ShadowCrew was an international cybercrime organization and online carding marketplace active from roughly 2002 to 2004. It operated as a large underground forum with approximately 4,000 members and a structured hierarchy that included administrators, moderators, reviewers, vendors, and general members. The group facilitated trafficking in stolen payment-card data, bank-account information, personal identifying information, and counterfeit identity documents, and it also provided guidance and services that supported identity theft and payment-card fraud. U.S. authorities alleged that ShadowCrew members trafficked in at least 1.5 to 1.7 million stolen credit and debit card numbers and caused more than $4 million in losses. ShadowCrew functioned as a criminal marketplace rather than a conventional intrusion set. Its operators vetted vendors, moderated postings, reviewed illicit goods and services, and enabled transactions involving stolen financial data and false documents. The forum also supported related fraud services, including testing of stolen card data and dissemination of tutorials for fraud and document forgery. The group’s activity centered on credential and identity-data theft, financial fraud, and monetization of stolen information. The organization had an international footprint. Individuals alleged to have administered, moderated, or sold through the forum were located in the United States, Russia, and Argentina, and later prosecutions also involved a Bulgarian national tied to ShadowCrew-related carding activity. ShadowCrew is closely associated with Albert Gonzalez, whom U.S. law enforcement identified as a leading figure connected to the forum and later to major payment-card theft operations. The group was dismantled in 2004 during a U.S. Secret Service undercover operation known as Operation Firewall, which led to multiple arrests and indictments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Carding and identity theft criminal group trafficking stolen credit/ATM card numbers and counterfeit identity documents via an online marketplace.
ShadowCrew appears only in a generic Wikipedia navigation list of hacking groups, without any discussion tying it to the PoisonIvy content.
Groups Anonymous associated events Avalanche Crime Boys GNAA Goatse Security Insanity Zine Corp. GhostNet Level Seven PLA Unit 61398 Prime Suspectz RBN ShadowCrew World of Hell Sandworm
Carding forum involved in cybercrime and payment-card fraud activities; the article discusses law-enforcement action tied to a fugitive charged in connection with it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.