Skip to main content
Mallory
3 malware families

Nullbulge

Also known asNullbulge

NullBulge is a cybercriminal threat group that emerged in early 2024, active between at least April and July 2024, targeting AI-focused applications, gaming communities, and related software supply chains. The group presents itself as a pro-artist, anti-AI hacktivist collective claiming to protect artists, but reporting in the provided content assesses its activity as financially motivated and involving data theft and extortion. NullBulge targets victims through software supply chain compromises and malware distribution via public repositories and community platforms, including GitHub, Hugging Face, Reddit, Discord, ModLand, and BeamNG-related communities. Reported activity includes compromising or abusing the ComfyUI_LLMVISION extension on GitHub and distributing malicious BeamNG mods. The group weaponized code in publicly available repositories, including modified requirements.txt files that loaded trojanized Python wheels masquerading as Anthropic and OpenAI libraries, including a fake OpenAI library version 1.16.3. Observed tooling and malware include Python-based payloads that exfiltrated victim data through Discord webhooks, trojanized libraries containing components such as Fadmino.py, admin.py, and cadmino.py, and Lua scripts executing base64-encoded PowerShell. These payloads harvested browser data, geographic data, system information, installed applications, security product information, and financial data. NullBulge also delivered Async RAT and Xworm, including infections launched from malicious PowerShell downloaded from services such as pixeldrain and modsfire. Later-stage activity included deployment of customized LockBit ransomware built using the leaked LockBit 3.0/LockBit Black builder. Reported LockBit configuration features included local disk and network share encryption, process and service termination, ransom note printing, wallpaper changes, self-deletion, and event log deletion. The actor allegedly leaked Disney-related data in June and July 2024, including DuckTales files and a purported 1.2TB archive of internal Slack data, and claimed access was obtained through compromised corporate account credentials. NullBulge used its own leak infrastructure and public channels such as 4chan to announce and distribute leaks. Reported infrastructure included nullbulge.com, nullbulge.se, nullbulge.co, group.goocasino.org, and a Tor onion site. The group also maintained underground forum profiles where it sold infostealer logs and stolen OpenAI API keys. The alias AppleBotzz is associated with GitHub, Hugging Face, ModLand, and related malware distribution activity tied to NullBulge. The provided content states there is insufficient evidence to confirm whether AppleBotzz and NullBulge are separate entities, but assesses AppleBotzz as likely central to NullBulge’s delivery infrastructure. No nation-state attribution is established in the provided content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Software & Services
  • Media & Entertainment

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
MITRE ATT&CK

Tradecraft

20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics26 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
3 techniques
T1078
Valid Accounts
T1195
Supply Chain Compromise
T1195.001
Compromise Software Dependencies and Development Tools
T1566
Phishing
T1566.002
Spearphishing Link
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.006
Python
T1204
User Execution
T1204.002
Malicious File
TA0003
Persistence
1 technique
T1078
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078
Valid Accounts
TA0005
Stealth
3 techniques
T1027
Obfuscated Files or Information
T1070
Indicator Removal
T1070.001
Clear Windows Event Logs
T1070.004
File Deletion
T1078
Valid Accounts
TA0006
Credential Access
1 technique
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
TA0007
Discovery
3 techniques
T1082
System Information Discovery
T1135
Network Share Discovery
T1518
Software Discovery
TA0011
Command and Control
1 technique
T1105
Ingress Tool Transfer
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
T1567.001
Exfiltration to Code Repository
TA0040
Impact
1 technique
T1486
Data Encrypted for Impact
IOCS

Observables

34 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

sentinelone labsNews
Jan 14, 2026
LABScon25 Replay | Hacktivism and War: A Clarifying Discussion | SentinelOne

Referenced as an example within a discussion of hacktivism tiers and the concept of state-sponsored proxy operations masquerading as grassroots activism.

Read more
the hacker newsNews
Nov 11, 2025
CISO's Expert Guide To AI Supply Chain Attacks

NullBulge is known for conducting sophisticated supply chain attacks by weaponizing open-source repositories, particularly targeting AI tools and gaming software. Their operations include exfiltrating data and deploying ransomware through compromised code in popular platforms.

Read more
sentinelone labsNews
Apr 11, 2025
NullBulge | Threat Actor Masquerades as Hacktivist Group Rebelling Against AI | SentinelOne

Cybercriminal group targeting AI-centric application and gaming communities through software supply-chain poisoning, trojanized GitHub and Hugging Face repositories, malicious BeamNG mods, credential theft, data exfiltration, and later-stage LockBit ransomware deployment. The group also operated leak sites and claimed responsibility for Disney-related data theft and leaks.

Read more
outpost24 blogNews
Aug 20, 2024
Threat Context monthly: Executive intelligence briefing for August 2024

NullBulge is a hacktivist group known for targeting AI-centric applications and gaming platforms, using sophisticated malware for data theft and extortion. They leverage software supply chain attacks via trusted platforms like GitHub and Hugging Face, and have claimed breaches of high-profile organizations such as Disney.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping20

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables34

Domains, IPs, and hashes tied to this actor, refreshed continuously.