Desorden, also referred to as Desorden Group, is a financially motivated data-extortion threat actor known for intrusions against organizations in Southeast Asia and elsewhere, with a particular emphasis on stealing large volumes of sensitive data and monetizing it through extortion and sale on cybercrime forums. The group has publicly claimed links to or a split from Chaos/ChaosCC, but only the self-asserted association is established here. Desorden has been associated with compromises of logistics, hospitality, restaurant, retail, and supply-chain-related organizations, including victims in Malaysia, Thailand, and Italy. Reported victimology includes ABX Express Enterprise in Malaysia, Centara Hotel Group, Central Restaurant Group, and Mistine Better Way Thailand, as well as claimed interest in supply-chain networks and public services. Operationally, Desorden is characterized by unauthorized access to internet-facing systems, movement from exposed servers into internal environments, persistence within victim networks, large-scale data theft, and subsequent extortion. In reported incidents, the actor claimed to have maintained persistent access, stolen databases, financial and corporate records, source code, and customer information, and then pressured victims by leaving notes and advertising stolen data to buyers when payment was not made. The group has also claimed destructive actions such as wiping drives in at least one intrusion, but its core pattern is data theft followed by extortion rather than ransomware encryption. Desorden’s tradecraft, as reflected in attributed incidents, includes initial compromise via front-facing infrastructure, persistence in compromised servers, post-exploitation within intranet environments, and exfiltration of high-value business and personal data. The actor has repeatedly used public leak and sale channels to increase pressure on victims, including releasing samples and offering datasets for sale. This places Desorden among extortion-focused intrusion actors that rely on theft and exposure of data as the primary coercive mechanism.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting data breach and extortion-style operations against Thai organizations, including hospitality, restaurants, and retail-related businesses, and posting stolen data samples for free on hacking forums.
Data theft and extortion operations targeting supply chain networks and public services, including exfiltration of customer and corporate data, wiping drives, leaving breach notes, and selling stolen data if victims do not pay.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.