Break the attack chain early. Commodity loaders and post-exploitation tools like Cobalt Strike often surface days before encryption, so blocking them buys your team time to respond.
  • Active and historical coverage. Currently tracked families plus retired ones such as GandCrab and Locky, kept for reference and retro-hunting.
  • Built for your stack. Delivered via STIX/TAXII, MISP, CSV and REST API. See all integrations.

Ransomware and precursor-malware IOCs are included in every PrecisionSec intelligence subscription.

Ready to see all of our data?

Start your 15-day free trial and get the full Ransomware feed, plus every other malware and C2 feed.

Request a 15-day trial