Company
About SphereTI
SphereTI is a threat intelligence platform built and operated by Alphatechs, a cybersecurity company based in Tirana, Albania. The same team that collects and analyzes the intelligence builds the product, and publishes its measurements openly. It was previously published as Sphere Threat Intelligence.
Who builds it
SphereTI is the threat intelligence platform of Alphatechs, a cybersecurity company based in Tirana, Albania. Alphatechs handles the collection, analysis, and engineering behind the platform: the people who gather the intelligence and the people who build the product are the same team.
The company operates from Blv. Gjergj Fishta, Tirana, and can be reached at the address, phone number and email below. That detail is here because a threat intelligence vendor asking to be trusted with your domain should be locatable.
What the platform monitors
SphereTI is organized into five intelligence modules, each covering a different way an organization is exposed:
- Cyber decoys — fake assets planted where an intruder looks after gaining a foothold, so one interaction is a high-confidence alert.
- Dark web and stealer log monitoring — credentials, session cookies and company data surfacing in dark-web markets and infostealer dumps.
- Data intelligence — findings from every other module, correlated and weighted by what is actually happening to your organization.
- DNS and brand monitoring — lookalike domains and DNS records registered to be mistaken for yours.
- Vulnerability intelligence — the weaknesses under active exploitation that match what you actually expose.
All five run in one console. The product tour walks through it in screenshots from the platform — the intelligence dashboard, credential search, lookalike domain analysis and vulnerability intelligence.
There is also a free credential exposure report: enter a work email and SphereTI checks it against known breaches and stealer logs. It never asks for a password. The annual packages and domain limits are published on the pricing page.
Where the intelligence comes from
First-hand collection, and the team publishes what it measures. Over a 60-day window spanning the May 2025 international operation against Lumma Stealer, Alphatechs observed 881,387 compromised systems, of which 242,091 were attributed to Lumma, alongside 786,041 antivirus installations recorded across compromised systems.
The figures, the observation window, and the method are published in full in the Lumma Stealer analysis. For a DNS and brand-monitoring case study, read the Albania e-Visa scam analysis, or start with one of the definition pages:
- What is stealer log monitoring? — What infostealer malware takes, why breach checks miss it, and how monitoring closes the gap.
- What are cyber decoys? — Fake assets that nothing legitimate should ever touch — and what it means when something does.
The name
The platform is published as SphereTI. It was previously Sphere Threat Intelligence, and the legal documents refer to it as Sphere. All three names refer to the same product, operated by the same company, at the same address. Coverage areas: cyber deception, dark web monitoring, infostealer logs, credential exposure, dns and brand monitoring, vulnerability intelligence.
Contact
Check your own exposure
Enter a work email and SphereTI checks it against known breaches and stealer logs, then shows you which credentials have been exposed. Free, and it never asks for your password.
Get your free report