Global kOS was a small 1990s hacker collective associated with offensive tooling, mailbombing, denial-of-service concepts, password cracking, and phreaking-related projects. The group was publicly linked to the Up Yours series, especially the Up Yours email bomber, and to plans for later variants that were described as adding denial-of-service functionality and anonymity features. Reported members and aliases associated with the group include Acid Angel, Glitch, Silicon Toad, The Raven, That Guy, Spidey, Zaven, The Shadow Hunter, Materva, and Swine. Bronc Buster was also publicly tied to the release and promotion of Up Yours 4 and stated that it was a Global kOS release. Global kOS was described as operating independently and as developing multiple offensive or dual-use software suites, including a Digital Destruction Suite, a Hacking Suite, a Phreaking Suite, and a planned Security Suite. The Hacking Suite was portrayed as automating intrusion activity and password-file cracking, while the Digital Destruction Suite was discussed as incorporating destructive utilities and brute-force functionality. Publicly attributed statements and archived discussions linked the group to anonymous mailbombing techniques, denial-of-service development, password cracking, and broader intrusion-enablement tooling. The actor’s activity was primarily directed at U.S.-based targets in public accounts, including politicians, major online services, and high-profile individuals. The group’s posture and tooling indicate motivations centered on disruptive hacking and destructive experimentation rather than espionage or financially motivated crime. Available information supports characterization as a loosely aligned hacker group from the 1990s rather than a state-sponsored actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a named hacking group in the historical timeline/navigation content.
Named hacking group listed in the content's 1990s timeline/navigation material.
Named as a hacking group in a 1990s hacking timeline/sidebar; no specific operations, malware use, or targeting details are provided in the content.
Referenced only as a named hacking group in a navigational list; no operational details are provided in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.