Sythe is a cybercriminal threat actor associated with the advertisement, sale, and alleged leaking of stolen databases. Activity attributed to this alias includes offering multiple purported datasets spanning cryptocurrency, artificial intelligence, finance, and e-commerce services, as well as claiming responsibility for leaking the database of WormGPT, a criminal AI platform marketed for offensive use. The actor’s operations indicate involvement in illicit data brokerage and exposure of compromised user information rather than a clearly established nation-state mission. Reported Sythe activity centers on monetizing or publicly releasing large collections of user data, including email addresses, account-related records, and subscription or billing metadata. Such activity can enable downstream phishing, credential abuse, account takeover, fraud, and broader cybercriminal targeting. The actor has advertised datasets individually, offered samples to prospective buyers, and directed interested parties to private contact channels, consistent with underground marketplace and breach-for-sale behavior. Sythe has also been linked to the alleged leak of WormGPT user data. Because WormGPT has been promoted as an AI service for generating phishing lures, malicious code, exploit assistance, and social-engineering content, a leak of its user base would be notable both for criminal ecosystem disruption and for secondary exploitation of exposed users. High-confidence reporting supports Sythe’s claimed role in the leak, but does not establish broader organizational structure, sub-groups, or durable affiliations beyond the alias itself. Observed behavior supports assessment of a financially motivated cybercriminal actor with capabilities centered on exfiltration and post-compromise monetization of stolen data. Available information does not directly establish the actor’s origin country, specific intrusion tradecraft used to obtain the data, or a consistent ransomware or extortion program.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Advertising the sale of multiple alleged stolen databases containing roughly 3.8 million email and user records from crypto, AI, finance, and ecommerce-related platforms.
Claimed responsibility for leaking the complete WormGPT database, allegedly exposing data tied to 19,000+ users (emails, user IDs, subscription and billing metadata).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.