764 is a nihilistic violent extremist online network and a prominent offshoot within the broader Com ecosystem. Active since at least 2021, it is associated with the grooming, coercion, and extortion of minors and other vulnerable people into producing child sexual abuse material, self-harm content, animal abuse content, and other violent or degrading material. Authorities and researchers describe the group as youth-heavy, decentralized, and transnational, with members and victims spanning multiple countries and with numerous copycat or splinter communities. The group has been linked to coordinated online abuse campaigns involving sextortion, blackmail, cyberstalking, doxing, swatting, harassment, and coercive control. Victims are pressured through threats, humiliation, and the collection of compromising material, which is then used to maintain compliance, force further abuse, or compel victims to recruit and exploit others. Reporting also ties 764 to blood-sign and self-mutilation rituals used for intimidation, status, and control within adjacent Com communities. 764 has been characterized by U.S. authorities as a nihilistic violent extremist network pursuing social collapse through corruption and exploitation of vulnerable populations, often minors. Some cases and charging documents describe accelerationist, neo-Nazi, or racially motivated violent extremist elements among members or affiliated subgroups, but the broader ecosystem is more consistently defined by nihilism, sadism, misanthropy, and status-seeking than by a single coherent ideology. Known subgroups and offshoots include 764 Inferno, 8884, and 7997. Public prosecutions have identified alleged leaders and members including Bradley Chance Cadenhead, Leonidas Varagiannis, Prasan Nepal, Alexis Aldair Chavez, Tony Christopher Long, Erik Lee Madison, Aaron Corey, Baron Cain Martin, and Kalana Limkin. The group is widely discussed alongside The Com and its related branches such as Hacker Com, IRL Com, and Extortion Com because of overlap in membership, tactics, and criminal social networks. Although 764 is primarily known for child exploitation and coercive abuse rather than enterprise intrusion operations, law enforcement reporting states that the network and its surrounding ecosystem use cybercriminal tactics to carry out crimes, and broader Com-linked activity overlaps with extortion, credential theft, ransomware, service disruption, and other financially motivated offenses. The dominant, high-confidence profile of 764 itself is a violent online exploitation network centered on coercion, abuse, and extremist harm against minors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A notorious community associated with The Com threat landscape, accused of aggressively recruiting and grooming young people into producing explicit content and committing harmful acts for sharing or blackmail.
Named online sadistic COM network referenced in connection with coercive abuse activity; the content discusses a suspect allegedly acting as a member of 764.
A named subgroup within The Com, notorious for grooming young people into producing explicit content later used for blackmail or shared among members.
A violent online network accused of exploiting vulnerable populations, especially minors, with accelerationist goals aimed at social unrest and the downfall of the current world order, including the U.S. government.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.