Masters of Deception (MOD) was a New York-based hacker and phone-phreak group active in the late 1980s and early 1990s. It was a principal rival of the Legion of Doom during the period commonly called the Great Hacker War. MOD members were associated with unauthorized access to telephone-company systems, acquisition and use of telecommunications credentials and technical material, and wiretapping-related offenses. The group’s activity prominently focused on telephone central-office infrastructure and the potential to manipulate or monitor telecommunications services. Known members included John Lee, who used the handle Corrupt and was convicted on federal wiretapping charges in connection with this era.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historic hacker collective mentioned as one of several organized hacker communities active in the 1980s; the reference provides no specific operations or malware attribution.
Described as one of the largest hacker and phreaker rings in the country targeted by U.S. law enforcement.
Early-1990s New York-based hacker group involved in the 'Great Hacker War' against Legion of Doom; associated with wiretapping-related federal charges against members.
Historic hacker group referenced as a rival to Legion of Doom; no specific malware/TTP detail provided in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.