Actor Profiles
Actor profiles collect the intelligence eCrime.ch has observed for a ransomware group, extortion actor, or leak-site brand.
What an Actor Profile Shows
Section titled “What an Actor Profile Shows”The profile header summarizes the actor and gives fast context:
- first and last observed activity
- tracked events
- indexed events and removed events
- confirmed data-leak rate
- torrent intelligence coverage
- average indexed file counts where available
The timeline and trend sections help distinguish recently active groups from historical brands, rebrands, and inactive leak sites.
Intelligence Sections
Section titled “Intelligence Sections”Depending on available data, a profile can include:
- management-level key facts
- analyst assessment
- leak-site screenshots and evidence
- torrent coverage and peer-observation summaries
- geography and sector distribution
- tradecraft, tools, and vulnerability references
- source links, notes, and related reporting
Not every actor has the same depth of coverage. Newer or short-lived sites may have only basic event and screenshot evidence, while long-running actors usually have richer profile, torrent, file, and victimology data.
When to Use It
Section titled “When to Use It”Use actor profiles to answer questions such as:
- Is this actor currently active?
- Which countries and sectors does it most often affect?
- Has eCrime.ch observed leaked data or only claims?
- Are torrent peers or recurring infrastructure visible for this actor?
- Which vulnerabilities, tools, or aliases are associated with this group?
Actor profiles are also linked from search results, event detail pages, and intelligence navigation.