{"uid":"cap_PL1_WlDFMr92gxcizJZ0B","slug":"cyberpulse-ransomware-intel-90bd1021","name":"CyberPulse Ransomware Intel","description":"Ransomware-group threat brief and tracking — victim patterns, TTPs, ransom economics, and defensive playbooks across LockBit, ALPHV, Cl0p, RansomHub, BlackBasta, Akira, and 50+ active groups, plus CISA KEV ransomware-linked CVEs. Global, for threat-intel and incident-response agents.","url":"https://cyberpulse-six.vercel.app/api/cyber/ransomware-intel","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","properties":{"lang":{"type":"string","description":"en | es | fr | de | ja | zh | ko | pt | ar | hi (default: en)"},"group":{"type":"string","description":"Ransomware group name — e.g. \"LockBit\" | \"ALPHV\" | \"Cl0p\" | \"RansomHub\" | \"BlackBasta\" | \"Akira\" | \"Play\" | omit for landscape overview"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"errors":{"type":"object","description":"Documented error responses, keyed by HTTP status code","additionalProperties":{"type":"object","required":["description"],"properties":{"example":{"type":"object"},"description":{"type":"string"}}}},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"query":"LockBit","groups_analyzed":[{"name":"LockBit","status":"disrupted (Operation Cronos Feb 2024) — partially active under LockBit 3.0","activity_level":"moderate","primary_targets":{"sectors":["Finance","Healthcare","Government"],"countries":["USA","UK","Germany","Australia"]},"ransomware_as_a_service":true,"typical_ransom_range_usd":"$1,000,000 - $50,000,000"}],"executive_summary":"LockBit remains one of the most prolific ransomware operations despite law enforcement disruption in Feb 2024. Healthcare and finance are primary targets. Immutable backups and MFA on all remote access are the most effective countermeasures.","global_ransomware_statistics":{"average_downtime_days":21,"percentage_paying_ransom":"34%","average_ransom_demand_usd":1500000}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.2","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.2/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_TKfvPnLT1iptAskyx8Lre","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.2","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns victim patterns, TTPs, ransom economics, defensive playbooks, and CISA KEV-linked entries for 50+ active ransomware groups including LockBit, ALPHV, Cl0p, RansomHub, BlackBasta, and Akira.","exampleAgentPrompt":"Pull me the full threat-intel profile for LockBit ransomware — victim patterns, TTPs, ransom economics, and the defensive playbook I should use for incident response, including any related CISA KEV entries.","exampleUseCases":[{"title":"Healthcare sector ransomware defense","prompt":"Which ransomware groups are actively targeting hospitals and healthcare networks right now, and what defensive playbooks should we implement to protect our patient data systems?"},{"title":"Incident response threat briefing","prompt":"We just got hit by what looks like Cl0p ransomware. Give me their victim patterns, current TTPs, ransom economics so I understand what we're dealing with, and the defensive playbook to contain this."},{"title":"Proactive vulnerability patch prioritization","prompt":"Show me which CISA known exploited vulnerabilities are being weaponized by the most active ransomware groups right now so we know which systems to patch first across our infrastructure."}],"resultDescription":"Returns structured threat intelligence for ransomware groups including victim targeting patterns, tactics/techniques/procedures (TTPs), ransom payment economics, defensive countermeasure playbooks, and CISA Known Exploited Vulnerabilities entries linked to the queried ransomware group(s).","failureModes":["Unknown or unrecognized ransomware group name returns empty or 404 response","Stale intelligence if a group has recently rebranded or dissolved","Rate limiting or payment failure returns 402 error","Overly broad queries may return aggregated rather than group-specific data"],"whenToPreferThis":"Use this endpoint when an agent needs structured, actionable ransomware threat intelligence — specifically victim patterns, TTPs, ransom economics, or defensive playbooks — for a named ransomware group or sector. Prefer this over generic CVE or OSINT endpoints when the threat context is ransomware-specific and incident response or proactive defense is the goal.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:43:07.338Z","isFirstParty":false}