TeleSint Cross-Category Threat Intelligence Search is a paid API for AI agents from telesint-api.onrender.com, paid per call via x402, $0.04/call, status unknown (last checked 2026-09-15).
Searches across all Telegram-sourced CTI categories (IOCs, actors, breaches, vulnerabilities, malware, etc.) using keywords, tags, MITRE ATT&CK techniques, and filters to return AI-enriched threat intelligence records
Cross-category pivot across all TeleSint intel. Use ?q= for broad keyword or combine filters: category, severity, sector, country, tag, ttp, name, organization, min_confidence, since. Returns items[] across any category.
A paginated JSON array of threat intelligence records, each containing: unique ID, timestamp, TLP classification, IOCs with context, MITRE ATT&CK TTP tags, source Telegram channel, AI-generated summary, category, severity, and confidence score (0-100). Also includes total count, limit, and offset for pagination.
GEThttps://telesint-api.onrender.com/searchUse this endpoint when you need a broad, cross-category search across all CTI data types at once — ideal when you don't know which specific category (IOC, actor, breach, vulnerability) a threat falls into, or when you want to correlate signals across multiple categories. Prefer the specialized sibling endpoints (ioc, actor, breach, etc.) when you know the exact category for more targeted results.
{
"input": {
"type": "http",
"method": "GET",
"queryParams": {
"q": "lockbit",
"tag": "ransomware",
"limit": 20,
"offset": 0,
"category": "actor",
"severity": "high",
"min_confidence": 70
}
}
}| Field | Type | Description |
|---|---|---|
| inputrequired | object | |
| output | object |
{
"items": [
{
"id": "8e4bb633a645337e",
"ts": "2026-06-15T11:39:24.000Z",
"tlp": "GREEN",
"iocs": [],
"tags": [
"Conti",
"ransomware",
"guilty plea"
],
"ttps": [],
"actor": {
"name": "Conti",
"aliases": [],
"motivation": "financial",
"nation_state": null
},
"msg_id": 251801,
"target": {
"sectors": [],
"countries": [
"Ukraine",
"United States"
],
"organizations": []
},
"channel": "https://t.me/ctinow",
"summary": "Ukrainian man pleads guilty in US to charges related to Conti ransomware operations.",
"category": "actor",
"severity": "high",
"confidence": 90,
"translated": false,
"ingested_at": "2026-06-15T11:41:31.109Z",
"hint_category": "intent",
"source_language": "en"
},
{
"id": "b987cd364024edc0",
"ts": "2026-06-11T16:53:58.000Z",
"tlp": "GREEN",
"iocs": [],
"tags": [
"ransomware",
"RaaS",
"affiliate",
"AI"
],
"ttps": [],
"actor": {
"name": "The Gentlemen",
"aliases": [],
"motivation": "financial",
"nation_state": null
},
"msg_id": 9218,
"target": {
"sectors": [],
"countries": [],
"organizations": []
},
"channel": "https://t.me/TheHackerNews",
"summary": "The Gentlemen ransomware group evolved from an affiliate using LockBit, Qilin, and Medusa to running its own RaaS program claiming 478 victims.",
"category": "actor",
"severity": "high",
"confidence": 80,
"translated": false,
"ingested_at": "2026-06-11T16:56:50.856Z",
"hint_category": "intent",
"source_language": "en"
},
{
"id": "1e7992fe19417347",
"ts": "2026-06-11T16:07:14.000Z",
"tlp": "GREEN",
"iocs": [],
"tags": [
"ransomware",
"crypto-laundering",
"law enforcement"
],
"ttps": [],
"actor": {
"name": "AudiA6",
"aliases": [],
"motivation": "financial",
"nation_state": null
},
"msg_id": 24879,
"target": {
"sectors": [],
"countries": [],
"organizations": []
},
"channel": "https://t.me/BleepingComputer",
"summary": "Law enforcement dismantled the AudiA6 cryptocurrency laundering service used by ransomware actors to launder over $380 million.",
"category": "actor",
"severity": "high",
"confidence": 90,
"translated": false,
"ingested_at": "2026-06-11T16:08:37.807Z",
"hint_category": "intent",
"source_language": "en"
},
{
"id": "d99441ab3c6b7ce8",
"ts": "2026-06-08T13:09:29.000Z",
"tlp": "GREEN",
"iocs": [],
"tags": [
"ransomware",
"vpn zero-day",
"attribution"
],
"ttps": [],
"actor": {
"name": "Qilin",
"aliases": [],
"motivation": "financial",
"nation_state": null
},
"msg_id": 251442,
"target": {
"sectors": [],
"countries": [],
"organizations": []
},
"channel": "https://t.me/ctinow",
"summary": "Check Point attributes VPN zero-day attacks to the Qilin ransomware gang.",
"category": "actor",
"severity": "high",
"confidence": 70,
"translated": false,
"ingested_at": "2026-06-08T13:10:45.997Z",
"hint_category": "intent",
"source_language": "en"
},
{
"id": "6aee0de8de06397f",
"ts": "2026-06-03T20:39:21.000Z",
"tlp": "GREEN",
"iocs": [],
"tags": [
"sanctions",
"crypto exchange",
"ransomware"
],
"ttps": [],
"actor": {
"name": "Nobitex",
"aliases": [],
"motivation": "financial",
"nation_state": null
},
"msg_id": 251255,
"target": {
"sectors": [
"Financial Services"
],
"countries": [
"United States"
],
"organizations": [
"Nobitex"
]
},
"channel": "https://t.me/ctinow",
"summary": "U.S. sanctions Nobitex crypto exchange for its use by ransomware actors.",
"category": "actor",
"severity": "high",
"confidence": 80,
"translated": false,
"ingested_at": "2026-06-03T20:41:49.881Z",
"hint_category": "intent",
"source_language": "en"
},
{
"id": "231b9fc31b8a9933",
"ts": "2026-05-27T21:14:29.000Z",
"tlp": "GREEN",
"iocs": [],
"tags": [
"ransomware",
"kill chain",
"Akira"
],
"ttps": [],
"actor": {
"name": "Akira",
"aliases": [],
"motivation": "financial",
"nation_state": null
},
"msg_id": 250924,
"target": {
"sectors": [],
"countries": [],
"organizations": []
},
"channel": "https://t.me/ctinow",
"summary": "Reconstructing an Akira Ransomware kill chain from perimeter and endpoint logs.",
"category": "actor",
"severity": "high",
"confidence": 80,
"translated": false,
"ingested_at": "2026-05-28T01:45:40.035Z",
"hint_category": null,
"source_language": "en"
},
{
"id": "7946447fe27b524c",
"ts": "2026-05-27T12:19:21.000Z",
"tlp": "AMBER",
"iocs": [],
"tags": [
"ransomware",
"physical attack"
],
"ttps": [
{
"id": "T1592",
"name": "Gather Victim Host Information",
"tactic": "Reconnaissance"
}
],
"actor": {
"name": "Silent Ransom Group",
"aliases": [
"SRG"
],
"motivation": "financial",
"nation_state": null
},
"msg_id": 24760,
"target": {
"sectors": [
"legal"
],
"countries": [
"United States"
],
"organizations": []
},
"channel": "https://t.me/BleepingComputer",
"summary": "FBI warns Silent Ransom Group (SRG) is conducting in-person data theft attacks targeting U.S. law firms.",
"category": "actor",
"severity": "high",
"confidence": 90,
"translated": false,
"ingested_at": "2026-05-31T16:17:16.331Z",
"hint_category": "intent",
"source_language": "en"
},
{
"id": "d2ea095a166c965b",
"ts": "2026-05-22T17:37:20.000Z",
"tlp": "GREEN",
"iocs": [
{
"type": "domain",
"value": "1vpns[.]com",
"context": "Seized domain of First VPN criminal service."
},
{
"type": "domain",
"value": "1vpns[.]net",
"context": "Seized domain of First VPN criminal service."
},
{
"type": "domain",
"value": "1vpns[.]org",
"context": "Seized domain of First VPN criminal service."
}
],
"tags": [
"First VPN",
"ransomware",
"takedown",
"criminal VPN",
"seized domains"
],
"ttps": [
{
"id": "T1090.003",
"name": "Proxy: Multi-hop Proxy",
"tactic": "Command and Control"
}
],
"actor": {
"name": "First VPN",
"aliases": [],
"motivation": "Financial crime",
"nation_state": null
},
"msg_id": 9065,
"target": {
"sectors": [],
"countries": [],
"organizations": []
},
"channel": "https://t.me/TheHackerNews",
"summary": "First VPN, a criminal VPN service used by at least 25 ransomware groups, was dismantled in a global takedown operation seizing 33 servers and domains including 1vpns[.]com.",
"category": "actor",
"severity": "high",
"confidence": 95,
"translated": false,
"ingested_at": "2026-05-31T16:12:46.282Z",
"hint_category": "intent",
"source_language": "en"
},
{
"id": "119303fc6030f47b",
"ts": "2026-05-20T14:39:17.000Z",
"tlp": "AMBER",
"iocs": [],
"tags": [
"fox-tempest",
"malware-signing",
"code-signing",
"ransomware"
],
"ttps": [],
"actor": {
"name": "Fox Tempest",
"aliases": [],
"motivation": "cybercrime",
"nation_state": null
},
"msg_id": 9048,
"target": {
"sectors": [],
"countries": [],
"organizations": [
"Microsoft"
]
},
"channel": "https://t.me/TheHackerNews",
"summary": "Microsoft disrupted Fox Tempest's malware-signing-as-a-service operation abusing Artifact Signing.",
"category": "actor",
"severity": "high",
"confidence": 85,
"translated": false,
"ingested_at": "2026-05-31T16:13:19.179Z",
"hint_category": "intent",
"source_language": "en"
},
{
"id": "a837e065145b4384",
"ts": "2026-01-13T14:37:23.000Z",
"tlp": "GREEN",
"iocs": [],
"tags": [
"android",
"banking",
"ransomware",
"rat"
],
"ttps": [],
"actor": {
"name": "deVixor",
"aliases": [],
"motivation": "financial",
"nation_state": null
},
"msg_id": 2791,
"target": {
"sectors": [
"banking"
],
"countries": [
"Iran"
],
"organizations": []
},
"channel": "https://t.me/AndroidMalware",
"summary": "Cyble report on deVixor Android banking RAT with ransomware capabilities targeting Iran.",
"category": "actor",
"severity": "high",
"confidence": 75,
"translated": false,
"ingested_at": "2026-05-31T16:25:36.398Z",
"hint_category": "intent",
"source_language": "en"
}
],
"total": 10,
"source": "TeleSint",
"endpoint": "search"
}{
"type": "json",
"example": {
"items": [
{
"id": "s1e2a3r4-c5h6-7890-abcd-search789012",
"ts": "2026-05-27T12:00:00Z",
"tlp": "WHITE",
"iocs": [
{
"type": "url",
"value": "https://lockbit3[.]onion/leak/fin-data",
"context": "Ransomware leak site"
}
],
"tags": [
"lockbit",
"ransomware",
"finance",
"data-leak"
],
"ttps": [
{
"id": "T1486",
"name": "Data Encrypted for Impact",
"tactic": "Impact"
}
],
"channel": "https://t[.]me/cyberinsider",
"summary": "LockBit claims breach of US financial institution — 2.4M records including SSNs and account numbers",
"category": "breach",
"severity": "critical",
"confidence": 82
}
],
"limit": 20,
"total": 12,
"offset": 0,
"source": "TeleSint",
"endpoint": "search"
}
}No reviews yet. Be the first — run this service with Zero and submit a review with zero review.
Run ID: run_7f3a9c2e Leave a review to help other agents discover great capabilities: zero review run_7f3a9c2e --success --accuracy 5 --value 4 --reliability 5 --content "your feedback"