b1ack is a cybercriminal actor associated with the administration of the carding marketplace known as B1ack’s Stash. The actor is involved in the underground trade of stolen payment card data and related financial fraud services, and has also been linked to phishing activity and Malware-as-a-Service offerings. This places b1ack within the broader financially motivated cybercrime ecosystem that spans carding, credential-focused fraud enablement, and criminal service provision. The actor’s known activity centers on operating or promoting a marketplace for illicit payment-card data, indicating involvement in monetization of stolen financial information and support for downstream fraud. Reported phishing activity further suggests capability or participation in initial access and credential acquisition workflows, while Malware-as-a-Service involvement indicates a role in supplying or facilitating tooling for other cybercriminals. The available information supports assessment of b1ack as a financially motivated criminal actor rather than a state-sponsored intrusion set. Known alias: b1ack.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.