Inferno Drainer is a cryptocurrency-draining operation described as a drainer-as-a-service offering used to steal digital assets from large numbers of cryptocurrency wallets. Public reporting has associated it with theft from more than 30,000 wallets and losses of roughly $9 million. The operation is known primarily for crypto-theft activity and appears to function as a service-based criminal ecosystem rather than a state-sponsored intrusion set. High-confidence public details in this context are limited; beyond its role in wallet theft and its branding as a drainer service, specific targeting patterns, infrastructure, sub-groups, and broader intrusion tradecraft are not sufficiently established here.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.