The Com, short for The Community, is a decentralized, primarily English-speaking cybercriminal ecosystem composed largely of young actors and overlapping sub-networks rather than a single hierarchical organization. It is widely associated with financially motivated cybercrime, especially social-engineering-led intrusions, SIM swapping, credential theft, account takeover, data theft, and extortion. Security reporting and law-enforcement assessments consistently place multiple prominent crews and brands within or adjacent to this ecosystem, including Scattered Spider, and likely affiliates or overlapping actors tied to Pink and BlackFile. The network has also been discussed in connection with overlaps or loose associations involving Lapsus$ and ShinyHunters in some operations and personnel relationships. The Com is notable for its reliance on human-centric intrusion tradecraft. Commonly reported tactics include voice phishing, SMS phishing, impersonation of IT help desk or internal support staff, phishing against identity platforms such as Okta and Microsoft 365, MFA interception or relay, passkey-enrollment abuse, SIM swapping, and rapid post-compromise data exfiltration from cloud and SaaS platforms such as SharePoint, OneDrive, Salesforce, and similar enterprise services. Actors linked to this ecosystem frequently exploit legitimate administrative workflows and trusted communications channels, then use compromised accounts for internal messaging, extortion, and further social engineering. The ecosystem is loosely structured and adaptive, with participants often operating under changing brands, temporary crews, or rebrands after arrests or disruption. Researchers and investigators have described substantial overlap among members, infrastructure, and tradecraft across multiple extortion and intrusion clusters. Rather than maintaining stable organizational boundaries, participants appear to move fluidly between subgroups and criminal specialties depending on opportunity, reputation, and access. Law-enforcement and intelligence reporting also describe The Com as extending beyond cyber-enabled fraud and extortion into broader criminality. The FBI has characterized it as an international online ecosystem with interconnected subsets, including Hacker Com, Extortion Com, and IRL Com. IRL Com in particular has been associated with violence-as-a-service, swatting, doxing, intimidation, assault, kidnapping, arson, and other real-world coercive acts. Broader reporting has further linked parts of the ecosystem to sextortion, exploitation of minors, and child sexual abuse material production and trafficking. Analysts have emphasized that the boundaries between cybercrime, extortion, harassment, and offline violence within this milieu are often blurred. The Com is not a nation-state actor. It is best understood as a fragmented criminal social network whose members coordinate across platforms such as Telegram, Discord, and gaming communities, with reputation, status, and profit serving as major drivers. Its significance lies in the convergence of advanced social engineering, cloud-focused enterprise intrusion, extortion, and, in some subsets, real-world violence, making it one of the more consequential English-speaking cybercriminal ecosystems currently tracked.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A broader cybercriminal collective referenced as the parent milieu or umbrella under which Scattered Spider is described as a subset.
Referenced as the broader criminal network to which Pink/O-UNC-066 is linked.
A decentralised online extremist community where actors move fluidly between extremist narratives, misogyny, nihilism, criminality and terrorist propaganda, with violence used for status, visibility and social capital.
A decentralized cybercriminal network described as likely affiliated with Pink in this campaign.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.