Miyako is a cybercriminal initial access broker (IAB) associated with the access-sales layer of the HellCat ecosystem. The actor has been observed advertising and brokering footholds into victim environments rather than primarily monetizing stolen data directly, and has explicitly positioned their role as selling access. Activity attributed to this persona spans multiple underground forums and Telegram channels over a sustained period, with linked aliases including miyak0, MIYAK000, nastya-miyako, and miya, as well as evidence of channel rebranding tied to the same operational infrastructure. Miyako has advertised access types including remote code execution, shell access, administrative or CLI-level control, firewall access, and VPN entry points. Reported offerings have repeatedly emphasized privileged access to perimeter infrastructure, especially Linux-based firewall devices and FortiOS environments, creating a strong foothold for downstream intrusion activity. Observed listings and related reporting indicate the actor has offered access affecting organizations in government, energy, telecommunications, manufacturing, logistics, healthcare-related retail, financial institutions, and defense-adjacent environments. Some reporting also links the persona to access involving Chinese financial institutions and to listings referencing U.S. government and aerospace or defense targets. The actor’s tradecraft is consistent with early-stage intrusion enablement for other operators. Advertised capabilities and observed behavior indicate initial compromise and brokering of privileged network access that could support later ransomware deployment, data theft, lateral movement, and broader post-compromise operations by buyers. Miyako has been linked to on-demand access acquisition services in which prospective buyers submit targets for compromise, further reinforcing the assessment that the actor operates as a service-oriented access supplier within a broader criminal ecosystem. Miyako has been described as having possible ties to East Asian cybercriminal forums and potentially state-linked interests, but those links are not established at a level sufficient to attribute the actor to a nation state. The dominant, well-supported characterization is that Miyako is a persistent financially motivated initial access broker supporting other intrusion actors, including ransomware ecosystems, through the sale of privileged footholds.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An initial access broker advertising unverified root RCE and shell access to firewall appliances at five unnamed organizations across the UAE, USA, South Korea, and Saudi Arabia. The access is positioned as a potential foothold for ransomware or data theft buyers.
Initial Access Broker operating within the HellCat ecosystem, advertising and supplying access to victim environments across forums and Telegram, including on-demand access acquisition and sales of footholds such as RCE, administrative, firewall, and VPN access.
An initial access broker selling administrator-level access credentials for Chinese financial institutions' firewall and network administrator panels on BreachForums.
Initial Access Broker advertising alleged privileged/root access (RCE, shell, admin panel) to a Linux-based firewall associated with an Indonesian government land authority.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.