r1z is the online moniker of Feras Khalil Ahmad Albashiti, a Jordanian cybercrime actor identified as a prolific initial access broker. He sold unauthorized access to enterprise networks, remote access footholds, stolen VPN access, and offensive tooling to other criminals through underground forums including the Russian-language XSS forum. Court proceedings established that he sold access to at least 50 victim companies and was later extradited to the United States, where he pleaded guilty to fraud-related charges tied to those sales. r1z operated as a supplier within the broader cybercrime and ransomware ecosystem rather than primarily as a public-facing ransomware brand. His offerings included access obtained through exploitation of internet-facing enterprise technologies and security appliances, including Confluence and Microsoft Exchange, as well as firewall and VPN weaknesses. Reporting tied him to sales of access with remote code execution privileges and to large-scale identification of vulnerable systems. He was also observed advertising cracked offensive security software and malware designed to disable endpoint protection products. The actor’s tooling and tradecraft indicate capabilities beyond simple brokerage. Malware attributed to r1z was described as able to disable multiple EDR products and to function as a persistent backdoor, credential harvester, malware dropper, and event-log remover. Investigators also documented sales of an EDR-bypass or “EDR killer” capability and purchases by an undercover law-enforcement operator that enabled direct observation of his methods. Authorities further linked infrastructure associated with r1z to a major ransomware incident affecting a U.S. manufacturing company, indicating that his access brokerage activity materially supported downstream ransomware operations. Known activity associated with r1z spans multiple underground communities and shows repeated sales of compromised corporate access across the United States, Europe, Mexico, and other regions. Public reporting also associates the persona with aliases and identifiers reused across platforms, including OrientalSecurity, j0rd4n14n, bashiti, j0, f1r4s, and Eddy_BAck0o. The dominant pattern is financially motivated cybercrime centered on obtaining, maintaining, and monetizing enterprise access for other threat actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access broker operating on multiple cybercrime forums, selling stolen VPN credentials and remote access into enterprise networks (often with RCE-level control), plus tooling (including an EDR-killer and cracked Cobalt Strike) to enable follow-on intrusions and support the ransomware supply chain.
Access broker activity: selling unauthorized access to dozens of victim company networks for cryptocurrency; advertising and potentially using exploits for Microsoft Exchange and Atlassian Confluence; offering EDR-bypass exploit and tooling, and promoting malware with backdoor/credential theft/dropper/log removal capabilities. Activity is linked (via IP evidence) to at least one ransomware incident against a US manufacturing company.
Initial Access Broker (IAB) selling compromised enterprise network access (including RCE-level access) and tooling/malware to other criminals; advertised an EDR-killer and discussed/trafficked cracked Cobalt Strike; activity spanned multiple underground forums and Telegram/TOX for communications; linked by investigators to a major ransomware attack via infrastructure and undercover purchases.
Initial access broker activity: selling illicit network access to dozens of victim companies via firewall exploits; advertising/abusing exploits for enterprise products (e.g., Confluence RCE) and selling cracked/illicit tooling (e.g., Cobalt Strike). Also offered an 'EDR killer' malware capable of disabling multiple EDR products; linked by IP to a June 2023 ransomware incident against a US manufacturing firm.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.