Sakura Samurai was a white-hat hacking and security research group founded in 2020 and later reported inactive in 2022. The group is associated with coordinated vulnerability discovery, validation, and public disclosure affecting government entities, international organizations, open-source software, and major private-sector companies. Known members and associates mentioned in reporting include founder John Jackson ("Mr. Hacking") and former members Robert Willis ("rej_ex"), Higinio Ochoa ("w0rmer"), and Aubrey Cottle ("Kirtaner"/"Kirt"). The group became widely known for disclosures involving exposed source-control repositories, configuration weaknesses, credential exposure, insecure storage practices, and application-layer flaws. Reported activity includes identifying exposed Git directories and credential material affecting United Nations-related organizations, with claimed access to source code, administrative credentials, and large volumes of employee records. Sakura Samurai also publicly disclosed vulnerabilities affecting multiple Indian government organizations, including exposed repositories and configuration directories, access to sensitive records, session hijacking opportunities, and arbitrary code execution conditions. Additional research attributed to the group includes disclosure of a cross-site scripting flaw in Apache Velocity Tools, insecure image retention in Keybase, a Pega Infinity misconfiguration associated with downstream enterprise exposure, and vulnerabilities affecting Fermilab systems. Sakura Samurai’s activity aligns with defensive security research rather than criminal intrusion for profit or espionage. Its operations centered on reconnaissance, validation of exploitable weaknesses, limited post-exploitation to demonstrate impact, and responsible or public disclosure intended to drive remediation. The group is best characterized as a security research collective rather than a malicious threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
White-hat security research group associated here with responsible disclosure/validation of vulnerabilities, including incidents involving UN data exposure and Ford web vulnerabilities enabling account takeover.
White-hat security research group focused on vulnerability discovery and responsible disclosure; reported exposed git/config directories, session hijacking and arbitrary code execution issues, and other misconfigurations affecting government and corporate systems. Announced inactivity in Oct 2022.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.