Chucky is a cybercrime actor associated with the operation of LeakBase, a large English-language cybercrime forum active since 2021 that facilitated the sale of hacked databases, stolen credentials, financial information, and stealer logs. Known aliases include Chuckies and Sqlrip. Chucky has been linked to the distribution and advertisement of large collections of breached data from global entities and to historical postings offering a large Instagram dataset that later reappeared under other aliases. Reporting also notes possible overlap between Chucky, Chucky_lucky, and Solonik based on shared datasets, timing, platforms, and Telegram-channel activity, but that linkage is not conclusive. LeakBase functioned as a marketplace for stolen data and cybercrime services, including material derived from infostealer malware that could enable account takeover, fraud, and follow-on intrusions. The forum reportedly prohibited the sale or publication of Russian databases, a pattern sometimes seen in Russian-speaking cybercrime ecosystems, but this alone does not establish Chucky’s nationality. Chucky’s activity is characterized by brokering and distributing compromised data rather than ransomware operations. High-confidence behaviors supported here include initial access enablement through trafficking in stolen credentials and logs, credential theft enablement via stealer-log commerce, and exfiltration-related handling and resale of stolen datasets. LeakBase was dismantled in March 2026 during the international law-enforcement action known as Operation Leak.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operator/administrator identity associated with the LeakBase cybercrime forum, involved in facilitating the sale/sharing of stolen databases and stealer logs (credential dumps harvested via infostealer malware) used for account takeover and fraud.
Earlier alias associated with the same recycled Instagram 17M dataset later marketed by Solonik. The content suggests possible identity overlap or close operational alignment based on shared datasets, timing, platforms, and monetization patterns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.