In Real Life (IRL) Com is a subset of the broader online criminal ecosystem known as The Com, a primarily English-speaking, international network associated with cybercrime, extortion, exploitation of minors, and real-world violence. IRL Com is most widely associated with violence-as-a-service activity and has been publicly linked to solicitations for shootings, kidnappings, armed robbery, stabbings, physical assault, bricking, and swatting-for-hire. The group has been described as a growing threat to youth, both because minors are targeted for recruitment and because younger participants are present within the wider ecosystem. IRL Com reportedly emerged from SIM-swapping circles and evolved from violence tied to online disputes into a more explicit market for contracted real-world attacks. Members and subgroups are assessed to organize around shared interests, ideology, or operational goals, and may splinter or recombine as needed. Within the wider Com environment, recruitment and grooming commonly occur through social media, gaming platforms, and messaging applications, with status often tied to increasingly extreme conduct, coercion, or production of abusive material. The broader Com ecosystem overlaps cyber-enabled and physical crime. Associated activity includes swatting, sextortion, doxxing, ransomware, distributed denial-of-service attacks, phishing, malware deployment, cryptocurrency theft, money laundering, and SIM swapping. IRL Com represents the physical-violence end of that spectrum, illustrating how online criminal communities can transition from harassment and fraud into organized offline attacks. Reporting has also noted overlap between The Com and other criminal milieus, including extortion-focused and intrusion-focused subsets such as Hacker Com, as well as associations in some reporting with actors such as Scattered Spider and LAPSUS$-linked networks, though IRL Com itself is specifically distinguished by violence-as-a-service and swatting-related operations. Known aliases include in_real_life_com and in_real_life (irl) com.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A subset of The Com associated with swat-for-hire and violence-as-a-service activity, including recruitment of children and teens for real-world violent crimes.
Subset of The Com highlighted by the FBI as an increasing threat to youth; associated with cybercrime ecosystems that can extend into real-world harm/violence recruitment dynamics (as referenced in the broader article context).
IRL Com is an online collective offering violence-as-a-service, swatting, DDoS, ransomware, and extortion, recruiting minors for a range of criminal activities.
Violent subset of The Com that emerged from the SIM-swapping community; includes subgroups offering 'violence as a service' (VaaS) with paid contracts for real-world violence and coercion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.