Threat intelligence that cites every claim, or makes none.

Signalis turns public CTI reporting into queryable reports, actors, CVEs, and indicators, all severity-ranked, cited, and honest about what the model assessed. Built for teams that read CTI daily. Free feed on a 7-day delay; real-time from $29/mo.

live feed · sampledelayed 7 days
High

Panzer ransomware gang publishes Edacentrum as new victim

in the wild7d ago
ransomware· ransomware.live· IOC ×1
Critical

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

in the wild7d ago
vulnerability disclosure· The Hacker News
High

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run Crypto Miner

in the wild7d ago
malware infection· The Hacker News· IOC ×9
High

Vexy ransomware claims McDonald's Ecuador breach

in the wild7d ago
ransomware· ransomware.live· IOC ×3
High

Direwolf ransomware gang publishes Mission Pet Health as victim

in the wild8d ago
ransomware· ransomware.live· IOC ×1
High

Kazu ransomware gang publishes Spirit Cultural Exchange as victim

in the wild8d ago
ransomware· ransomware.live· IOC ×6

Speculo: cited, or refused.

Ask the corpus. Every claim carries a report citation, and when Signalis has nothing, it says so instead of guessing. No confident hallucinations.

> Who is APT28 and what are they known for?

apt28 is a Russia-aligned threat actor, also known as Forest Blizzard, Fancy Bear, Pawn Storm, Sednit, and GruesomeLarch #4223#3461#4163#5080. In Signalis reporting, the group first appears on 2024-11-22, with 20 reports in Signalis reporting to date [summary].

Primary Activities & Tactics:

apt28 specializes in espionage and infrastructure targeting, with a focus on government and critical infrastructure sectors [summary]. The group's primary attack techniques include exploiting public-facing applications [T1190], phishing [T1566], exfiltration over C2 channels [T1041], leveraging valid accounts [T1078], and deploying data-encrypting malware [T1486] [summary].

Notable Campaigns & Techniques:

DNS Hijacking & Token Harvesting: In a 2026 campaign, apt28 exploited vulnerabilities in Mikrotik and TP-Link routers to hijack DNS traffic and intercept Microsoft OAuth tokens from over 200 organizations and 5,000 consumer devices #4223.
Advanced Malware Suites: The group deployed PRISMEX, a multi-component malware combining steganography, COM hijacking, and cloud service abuse, targeting Ukrainian defense supply chains and NATO allies #3461. The group also operates BeardShell and Covenant implants leveraging cloud providers for command-and-control #4163.
AI-Enhanced Malware: apt28 has embedded AI capabilities into malware like LameHug for dynamic command generation and refined backdoors with AI-enhanced evasion #4221.
Supply-Chain Targeting: The group conducts proximity-based attacks, compromising adjacent organizations to establish network access to primary targets #5080.

Associated CVEs: CVE-2026-21509, CVE-2026-1340, CVE-2025-55182, CVE-2026-1281, CVE-2026-21513 [summary].

> What do you know about the Voidglobe ransomware group?

Signalis has no reporting on that.

No fabrication. The corpus is silent, so Speculo is too.

#id = grounded report citation (report detail is a member feature). Actor and CVE links are public.

Actor intelligence, at a glance.

Every actor gets a deterministic mark and a relationship graph of co-mentioned actors, exploited CVEs, targeted sectors, derived from the corpus, honestly labeled as co-mention, not confirmed collaboration.

A feed you can query. And an API.

Severity-ranked reports with structured extraction: CVEs, MITRE ATT&CK techniques, actors, and refanged indicators. Pull the actionable, attacker-role IOCs straight into MISP, OpenCTI, or your own tooling. API docs →

# attacker-role IOCs, cursor-paginated (Pro/Team key)
curl -H "Authorization: Bearer $SIGNALIS_API_KEY" \
  https://api.signalis.watch/api/feed/v1/iocs?type=domain

Watchlist alerts

Pin actors and CVEs; get one daily digest when they show new activity. Inbox respect is a feature.

Weekly briefing

A Monday digest of your watchlist plus the week's most-active actors and newly-exploited CVEs. Free tier included.

Honest by construction.

Severity and classification are model judgments, not measurements. And we say so. Extractions carry confidence; dates and counts describe Signalis's reporting window, not real-world ground truth. We'd rather show you a refusal than a confident guess. Read the methodology →

Plans

FreePro $29/moTeam $69/mo
Feed7-day delayedreal-timereal-time
Report filters1unlimitedunlimited
Watchlist pins125100
Weekly digest
Daily alerts
Analytics board
Speculo Q&A200/mo1,000/mo
IOC / feed API10k calls/mo100k calls/mo