Prolific Puma is a cybercriminal infrastructure operator centered on DNS abuse and an underground link-shortening service used to support phishing, scams, and malware delivery. The actor has been active for at least four years and is notable for operating at scale through a registered domain generation algorithm that produces large volumes of short, pseudo-random domains, many of them strategically aged before operational use to reduce detection by controls focused on newly registered domains. The actor heavily abuses the .us top-level domain and has been associated with large-scale domain registration through NameSilo. Public WHOIS exposure in the .us namespace enabled researchers to correlate substantial portions of its infrastructure through registrant records, despite the actor’s use of false registration personas and fabricated address details. Prolific Puma has also used bulletproof hosting, dedicated VPS infrastructure, and cryptocurrency payments to sustain and anonymize its operations. Operationally, Prolific Puma functions as an enabler within the broader cybercrime ecosystem rather than solely as a direct intrusion actor. Its shortened links have been distributed through SMS, social media, and online advertisements, and have redirected victims to phishing pages, scam payment workflows, and browser-based malware. The actor’s infrastructure has been used by multiple malicious parties, and reporting has linked infrastructure associated with Prolific Puma to the Play ransomware operation. Shared infrastructure and tooling have been cited in connection with Play activity, indicating that Prolific Puma may provide services or infrastructure that support downstream ransomware and post-compromise operations. Known aliases are limited to Prolific Puma. The actor is best understood as a large-scale malicious infrastructure provider specializing in domain generation, DNS-enabled traffic redirection, and support services for financially motivated cybercrime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
92 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another threat actor that adopts registered domain generation algorithm (RDGA) techniques for domain provisioning; no additional campaign details provided in the content.
Prolific Puma is an infrastructure and tooling provider for ransomware operations, supporting Play Ransomware Gang with shared IPs and tools.
Associated with a large number of malicious domains that were correlated through WHOIS domain owner records; the operator registered domains under the .us TLD.
Prolific Puma is a DNS-based threat actor operating a large-scale, underground link shortening service that enables other cybercriminals to distribute phishing, scams, and malware. They register tens of thousands of domains using a registered domain generation algorithm (RDGA), primarily with the registrar NameSilo, and abuse TLDs such as .us, .info, .link, and others. Their infrastructure is used as a service by multiple malicious actors to evade detection and facilitate a variety of cybercrime campaigns, including phishing, identity theft, and browser-based malware delivery.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.