DOHI is depicted as a prominent hacking group in a fictional narrative set around DEF CON. The group is characterized as publishing exploits for widely used Internet software to public mailing lists and cultivating disruption and notoriety. Named members or associates in the story include persephone, august, z, and sp3rt/Mark Owens, with persephone portrayed as a core member. The narrative associates DOHI with IRC-based coordination, social connections in the conference scene, and interest in offensive tooling tied to a cyberweapon called the Great Artillery and a counter-tool called the Antidote. Because the available material is explicitly fictional, DOHI cannot be treated as a verified real-world threat actor, and no high-confidence attribution, targeting profile, or operational history can be established from it.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.