Discomrade is a Russian-language underground actor known for advertising Coala, an HTTP Layer 7 distributed denial-of-service malware, in late 2017. Coala was marketed as a bot focused on application-layer flooding and was promoted with features such as customizable HTTP headers, task limits, asynchronous sockets, request-rate tracking, and support for communications via Namecoin .bit domains. The operator also claimed the malware could bypass several commercial DDoS protection services. Discomrade is associated with offensive botnet tooling intended for disruptive attacks rather than espionage or credential theft. The available reporting ties this actor to underground malware development and sales activity in Russian-speaking criminal forums, but does not provide high-confidence attribution to a specific real-world identity or state sponsor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.