Karma Fullz is a Russian-speaking cybercriminal fraud group operating a darknet and Telegram-based marketplace focused on synthetic and stolen identity-enabled financial fraud. The group is known for packaging identities of former U.S. visa holders into high-value fraud products that include personally identifying data, financial-history elements, and supporting artifacts designed to make the identities appear legitimate to lenders and service providers. Its offerings have included enhanced identity packages supported by credit-bureau account setup, aged communications accounts, and public-record registration to improve acceptance in downstream fraud workflows. The group’s activity supports a range of financially motivated fraud schemes, including fraudulent bank-account opening, credit-card applications, tax-refund fraud, and abuse of public-benefit systems in the United States. Its tradecraft centers on enabling initial access to financial services through convincing synthetic or reactivated identities rather than network intrusion. Karma Fullz functions as a criminal service provider within the broader fraud ecosystem, supplying identity material and associated enablement to downstream fraudsters. Available reporting supports characterization of the actor as a financially motivated Russian-speaking criminal operation rather than a state-linked espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.