Void Balaur is a Russian-linked hack-for-hire and cyber-mercenary threat actor active since at least 2016, known for credential-phishing, account compromise, and data collection operations conducted on behalf of clients. The actor has been publicly associated with the earlier Hacknet and RocketHack personas, which advertised paid intrusion and surveillance services including email and social-media account compromise, private-data acquisition, remote access, content manipulation, and other bespoke offensive tasks. Void Balaur has targeted individuals and organizations across multiple countries, with a notable concentration on victims connected to Russian business, political, legal, human-rights, and geopolitical interests. The group primarily seeks access to webmail, messaging, social-media, and corporate accounts. Reported targets have included major consumer email providers, regional mail services, messaging platforms, and enterprise email environments. Its operations rely heavily on scalable phishing infrastructure, including large numbers of lookalike domains themed around email security, authentication workflows, privacy services, and government-related services. Void Balaur has also used localized lures tailored to banking, social-media, and public-service themes. A notable operational characteristic is its focus on defeating account protections rather than only harvesting passwords. In addition to credential theft through spoofed login pages, Void Balaur has targeted accounts protected by multi-factor authentication by soliciting backup codes. It has also been observed maintaining post-compromise access through abuse of legitimate account features, including granting OAuth access to benign email applications and creating app passwords for IMAP-based mailbox access. These techniques support durable access and mailbox exfiltration even after the initial phishing event. Void Balaur has demonstrated broad and persistent infrastructure management, with assessments linking it to thousands of unique domains over several years. Public reporting has described the actor as highly active and resilient despite disruptions to its public-facing advertising personas. A limited and low-confidence infrastructure overlap has been noted with systems operated by the Russian Federal Protective Service, but this has not established direct state control. The actor is best characterized as a mercenary intrusion service aligned with client-driven espionage and surveillance objectives rather than a conventional ransomware operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
599 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hack-for-hire / cyber mercenary operations targeting individuals and organizations globally through credential phishing and account compromise, including email, social media, messaging, and corporate accounts; also advertised services for private data collection, remote access, mobile tracking, and content manipulation.
Referenced as another mercenary or hack-for-hire threat actor previously tracked by SentinelLabs; no operational detail is provided in this content.
Named as a cyber-mercenary actor targeting Ukraine and its allies in the broader ecosystem of post-invasion campaigns.
Russian hack-for-hire credential-phishing operator targeting journalists, politicians, NGOs/non-profits, and also unaffiliated individuals; maintains access via OAuth tokens or app passwords for IMAP access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.