Check Point is a cybersecurity research and security vendor entity referenced as identifying and reporting on cybercriminal insider-recruitment trends. In the provided content, Check Point researchers reported that cybercriminals, including ransomware groups and access brokers, recruit insiders in banking, telecommunications, technology, and government-related organizations via Russian-language darknet forums and Telegram channels. Reported activity includes offers of $3,000 to $15,000 for access or sensitive information, with telecom cooperation specifically reaching $10,000 to $15,000. The content attributes to Check Point the identification of tactics such as soliciting employees to disable endpoint protection, provide VPN credentials, install remote access tools, exfiltrate databases, and facilitate SIM-swapping. No aliases, sub-groups, or nation-state attribution for Check Point are provided in the content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.