International Pentest Company is a fraudulent front organization used in a cyber-enabled social engineering and phishing operation. It posed as a legitimate penetration testing company and advertised roles such as translators, copywriters, and communications specialists in order to recruit unwitting individuals who would help produce convincing phishing content. Reported targeting for recruitment focused particularly on individuals in Ukraine and Russia. The operation illustrates the use of deceptive employment schemes to support large-scale phishing activity by outsourcing or crowdsourcing lure development through a fake corporate identity. Based on the available information, the entity is best characterized as an operational cover or front used to facilitate phishing and related initial-access activity rather than as a fully attributed standalone threat actor with a well-established intrusion history. No high-confidence attribution to a specific state, criminal group, or broader cluster is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.