764 is a nihilistic violent extremist online network and child-exploitation community active since at least 2021, widely described as an offshoot or subgroup within the broader Com ecosystem. The network is associated with the grooming, coercion, and blackmail of minors and other vulnerable people into producing child sexual abuse material, self-harm imagery, animal abuse content, and other violent or degrading acts. Authorities and researchers have also linked 764 to doxing, swatting, harassment, and coercive control techniques designed to maintain dominance over victims and expand recruitment. The group operates through decentralized online communities and affiliated splinter groups, including 764 Inferno, Harm Nation, 8884, and 7997. Known aliases and related labels in reporting place 764 within the wider Com landscape alongside sextortion-focused, offline violent, and cybercrime-oriented subgroups. U.S. authorities have characterized 764 as a nihilistic violent extremist network seeking social unrest through the corruption and exploitation of vulnerable populations, often minors. Some reporting also places parts of the 764 milieu within accelerationist and neo-Nazi extremist currents, though the ecosystem is more consistently defined by nihilism, sadism, and status-seeking through the production and circulation of harm than by a single coherent ideology. Its tradecraft centers on aggressive online recruitment, grooming, blackmail, and sustained psychological abuse. Members have coerced victims into creating explicit material later used for extortion or shared among members, and have pressured victims into self-mutilation, suicide-related acts, sibling abuse, animal torture, and other forms of recorded violence. The network has also been tied to harassment tactics such as doxing and swatting. Broader Com-linked reporting indicates overlap between sextortion communities and cybercriminal activity, but for 764 specifically the strongest corroborated pattern is child exploitation and violent coercion rather than enterprise-focused intrusion operations. Law-enforcement actions have identified multiple alleged leaders and members across the United States and Europe, including prosecutions tied to child sexual abuse material distribution, coercion, racketeering, and related offenses. Individuals publicly linked to 764 or its offshoots include Bradley Chance Cadenhead, Leonidas Varagiannis, Prasan Nepal, Kyle William Spitze, Alexis Aldair Chavez, Erik Lee Madison, Tony Christopher Long, Aaron Corey, and Baron Cain Martin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A nihilistic violent extremist network affiliated with The Com that exploits and coerces children and other vulnerable populations into producing CSAM, self-harm, mutilation, doxing- and swatting-backed abuse, and animal torture content to foster social unrest.
A subgroup of The Com known for grooming young people into producing explicit content that is then used for extortion or shared among members.
A sub-group of The Com focused on grooming young people to produce explicit content for extortion. The article notes two alleged leaders were arrested in April 2025.
A notorious community associated with The Com threat landscape, accused of aggressively recruiting and grooming young people into producing explicit content and committing harmful acts for sharing or blackmail.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.