CyberN****** is a cybercriminal group that emerged from a March 2023 rebrand of an earlier collective known as The Boys, which had roughly 32 members in January 2023. The group has been linked to the broader stolen-data economy and to BreachForums activity, with IntelBroker identified as affiliated with CyberN******. By August 2024, reporting identified four core members, including a collaborator referred to as CC-1. The group is associated with financially motivated intrusion and data brokerage activity centered on stealing, brokering, and distributing victim data. Operations attributed to affiliated actors relied primarily on exploiting basic security misconfigurations, insecure APIs, and compromises of third parties rather than zero-day vulnerabilities. Observed behavior includes unauthorized access to victim environments, exfiltration of data, and in at least one case deletion of victim data. The group’s ecosystem overlaps with criminal marketplace operations in which stolen datasets were advertised for sale or released publicly through forum posts. CyberN****** is best understood as part of an organized cybercriminal milieu focused on monetizing intrusions through data theft and resale rather than destructive or ideological objectives. Its known associations indicate post-compromise exploitation and exfiltration capabilities, with activity affecting dozens of victims globally through affiliated operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.