Legendary Rescator is a long-running cybercriminal actor in the carding underground, active since the early 2010s. The actor is known as the administrator of the Rescator carding marketplace, a criminal market focused on the sale of stolen payment card data and related financial information. The actor has been associated with the sale of millions of stolen cards and other financial data, making the name one of the more prominent identities in the card-fraud ecosystem. The actor’s activity is centered on financially motivated cybercrime, specifically the monetization of stolen payment data through underground market operations. Rescator functions as part of the broader carding ecosystem in which stolen cards, dumps, and victim financial data are traded, often alongside tooling and services that support payment fraud. As an administrator of such a marketplace, Legendary Rescator is linked to the criminal distribution and resale layer of card fraud rather than to a publicly documented ransomware or state-directed intrusion program. Available high-confidence reporting supports Legendary Rescator’s role in operating carding infrastructure and facilitating the sale of stolen financial data. There is insufficient direct support here for more specific intrusion tradecraft, victim geography, or sector targeting beyond the actor’s involvement in payment-card fraud markets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.