Ares Leaks is an online criminal data-broker and espionage-as-a-service actor known for advertising and selling stolen data, including hacked corporate databases and sensitive government documents. The group has operated under the aliases Ares Leaks, aresleaks, and ares_leaks, and has used Telegram to market its access and offerings. Reporting links Ares Leaks to the sale or attempted sale of classified material stolen from Russia’s FSB, including internal counterintelligence documents that were assessed as apparently authentic by multiple Western intelligence services. The group has also been described as expanding from trafficking in compromised corporate datasets into brokering higher-value state-related intelligence, indicating a business model centered on monetizing unauthorized access and exfiltrated information rather than purely ideological disruption. Ares Leaks has also appeared in conflict-related cyber ecosystems. During the Israel-Hamas war, the actor publicly expressed interest in purchasing data related to Hamas military personnel, suggesting opportunistic collection and resale activity tied to geopolitical events. This behavior is consistent with a mercenary or profit-driven actor that may exploit politically charged conflicts for intelligence acquisition and commercial gain rather than acting as a conventional hacktivist collective. High-confidence characterization of Ares Leaks is that of a cybercriminal marketplace actor specializing in stolen information, with an emphasis on sensitive or classified material and a willingness to facilitate espionage-oriented transactions. Publicly available information does not support a confirmed nation-state attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Online crime group marketing an espionage-as-a-service style offering; sells hacked corporate databases and sensitive government documents (including alleged FSB materials) via Telegram, with pricing in Monero.
Online crime group offering “espionage-as-a-service,” advertising and selling stolen/hacked sensitive government documents (including Russian FSB materials) and hacked corporate databases, with sales conducted via Telegram and payments requested in Monero.
Threat actor involved in soliciting or purchasing sensitive data related to Hamas.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.