Full-stack illicit infrastructure providers are criminal service providers that supply technical infrastructure used to enable malicious cyber and cyber-enabled financial crime. Their offerings include services such as domain registration, bulletproof hosting, and related infrastructure that supports both nation-state operations and conventional cybercriminal activity. These providers function as upstream enablers rather than a single cohesive intrusion set, supplying resilient infrastructure used by ransomware operators, malware distributors, scammers, illicit marketplaces, and child sexual abuse material platforms. Their role in the threat ecosystem is to facilitate operational security, service continuity, and abuse-resistant hosting for downstream actors. By providing infrastructure that is difficult to disrupt, they support multiple phases of malicious operations, including initial access enablement, persistence of attacker-controlled services, defense evasion through resilient hosting arrangements, and post-exploitation support for data handling or criminal service delivery. Their emergence reflects the broader professionalization and diversification of cybercriminal and sanctions-evasion ecosystems, including increasing overlap between financially motivated cybercrime and state-linked illicit activity. These providers are associated with illicit on-chain ecosystems because they visibly participate in cryptocurrency-based payment flows and service relationships. They have been identified as supporting a wide range of abuse categories, including ransomware, malware distribution, scams, and illicit online marketplaces. Available information supports classifying them primarily as financially motivated criminal enablers rather than a distinct nation-state threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.