Stormfront is a white nationalist and neo-Nazi online forum founded in 1995 by Don Black. It became one of the earliest major internet hubs for white supremacist and white separatist communities, providing a long-running platform for propaganda, ideological discussion, movement networking, and online organizing. The forum has been associated with extremist self-description, internal disputes among white nationalist factions, and discussions that contributed to radicalization within the broader far-right ecosystem. Stormfront has also been cited in connection with violent extremism, with advocacy organizations linking numerous murders to registered members. It was deplatformed by service providers in 2017 following pressure related to violent crimes associated with site users. Stormfront is not a conventional cyber threat actor and there is no high-confidence evidence here of distinct cyber intrusion, ransomware, or malware operations attributable to it.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.