Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory

Crimson Collective

Also known asCrimson Collective

Crimson Collective is an emerging cyber extortion group first reported as emerging in September 2025. The group is described as a criminal/extortion actor, not a nation-state actor. It has been linked to data theft and extortion operations against enterprise and telecommunications targets, including Red Hat Consulting, Nissan Fukuoka Sales Co., Ltd. via the Red Hat incident, and Brightspeed. Reported aliases in the provided content are limited to "crimson_collective" / "Crimson Collective." The content also states the group has been associated with adjacent clusters CryptoChameleon and Crimson Collective, and that it announced collaboration with the ShinyHunters-linked Scattered Lapsus$ Hunters collective in extortion activity. The group’s publicly reported tradecraft centers on credential abuse and cloud-native tooling rather than custom malware. In a Cisco Talos engagement attributed to Crimson Collective, the intrusion began after a GitHub Personal Access Token was accidentally exposed on a public-facing website for several months. The actor used TruffleHog to scan GitHub repositories for secrets, leveraged discovered client secrets to access Azure cloud storage, and used Microsoft Graph API calls to authenticate, enumerate, and exfiltrate data. Talos also reported the actor attempted to inject malicious code into multiple GitHub repositories to harvest secrets committed in the future. Separate reporting in the provided content says Crimson Collective has targeted AWS environments, exploiting exposed credentials, creating privileged users, attaching AdministratorAccess policies, enumerating resources via AWS APIs, and exfiltrating data using snapshots, S3, and GetObject operations. Extortion was conducted through public claims and Telegram posts, including auctioning or offering stolen datasets for sale and threatening public release. A major reported operation involved Red Hat Consulting’s self-managed GitLab environment. Crimson Collective claimed it copied about 570 GB of compressed data from Red Hat private repositories and attempted to extort Red Hat. Reporting states the breach affected Nissan Fukuoka Sales Co., Ltd., exposing personal data of about 21,000 customers, including names, addresses, phone numbers, partial email addresses, and sales-related information; no credit card data was reported stolen. The content also states Crimson Collective claimed to have stolen customer engagement reports for Red Hat Consulting clients. The group also claimed a breach of U.S. fiber broadband provider Brightspeed, alleging theft of data on over 1 million customers. According to the provided reporting, the claimed data included names, billing and service addresses, email addresses, phone numbers, account status, payment history, payment methods, service records, order records, session IDs, user IDs, and the last four digits of payment cards. The group advertised the dataset for sale for three bitcoin, posted samples on Telegram, and threatened to dump the data if unsold. Some reports also note unverified claims that the group could disconnect users from service. Overall, the content characterizes Crimson Collective as a new extortion crew focused on stealing data from cloud and code-repository environments, abusing exposed credentials and legitimate cloud services/APIs, exfiltrating sensitive data, and using public extortion pressure via Telegram and leak-style disclosures.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Software & Services
MITRE ATT&CK

Tradecraft

22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics27 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589×2
Gather Victim Identity Information
T1593
Search Open Websites/Domains
TA0042
Resource Development
1 technique
T1585
Establish Accounts
T1585.001
Social Media Accounts
TA0001
Initial Access
2 techniques
T1078×2
Valid Accounts
T1195
Supply Chain Compromise
T1195.001
Compromise Software Dependencies and Development Tools
TA0003
Persistence
1 technique
T1078×2
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078×2
Valid Accounts
TA0005
Stealth
1 technique
T1078×2
Valid Accounts
TA0006
Credential Access
1 technique
T1649
Steal or Forge Authentication Certificates
TA0007
Discovery
4 techniques
T1087
Account Discovery
T1087.003
Email Account
T1526×2
Cloud Service Discovery
T1580
Cloud Infrastructure Discovery
T1654
Log Enumeration
TA0009
Collection
2 techniques
T1213
Data from Information Repositories
T1530
Data from Cloud Storage
TA0011
Command and Control
1 technique
T1102
Web Service
TA0010
Exfiltration
3 techniques
T1020×4
Automated Exfiltration
T1041×3
Exfiltration Over C2 Channel
T1567×3
Exfiltration Over Web Service
T1567.002×2
Exfiltration to Cloud Storage
TA0040
Impact
4 techniques
T1486×3
Data Encrypted for Impact
T1499
Endpoint Denial of Service
T1565
Data Manipulation
T1657×4
Financial Theft
IOCS

Observables

4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping22

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables4

Domains, IPs, and hashes tied to this actor, refreshed continuously.

Crimson Collective | Mallory