FROST-KRAKEN
Ragnarok malware · high severity
A payload-staging and C2 operator behind the Ragnarok family. Tracked across staging domains, C2 panels, and first-stage droppers; our highest-confidence cluster.
RuneFeed is the NorseStar threat-intelligence database — every indicator our sensor grid attributes, scored and enriched, delivered as STIX/TAXII, a REST API, or native connectors for your SIEM and SOAR. The same data that trains Valkyrie AI, in your stack.
Every indicator RuneFeed publishes carries the same enrichment: the actor and malware family it belongs to, a confidence score, a severity, and a first-seen timestamp. Analysts query it directly; machines pull it through the API; Valkyrie AI trains on it nightly.
Confidence 0–100 with first-seen and last-seen on every record.
Adversary-infrastructure and malware-family tagging on every indicator.
IPv4, domain, URL, SHA-256, MD5, and email indicators.
Push to Splunk, Sentinel, Elastic, and webhook sinks.
| Type | Indicator | Actor | Malware family | Conf. | Severity |
|---|---|---|---|---|---|
| ipv4 | 203.0.113.47 | FROST-KRAKEN | Ragnarok | 85 | high |
| domain | cdn-updates.frosthollow.example | FROST-KRAKEN | Ragnarok | 78 | high |
| ipv4 | 198.51.100.22 | NIGHT-RAVEN | Draugr | 72 | medium |
| sha256 | a3f1c9e4b7d20516… | FROST-KRAKEN | Ragnarok | 90 | critical |
| payments@odin-invoices.example | FJORD-SPIDER | — | 70 | high | |
| md5 | 1a2b3c4d5e6f7a8b… | — | Fenrir | 60 | medium |
Representative records — all indicators shown are fictional.
RuneFeed clusters indicators into the adversaries behind them. Three of the campaigns our intelligence team tracks most closely:
Ragnarok malware · high severity
A payload-staging and C2 operator behind the Ragnarok family. Tracked across staging domains, C2 panels, and first-stage droppers; our highest-confidence cluster.
Draugr malware · medium severity
A reconnaissance and credential-phishing actor distributing the Draugr loader. Noted for valhalla-themed SSO phishing landings and scanning infrastructure.
BEC & exfiltration · high severity
A financially-motivated actor running business-email-compromise and data-exfiltration campaigns. Tracked by sender infrastructure and exfil endpoints rather than a named family.
Community
Public sample feed
Pro
Real-time API
Enterprise
Private intelligence
RuneFeed is not just an export. It is the ground-truth label store the rest of DarkWatch learns from — every analyst-confirmed indicator becomes a training example.
Each night, confirmed RuneFeed indicators are promoted into the labeled corpus that retrains Valkyrie AI's classifiers from the NorseStar model registry. A new indicator an analyst confirms today shapes how Valkyrie scores tomorrow's traffic.
Currently shipping RuneFeed 5.2. Highlights from recent releases.
The feed is the data. These products collect it, read it, and connect it.
The global attack map
Renders every attack the sensor grid sees, in real time, with AI-attack fingerprinting — the screen on the SOC wall.
Explore DarkWatch Live ▸Global collection grid
Passive sensors, honeypots, and dark-IP listeners that capture the raw attack traffic RuneFeed enriches.
Explore Bifrost ▸Analyst copilot & triage
Reads the firehose for you — clustering campaigns and flagging machine-generated attacks, trained on RuneFeed labels.
Explore Valkyrie AI ▸Attribution & infrastructure graph
Connects every RuneFeed indicator — domains, certs, ASNs, wallets, operators — into the whole adversary tree.
Explore Yggdrasil ▸A sandbox key, the STIX/TAXII docs, and a sample sector-scoped collection — enough to wire RuneFeed into your SIEM this afternoon.
Request API access ▸