# Malware adversary profiles & threat intelligence Attack chains, MITRE ATT&CK mappings, IOCs, and detection guidance for ransomware operations, infostealers, loaders, and emerging malware campaigns. ## Threat profiles ### Infostealers #### [Lumma Stealer](https://www.manageengine.com/malware-protection/adversaries/lumma-stealer.html) Steals credentials, session cookies, crypto wallets, and browser data. Published on Apr 28, 2026 #### [Fake Maccy Stealer](https://www.manageengine.com/malware-protection/adversaries/fakemaccy-stealer.html) Discovered by ManageEngine Impersonates a macOS app to steal credentials and sensitive data. Published on Jun 30, 2026 ### Loaders #### [CastleLoader](https://www.manageengine.com/malware-protection/adversaries/castleloader.html) Profiles infected devices and delivers additional malware payloads. Published on May 11, 2026 ### Ransomware #### [Medusa Ransomware](https://www.manageengine.com/malware-protection/adversaries/medusa-ransomware.html) Steals data and encrypts systems for double-extortion attacks. Published on Apr 28, 2026 #### [LockBit Ransomware](https://www.manageengine.com/malware-protection/adversaries/lockbit-ransomware.html) Spreads across enterprise environments and encrypts critical systems. Published on Jul 2, 2026 #### [Akira Ransomware](https://www.manageengine.com/malware-protection/adversaries/akira-ransomware.html) Disables defenses, steals data, and encrypts Windows and Linux systems. Published on Jun 2, 2026 #### [The Gentlemen Ransomware](https://www.manageengine.com/malware-protection/adversaries/gentlemen-ransomware.html) Destroys recovery options before encrypting networked systems. Published on Jul 14, 2026 #### [Qilin Ransomware](https://www.manageengine.com/malware-protection/adversaries/qilin-ransomware.html) Steals data, disables defenses, destroys backups, and encrypts Windows, Linux, and VMware ESXi systems. Published on Jul 13, 2026 #### [Jadepuffer Ransomware](https://www.manageengine.com/malware-protection/adversaries/jadepuffer-ransomware.html) LLM-driven malware that turns AI into an attack weapon. Published on Jul 22, 2026