{"uid":"cap_p2uzxqMddh8vHccnSSw4X","slug":"cyberpulse-ransomware-intelligence-api-d3796471","name":"CyberPulse Ransomware Intelligence API","description":"Ransomware-group threat brief and tracking — victim patterns, TTPs, ransom economics, and defensive playbooks across LockBit, ALPHV, Cl0p, RansomHub, BlackBasta, Akira, and 50+ active groups, plus CISA KEV ransomware-linked CVEs. Global, for threat-intel and incident-response agents.","url":"https://cyberpulse.theaslangroupllc.com/api/cyber/ransomware-intel","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","properties":{"lang":{"type":"string","description":"en | es | fr | de | ja | zh | ko | pt | ar | hi (default: en)"},"group":{"type":"string","description":"Ransomware group name — e.g. \"LockBit\" | \"ALPHV\" | \"Cl0p\" | \"RansomHub\" | \"BlackBasta\" | \"Akira\" | \"Play\" | omit for landscape overview"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"errors":{"type":"object","description":"Documented error responses, keyed by HTTP status code","additionalProperties":{"type":"object","required":["description"],"properties":{"example":{"type":"object"},"description":{"type":"string"}}}},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"query":"LockBit","groups_analyzed":[{"name":"LockBit","status":"disrupted (Operation Cronos Feb 2024) — partially active under LockBit 3.0","activity_level":"moderate","primary_targets":{"sectors":["Finance","Healthcare","Government"],"countries":["USA","UK","Germany","Australia"]},"ransomware_as_a_service":true,"typical_ransom_range_usd":"$1,000,000 - $50,000,000"}],"executive_summary":"LockBit remains one of the most prolific ransomware operations despite law enforcement disruption in Feb 2024. Healthcare and finance are primary targets. Immutable backups and MFA on all remote access are the most effective countermeasures.","global_ransomware_statistics":{"average_downtime_days":21,"percentage_paying_ransom":"34%","average_ransom_demand_usd":1500000}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.2","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.2/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_OtII1bUvDCvhbA9h1BXXP","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.2","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns structured threat intelligence briefs on ransomware groups including victim patterns, TTPs, ransom economics, defensive playbooks, and CISA KEV-linked CVEs for 50+ active groups.","exampleAgentPrompt":"Give me a full threat intel brief on the LockBit ransomware group — victim patterns, known TTPs, ransom economics, any CISA KEV CVEs they exploit, and a defensive playbook I can hand to our incident response team.","exampleUseCases":[{"title":"Incident response plan for active ransomware","prompt":"We just got hit by what looks like a BlackBasta attack. Pull together everything on their victim targeting patterns, their typical attack techniques, what they're asking for in ransom demands, and give me a step-by-step playbook our team can use to contain and recover."},{"title":"Ransomware threat landscape for security team","prompt":"I need to brief our security leadership next week on what ransomware groups are actively targeting organizations like ours right now. Give me an overview of the top active groups, what their sweet spots are for victims, and what vulnerabilities they're exploiting so we know where to focus our patches."},{"title":"Vulnerability patching priority for Cl0p exposure","prompt":"Our vulnerability scanner flagged some systems that might be exposed to Cl0p ransomware. What are the CISA KEV CVEs that Cl0p is actually using in the wild, and what's their typical attack flow so I can understand how critical these patches really are?"}],"resultDescription":"A structured ransomware threat brief covering victim targeting patterns, tactics/techniques/procedures (TTPs), ransom demand economics, defensive and mitigation playbooks, and associated CISA KEV-listed CVEs for the queried ransomware group or across all tracked active groups.","failureModes":["Unknown or misspelled ransomware group name returns empty or partial results","Group no longer active may return stale data","Rate limiting or payment failure (402) if USDC balance insufficient","Network timeout if upstream threat-intel aggregation is slow","Very new ransomware groups may not yet be indexed"],"whenToPreferThis":"Choose this endpoint when you need structured, aggregated ransomware-specific threat intelligence including TTPs, victim profiling, and defensive guidance for a named group (LockBit, ALPHV, Cl0p, RansomHub, BlackBasta, Akira, and 50+ others). Prefer this over generic threat-intel endpoints when the query is explicitly ransomware-focused or involves incident response planning against a specific ransomware actor.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T00:36:19.958Z","isFirstParty":false}