Skip to main content
Mallory
2 malware families

The Com

Also known asthe_comthe_community

The Com, short for “The Community,” is a loosely knit, primarily English-speaking cybercriminal ecosystem composed of interconnected networks of hackers, SIM swappers, extortionists, and violent criminal subsets. Reporting describes it as international but predominantly North American, with many members being minors or young adults, often roughly 11 to 25 years old. Known aliases include the_com and the_community. The Com is repeatedly described as the broader community from which groups such as Scattered Spider emerged, and reporting also links or associates activity by Lapsus$, ShinyHunters, BlackFile, and Pink to this ecosystem to varying degrees. Europol and the FBI describe The Com as splintered into three primary subsets: Hacker Com, In Real Life (IRL) Com, and Extortion Com. Hacker Com is associated with corporate intrusions and cybercrime including social engineering, phishing, vishing, credential theft, MFA bypass, SIM swapping, DDoS, ransomware, data theft, and extortion. Multiple reports state that actors tied to The Com commonly impersonate IT or help-desk staff, use Okta-themed phishing pages, target SSO environments, and abuse cloud and SaaS platforms including Okta, Salesforce, Microsoft 365, SharePoint, and OneDrive. The ecosystem is also described as using Telegram, Discord, hacker forums, social media, gaming communities, and messaging apps for coordination, recruitment, and bragging. IRL Com is described by the FBI as having evolved from the SIM-swapping community into a violence-as-a-service market. Reported IRL Com activities include shootings, kidnappings, armed robbery, stabbings, physical assault, bricking, swatting-for-hire, doxing, and intimidation. The FBI and other reporting state that The Com has at times resorted to violent tactics including throwing bricks through windows, arson, kidnapping, and shootings. Extortion Com is described in reporting as using sextortion, manipulation, and coercion, including recruitment and indoctrination of members through exploitation. Multiple sources cited in the content state that parts of The Com are linked to grooming, sextortion of minors, and production or trafficking of child sexual abuse material. Europol further characterizes The Com as a decentralized extremist network that recruits, radicalizes, and exploits young people, including via social media, messaging apps, gaming platforms, and music streaming platforms. The ecosystem is decentralized and overlapping rather than siloed: the FBI states members often participate across more than one subset simultaneously and maintain relationships across subsets when useful. Reporting also states that some members work under multiple banners at the same time, and that overlap among Scattered Spider, Lapsus$, ShinyHunters, and related “Scattered Lapsus$ Hunters” branding has caused attribution confusion. Law-enforcement and industry reporting indicate sustained attention on The Com. Europol’s Project Compass, launched in January 2025, described The Com as an extremist network and reported 30 arrests and 179 fully or partially identified members. The FBI has issued public warnings on both The Com broadly and IRL Com specifically.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics21 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1598
Phishing for Information
T1598.004×3
Spearphishing Voice
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.006
Web Services
TA0001
Initial Access
3 techniques
T1078×3
Valid Accounts
T1133
External Remote Services
T1566×2
Phishing
T1566.002
Spearphishing Link
T1566.004×4
Spearphishing Voice
TA0003
Persistence
2 techniques
T1078×3
Valid Accounts
T1133
External Remote Services
TA0004
Privilege Escalation
1 technique
T1078×3
Valid Accounts
TA0005
Stealth
1 technique
T1078×3
Valid Accounts
TA0006
Credential Access
1 technique
T1649×2
Steal or Forge Authentication Certificates
TA0009
Collection
1 technique
T1213
Data from Information Repositories
TA0011
Command and Control
1 technique
T1090
Proxy
T1090.002
External Proxy
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
TA0040
Impact
2 techniques
T1498
Network Denial of Service
T1657
Financial Theft
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping14

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

The Com | Mallory