Crimson Collective is a financially motivated cyber-extortion group that emerged in September 2025. It conducts data-theft extortion rather than deploying ransomware encryption, publicly claiming intrusions and threatening to sell or release stolen data to pressure victims. The group has targeted cloud and source-code repository environments, abusing exposed credentials and access tokens to access cloud services, enumerate repositories and resources, identify embedded secrets, escalate privileges, and exfiltrate data. It has used cloud-native administrative functions and Microsoft Graph API activity to collect data, and has attempted to implant malicious code in repositories to harvest secrets committed later. Crimson Collective claimed responsibility for the compromise of a Red Hat Consulting-managed GitLab environment. Red Hat confirmed that an unauthorized party accessed and copied data from that dedicated instance. The incident affected Nissan Fukuoka Sales customers in Japan, whose personal and sales-related information was exposed through the Red Hat breach. The group has also claimed responsibility for stealing data from Brightspeed, a U.S. fiber-broadband provider; Brightspeed confirmed that it was investigating the reported incident but had not publicly verified the group’s claims. Crimson Collective has publicly associated itself with the ShinyHunters-linked Scattered Lapsus$ Hunters collective in extortion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Com-associated group reported as compromising source-code or DevOps repositories and conducting data extortion without encryption.
Compromised Red Hat Consulting’s GitLab instance and obtained customer credentials and secrets committed to the repository.
Cyber extortion activity involving compromise via an exposed GitHub Personal Access Token, use of TruffleHog to scan repositories for secrets, access to Azure cloud storage through discovered client secrets, Microsoft Graph API-based authentication/enumeration/data exfiltration, and attempted malicious code injection into GitHub repositories to harvest future secrets.
Data-theft/extortion group using Telegram to announce breaches, post samples as proof, and threaten to release/sell large customer datasets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.