Threat intelligence that cites every claim, or makes none.

Signalis turns public CTI reporting into queryable reports, actors, CVEs, and indicators, all severity-ranked, cited, and honest about what the model assessed. Built for teams that read CTI daily. Free feed on a 7-day delay; real-time from $29/mo.

live feed · sampledelayed 7 days
Medium

Kairos ransomware gang publishes LR Reed as victim

in the wild7d ago
ransomware· ransomware.live· IOC ×1
High

South Korea discloses data breach impacting diplomats worldwide

7d ago
data breach· Bleeping Computer
Medium

Nova ransomware group publishes VNSO as new victim

in the wild7d ago
ransomware· ransomware.live· IOC ×1
High

Blacknevas ransomware claims Zuni Shopping Center, Inc.

in the wild7d ago
ransomware· ransomware.live· IOC ×2
High

Federal agencies broaden alert on Iran-linked OT attacks

in the wild7d ago
espionage· The Record (Recorded Future News)
Critical

Drupal Internationalization Single Sign-On Security Update (AV26-738)

7d ago
vulnerability disclosure· Canadian Centre Alerts

Speculo: cited, or refused.

Ask the corpus. Every claim carries a report citation, and when Signalis has nothing, it says so instead of guessing. No confident hallucinations.

> Who is APT28 and what are they known for?

apt28 is a Russia-aligned threat actor, also known as Forest Blizzard, Fancy Bear, Pawn Storm, Sednit, and GruesomeLarch #4223#3461#4163#5080. In Signalis reporting, the group first appears on 2024-11-22, with 20 reports in Signalis reporting to date [summary].

Primary Activities & Tactics:

apt28 specializes in espionage and infrastructure targeting, with a focus on government and critical infrastructure sectors [summary]. The group's primary attack techniques include exploiting public-facing applications [T1190], phishing [T1566], exfiltration over C2 channels [T1041], leveraging valid accounts [T1078], and deploying data-encrypting malware [T1486] [summary].

Notable Campaigns & Techniques:

DNS Hijacking & Token Harvesting: In a 2026 campaign, apt28 exploited vulnerabilities in Mikrotik and TP-Link routers to hijack DNS traffic and intercept Microsoft OAuth tokens from over 200 organizations and 5,000 consumer devices #4223.
Advanced Malware Suites: The group deployed PRISMEX, a multi-component malware combining steganography, COM hijacking, and cloud service abuse, targeting Ukrainian defense supply chains and NATO allies #3461. The group also operates BeardShell and Covenant implants leveraging cloud providers for command-and-control #4163.
AI-Enhanced Malware: apt28 has embedded AI capabilities into malware like LameHug for dynamic command generation and refined backdoors with AI-enhanced evasion #4221.
Supply-Chain Targeting: The group conducts proximity-based attacks, compromising adjacent organizations to establish network access to primary targets #5080.

Associated CVEs: CVE-2026-21509, CVE-2026-1340, CVE-2025-55182, CVE-2026-1281, CVE-2026-21513 [summary].

> What do you know about the Voidglobe ransomware group?

Signalis has no reporting on that.

No fabrication. The corpus is silent, so Speculo is too.

#id = grounded report citation (report detail is a member feature). Actor and CVE links are public.

Actor intelligence, at a glance.

Every actor gets a deterministic mark and a relationship graph of co-mentioned actors, exploited CVEs, targeted sectors, derived from the corpus, honestly labeled as co-mention, not confirmed collaboration.

A feed you can query. And an API.

Severity-ranked reports with structured extraction: CVEs, MITRE ATT&CK techniques, actors, and refanged indicators. Pull the actionable, attacker-role IOCs straight into MISP, OpenCTI, or your own tooling. API docs →

# attacker-role IOCs, cursor-paginated (Pro/Team key)
curl -H "Authorization: Bearer $SIGNALIS_API_KEY" \
  https://api.signalis.watch/api/feed/v1/iocs?type=domain

Watchlist alerts

Pin actors and CVEs; get one daily digest when they show new activity. Inbox respect is a feature.

Weekly briefing

A Monday digest of your watchlist plus the week's most-active actors and newly-exploited CVEs. Free tier included.

Honest by construction.

Severity and classification are model judgments, not measurements. And we say so. Extractions carry confidence; dates and counts describe Signalis's reporting window, not real-world ground truth. We'd rather show you a refusal than a confident guess. Read the methodology →

Plans

FreePro $29/moTeam $69/mo
Feed7-day delayedreal-timereal-time
Report filters1unlimitedunlimited
Watchlist pins125100
Weekly digest
Daily alerts
Analytics board
Speculo Q&A200/mo1,000/mo
IOC / feed API10k calls/mo100k calls/mo