Karma Fullz is a Russian-speaking cybercriminal fraud group operating a darknet and Telegram-based marketplace focused on synthetic and stolen identity-enabled financial fraud. The group is known for packaging identities of former U.S. visa holders into high-value fraud products that include personally identifying data, financial-history elements, and supporting artifacts designed to make the identities appear legitimate to lenders and service providers. Its offerings have included enhanced identity packages supported by credit-bureau account setup, aged communications accounts, and public-record registration to improve acceptance in downstream fraud workflows. The group’s activity supports a range of financially motivated fraud schemes, including fraudulent bank-account opening, credit-card applications, tax-refund fraud, and abuse of public-benefit systems in the United States. Its tradecraft centers on enabling initial access to financial services through convincing synthetic or reactivated identities rather than network intrusion. Karma Fullz functions as a criminal service provider within the broader fraud ecosystem, supplying identity material and associated enablement to downstream fraudsters. Available reporting supports characterization of the actor as a financially motivated Russian-speaking criminal operation rather than a state-linked espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.