Cyber Threat Intelligence Using Ensemble Approach to Identify Ransomware Attacks
Umar Ibrahim, Rayan Mosli · 2025
Numerous research studies have been carried out utilizing different datasets from X (formally Twitter) to other social media contents as sources of cyber threat intelligence. Some of these use different machine learning and deep learning techniques to automate the identification and profiling of emerging threats. This is due to the difficulty of manually locating and analyzing insightful patterns, trends, and insights from a large volume of unstructured tweets and other social media contents. Because information on X is updated in real time, researchers use the microblog as an open-source intelligence gateway to gather intelligence about various events like earthquakes, forest fires, terrorist attacks, and more. While X has proven useful in providing accurate and timely cyber threat intelligence about software vulnerabilities, cyber threats, and exploits, this work attempts to overcome the shortcomings of existing systems, like low accuracy and lack of feature contribution analysis. In this paper, we proposed a novel ensemble approach that integrates traditional machine learning, a convolutional neural network (CNN) and a fine-tuned BERT model for more efficient way of identifying ransomware attacks. The model leverages the weighted ensemble model to achieve higher accuracy. Our model uses feature engineering and sophisticated text preprocessing to identify important ransomware indicators. We employed LIME for Explainable AI, allowing for in-depth feature contribution analysis. Our approach also utilizes Ransomware.live API, which enabled us to obtain real-time indicators, such as ransomware groups, domains, and keywords to identify possible ransomware conversations. The ensemble model achieved an accuracy of 0.9859 and a ROC score of 1.00, which is a significant improvement in the field of cybersecurity and ransomware identification.