dk0m is an underground cybercriminal data broker active since at least 2024 that has advertised government-related datasets for sale on criminal forums. The actor has been linked to the sale of alleged government and judicial data associated with Armenia and Ukraine, and has also been reported to have advertised data tied to ministries in Argentina and Brazil. Reported activity indicates a focus on monetizing unauthorized access to sensitive state-related information rather than disruptive operations. The actor has been assessed as using information-stealing malware to harvest saved credentials and session cookies from compromised devices, then leveraging that access to identify reachable government portals and obtain data for repackaging and resale. This behavior supports capabilities in credential theft, session hijacking, initial access, reconnaissance, and exfiltration, followed by post-compromise monetization through underground marketplace sales. dk0m has also reportedly shared sample data or database structures to increase the credibility of sale offers. Known activity includes advertising a large dataset allegedly sourced from an Armenian government notification or civil litigation-related platform, including police and judiciary communications, and offering confidential Ukrainian justice and court-related data for sale. The actor is best characterized as a financially motivated cybercriminal broker specializing in stolen government-related data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Advertised the sale of a large dataset (~8 million) of allegedly stolen Armenian government records, reportedly using information-stealing malware to validate/obtain access to government portals and then repackaging and reselling the data; activity increases downstream social-engineering/scam risk using real case numbers/fines/enforcement details.
Underground forum data broker offering for sale an alleged trove of ~8 million Armenian government-related notification/civil litigation records; reportedly uses infostealer malware to harvest credentials/session cookies, identify access to government portals, and resell obtained datasets. Previously advertised government-related data tied to ministries in Argentina, Ukraine, and Brazil.
dk0m is an underground forum actor selling access to Ukrainian confidential data, including justice and court data, and access to a Ukrainian court account.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.