UGNazi is a hacktivist hacking group active in the early 2010s and known for disruptive intrusions, data leaks, account hijacking, and social-engineering-based compromises. The group is associated with attacks against organizations including WHMCS and MyBB, and it publicly framed some operations as retaliation or punishment against perceived misconduct or poor security practices. UGNazi used social engineering to obtain unauthorized access, including taking control of the MyBB domain and compromising WHMCS through impersonation of a company representative to a hosting provider. Reported impacts from its operations included large-scale data theft and public leakage, deletion of victim data, website disruption, and takeover of social-media accounts. Public statements attributed to the group emphasized exposing weak security and threatening further leaks and destruction. UGNazi has also been linked in reporting to members or associates including Mir Islam and Troy Woody Jr. The actor is best characterized as a hacktivist collective focused on publicity-generating intrusions, data exposure, and disruptive actions rather than espionage or ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a hacking collective of which the two charged individuals were longtime members; no specific cyber operations, malware, targets, or campaigns are described in the content.
Hacktivist-style intrusion and data leak activity, presenting itself as exposing poor security practices and threatening continued destructive actions and data leaks against insecure sites using MyBB/WHMCS.
Hacktivist group claiming responsibility for the WHMCS breach, including social engineering of the web host, data theft and leak, website disruption, and Twitter account hijacking. The group also claimed denial-of-service activity against Papa John's and previous attacks on Visa, MGM, and CIA.gov.
Conducted a social-engineering-driven domain takeover of MyBB.com (unauthorized control over the domain), reportedly motivated by MyBB’s use by a third-party site (HackForums).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.