Anna's Archive is a pirate activist and shadow-library collective launched in 2022 and associated with a pseudonymous operator known as Anna or Anna Archivist. It is best known for indexing and facilitating access to copyrighted books, academic papers, and other media from shadow-library ecosystems, and later expanded its activity into large-scale music preservation and piracy operations. The group frames its mission as preserving knowledge and culture and has publicly justified its actions as archival preservation rather than conventional cybercrime. In 2025, Anna's Archive claimed responsibility for a large-scale scrape of Spotify, asserting that it collected metadata for roughly 256 million tracks and obtained approximately 86 million audio files, representing most of the platform's listening activity. The operation was described as using automated scraping at scale, abuse of platform accounts, and circumvention of digital rights management protections to access audio content. The group organized the resulting data into structured archives and distributed or planned to distribute it through BitTorrent as an open music preservation archive. Available reporting characterizes the Spotify operation as unlawful scraping and mass copyright infringement rather than a traditional network intrusion involving theft of passwords, payment data, or private user information. Spotify stated it identified and disabled accounts involved in the activity, implemented additional safeguards, and reported that no non-public user data was compromised aside from public playlist information. Subsequent legal action by Spotify and major record labels sought to halt distribution, and a preliminary injunction was reportedly issued in early 2026 after the group failed to appear or respond. Known aliases include Anna's Archive, anna's_archive, anna’s_archive, and anna's_archives. The actor is most accurately characterized as a hacktivist or pirate-preservation collective whose operations center on large-scale scraping, exfiltration of copyrighted content and metadata, and public redistribution in support of an ideological preservation agenda.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Accused of large-scale automated scraping/exfiltration of Spotify’s catalog (tracks, audio files, and metadata) via automated tools and use of multiple user accounts; activity framed as “archiving/preservation” by the group and as theft/copyright infringement by rights holders, resulting in a major lawsuit and injunction efforts.
Scraped and published large-scale Spotify track metadata and audio files by bypassing DRM, distributing the dataset via torrents as a purported “preservation archive.”
Data scraping and exfiltration of large-scale music metadata from Spotify, with a stated mission of digital preservation.
Data scraping and exfiltration of large-scale music metadata from Spotify, with a stated mission of digital preservation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.