Hacker Com is a broad, technically sophisticated cybercriminal sub-community within The Com, a primarily English-speaking international online criminal ecosystem. It consists of loosely connected groups and individuals, including associations reported with ShinyHunters, Scattered Spider, and TeamPCP. Members monetize cybercriminal services for other criminal operations and have affiliations with ransomware-as-a-service ecosystems. Observed activity includes phishing, malware development and deployment, computer intrusions, distributed denial-of-service attacks, theft of personally identifiable information and cryptocurrency, SIM swapping, ransomware attacks, and the sale of compromised government email accounts. Hacker Com actors employ remote-access malware, phishing kits, anonymization services, voice-over-IP and voice-modulation services, spoofing technology, cryptocurrency cash-out services, and encrypted communications to facilitate operations and conceal identity. Financial gain is a primary driver, including through the sale of technical services and cryptocurrency theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A separate cybercriminal sub-community within The Com. It is mentioned as sharing online spaces with Russian intelligence recruitment activity, but the content states there is no indication its members were approached for sabotage.
Cyber-criminal subset of The Com comprising technically sophisticated actors; some linked/affiliated with ransomware-as-a-service ecosystems; monetizes technical services and cryptocurrency theft and conducts intrusions, phishing, malware deployment, and ransomware attacks while using anonymity/obfuscation tooling.
Service-provider subgroup in The Com ecosystem; members linked to RaaS groups and monetizing access/capabilities (selling services, accounts, tooling) to other criminal operations; involved in cryptocurrency-motivated crime.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.