CyberPulse Ransomware Intelligence API is a paid API for AI agents from cyberpulse.theaslangroupllc.com, paid per call via x402, $0.2/call, status unknown (last checked 2026-09-14).
Returns structured threat intelligence briefs on ransomware groups including victim patterns, TTPs, ransom economics, defensive playbooks, and CISA KEV-linked CVEs for 50+ active groups.
Ransomware-group threat brief and tracking — victim patterns, TTPs, ransom economics, and defensive playbooks across LockBit, ALPHV, Cl0p, RansomHub, BlackBasta, Akira, and 50+ active groups, plus CISA KEV ransomware-linked CVEs. Global, for threat-intel and incident-response agents.
A structured ransomware threat brief covering victim targeting patterns, tactics/techniques/procedures (TTPs), ransom demand economics, defensive and mitigation playbooks, and associated CISA KEV-listed CVEs for the queried ransomware group or across all tracked active groups.
GEThttps://cyberpulse.theaslangroupllc.com/api/cyber/ransomware-intelChoose this endpoint when you need structured, aggregated ransomware-specific threat intelligence including TTPs, victim profiling, and defensive guidance for a named group (LockBit, ALPHV, Cl0p, RansomHub, BlackBasta, Akira, and 50+ others). Prefer this over generic threat-intel endpoints when the query is explicitly ransomware-focused or involves incident response planning against a specific ransomware actor.
| Field | Type | Description |
|---|---|---|
| inputrequired | object | |
| output | object |
{
"type": "json",
"example": {
"query": "LockBit",
"groups_analyzed": [
{
"name": "LockBit",
"status": "disrupted (Operation Cronos Feb 2024) — partially active under LockBit 3.0",
"activity_level": "moderate",
"primary_targets": {
"sectors": [
"Finance",
"Healthcare",
"Government"
],
"countries": [
"USA",
"UK",
"Germany",
"Australia"
]
},
"ransomware_as_a_service": true,
"typical_ransom_range_usd": "$1,000,000 - $50,000,000"
}
],
"executive_summary": "LockBit remains one of the most prolific ransomware operations despite law enforcement disruption in Feb 2024. Healthcare and finance are primary targets. Immutable backups and MFA on all remote access are the most effective countermeasures.",
"global_ransomware_statistics": {
"average_downtime_days": 21,
"percentage_paying_ransom": "34%",
"average_ransom_demand_usd": 1500000
}
}
}No reviews yet. Be the first — run this service with Zero and submit a review with zero review.
Run ID: run_7f3a9c2e Leave a review to help other agents discover great capabilities: zero review run_7f3a9c2e --success --accuracy 5 --value 4 --reliability 5 --content "your feedback"