NullBulge is a cybercriminal threat group that emerged in the first half of 2024 and targets AI-focused applications, gaming communities, and related software supply chains. The actor presents itself as a pro-artist, anti-AI collective, but its operations include data theft, sale of stolen access and logs, and extortion activity consistent with a primarily financial motive. NullBulge is known for software supply chain compromise and malware distribution through public developer and community ecosystems, including code repositories and gaming-mod channels. Campaigns have involved weaponized repositories and trojanized dependencies in AI-related projects, as well as malicious modifications distributed to gaming and modeling communities. The group has been linked to abuse of the ComfyUI_LLMVISION extension and to malicious packages masquerading as AI libraries. Its Python-based tooling harvested browser data, system information, installed applications, security-product details, geographic information, and financial data, then exfiltrated the results through webhook-based collection infrastructure. The actor has also used malicious scripts in gaming mods to execute PowerShell and deploy commodity remote-access malware including AsyncRAT and Xworm, followed in some cases by customized LockBit ransomware built with the leaked LockBit Black builder. Reported ransomware functionality included local and network-share encryption, process and service termination, self-deletion, and event-log deletion. In parallel with malware deployment, NullBulge has operated leak infrastructure and underground personas used to publicize intrusions and monetize stolen data, including sales of infostealer logs and stolen API keys. NullBulge has been associated with high-profile claims involving theft and publication of Disney-related data, including internal Slack material and creative assets. The group is notable for blending hacktivist branding with cybercrime tradecraft, using public ideological messaging as cover for supply-chain intrusion, credential abuse, exfiltration, and extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example within a discussion of hacktivism tiers and the concept of state-sponsored proxy operations masquerading as grassroots activism.
NullBulge is known for conducting sophisticated supply chain attacks by weaponizing open-source repositories, particularly targeting AI tools and gaming software. Their operations include exfiltrating data and deploying ransomware through compromised code in popular platforms.
Cybercriminal group targeting AI-centric application and gaming communities through software supply-chain poisoning, trojanized GitHub and Hugging Face repositories, malicious BeamNG mods, credential theft, data exfiltration, and later-stage LockBit ransomware deployment. The group also operated leak sites and claimed responsibility for Disney-related data theft and leaks.
Mentioned as one of several threat actors known to use VenomRAT and AsyncRAT.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.