ViLE is a cybercriminal doxing and extortion group known for acquiring victims’ personal information and using it to harass, threaten, blackmail, and publicly expose targets. The group operated a public doxing site where sensitive personal data could be posted, and victims were pressured to pay to prevent publication or to have their information removed. U.S. law enforcement actions tied ViLE members to unauthorized access to a nonpublic federal law enforcement portal containing intelligence and seizure records, which was used to enrich victim dossiers and support extortion. Reported ViLE tradecraft also includes social engineering of customer service personnel, fraudulent emergency or legal-style data requests, impersonation of law enforcement, use of compromised credentials, insider-enabled data acquisition, and abuse of public and private databases. Known members and aliases include Sagar Steven Singh ("Weep") and Nicholas Ceraolo ("Convict," "Anon," and "Ominous"). ViLE has also been discussed in connection with the broader English-speaking online criminal ecosystem often referred to as “The Com,” where doxing, harassment, stalking, SIM-swapping, swatting, and related extortionate abuse overlap. ViLE’s activity is best characterized as financially motivated cyber-enabled extortion centered on stolen personal data rather than ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ViLE is a hacking group involved in identity theft, computer intrusion, and extortion using stolen law enforcement credentials.
Criminal doxxing/extortion activity leveraging stolen law-enforcement portal credentials to access nonpublic police records and extort victims.
Cybercriminal doxing/extortion group that breached a U.S. federal law enforcement (DEA) portal, stole victim data, impersonated law enforcement, and used threats to extort payments.
Intrusion group focused on compromising law-enforcement portals to steal data for doxxing/harassment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.