Lionishackers is a financially motivated cybercriminal actor focused on stealing and monetizing corporate databases. Active since at least July 2024, the group is known for exfiltrating data from organizations and reselling the stolen databases through Telegram channels and underground forums. Reporting links the actor primarily to attacks against organizations in Asian markets. The group’s operations center on database compromise and resale rather than disruptive or destructive activity. Observed tradecraft includes SQL injection to gain access to exposed or vulnerable web-connected databases, followed by data exfiltration and commercialization of the stolen information. Lionishackers has also been associated with DDoS activity in support of its operations. The actor has been described as collaborating with Hunt3r Kill3rs. Lionishackers fits the broader trend of professionalized cybercrime in which access, stolen data, and downstream monetization are treated as scalable business lines. Its dominant objective is financial gain through the theft and sale of corporate information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated threat actor targeting corporate databases in Asia for exfiltration and resale, also involved in DDoS campaigns.
Exfiltrating and selling corporate databases, collaborating with other cybercrime groups, and offering additional services such as pen testing and botnet commercialization.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.