The Com is a loose, amorphous collective of mostly cybercriminal groups, also referred to as Comm. Reporting describes it as a broader network/community known for aggressive social engineering campaigns and as having evolved on Discord and Telegram, with a loose-knit and fluid structure that makes disruption difficult. Known groups associated with The Com in the provided content include Scattered Spider and LAPSUS$ / Lapus$, and one report also notes tactical similarities between Com-affiliated activity and ShinyHunters. The collective is associated with social-engineering-heavy intrusion activity, including vishing and help-desk impersonation, credential theft, MFA bypass, and rapid cloud data theft followed by extortion. In the provided reporting, Com-affiliated tradecraft includes impersonating internal IT staff, directing victims to phishing pages to capture credentials, MFA codes, and session cookies, then accessing Microsoft 365 environments and rapidly exfiltrating data from SharePoint and OneDrive using legitimate tools. Compromised accounts are then used to send internal emails or Microsoft Teams messages to pressure victims with extortion demands. Scattered Spider, described as part of The Com, is further associated in the content with help-desk social engineering, unauthorized MFA device enrollment, targeting third-party IT providers, data theft, extortion, ransomware deployment, and rapid privilege escalation across cloud and on-premises environments. The content also attributes doxxing activity to The Com, stating that the group reportedly published personal data belonging to hundreds of government officials, including DHS, FBI, DOJ, and ICE personnel, with leaked information including names, email addresses, phone numbers, and in some cases home addresses.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loose cybercriminal community associated with aggressive social engineering campaigns; mentioned as the broader network with which Pink appears affiliated.
A broader cybercrime network with which Pink is believed to be associated.
Com-affiliated groups are referenced as commonly using vishing for initial access, harvesting credentials and MFA codes via phishing pages, rapidly exfiltrating data from SharePoint and OneDrive, and using compromised accounts for extortion via email and Microsoft Teams.
Reportedly published personal data belonging to hundreds of government officials, indicating doxxing and exposure of sensitive personal information.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.