PHIRM, also written as P.H.I.R.M., was an early United States hacker group active from 1983 until its voluntary dissolution in 1990. The group initially operated under the name KILOBAUD before reorganizing in 1985 and expanding its visibility and membership during the mid-1980s. It is associated with the bulletin board system scene of that era, with members operating numerous BBS platforms and participating prominently in early underground hacker culture. PHIRM is known for publishing and circulating material related to unauthorized access and security bypass techniques. Its activities included research and publication concerning weaknesses in consumer banking systems, most notably a guide addressing methods for compromising Bank of America home banking security in 1989. That publication drew significant scrutiny and was followed by arrests. The group reportedly chose to disband in 1990 after heightened law-enforcement attention following arrests affecting the broader hacker scene, including those involving Legion of Doom. Known aliases and predecessor naming include PHIRM, P.H.I.R.M., and KILOBAUD. Reported founding members included Archangel, Blade Runner, Jack The Ripper, Systematic, The Stingray, Sir Gamelord, Meo Dino, and Chris TC Wilson, also known as Night Crawler. PHIRM is widely regarded as one of the last major "old school" 1980s hacker groups to dissolve.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.