Fly is a threat actor linked to Russian Market infrastructure. Multiple cited sources state that Fly is likely the administrator of Russian Market, an underground marketplace for selling credentials stolen via infostealers. Intrinsec reported that Fly was the first user to publicly promote the marketplace via the username "FLYDED," which was also described as a previous name of Russian Market. The available content further states that Fly’s online presence has been linked to Russian Market infrastructure and to bitcoin flows to non-KYC exchanges and mixing services. No additional high-confidence information about specific victim sectors, malware operated directly by Fly, or distinct sub-groups is provided in the content. Known alias mentioned in the content: FLYDED.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Fly is the administrator of Russian Market, a cybercriminal marketplace for selling credentials stolen via infostealers. The actor is involved in promoting and managing the marketplace.
Individual threat actor persona linked to the Russian Market cybercrime marketplace; associated with promotion/operation signals and with wallet infrastructure tied to non-KYC exchanges and mixing services.
Fly is a threat actor associated with the administration of Russian Market, a marketplace for credentials stolen via infostealers.
A threat actor named Fly is discussed in the context of having links to Russian Market’s infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.