'Ndrangheta is an Italian organized crime syndicate originating in Calabria that has evolved from a regional mafia into a highly internationalized criminal network. It is widely regarded as one of the wealthiest and most globally active Italian organized crime groups, with operations spanning dozens of countries. The organization is structured as decentralized, family-based clans known as 'ndrine, a model that increases resilience by allowing the broader network to survive disruption of individual cells or families. Historically, the group expanded its economic power through kidnappings for ransom and later consolidated a central role in cocaine trafficking, which remains a principal source of profit. It also uses corruption, infiltration of public institutions, manipulation of administrative processes, and investment in legitimate businesses to entrench itself in local economies and political systems. Reported activity includes influence over public procurement, misappropriation of public and European Union funds, reinvestment of illicit proceeds into commercial enterprises, and participation in transnational financial fraud and money laundering networks. The group has demonstrated a strong ability to expand beyond Italy by leveraging migration ties from Calabria, recruiting trusted associates from the same home region, and establishing international cells that facilitate infiltration, investment, and operational growth. It has been described as particularly influential in Germany and as deeply involved in money laundering networks across Central and Eastern Europe. In Slovakia, it has been linked to the use of agricultural and renewable-energy businesses to obtain EU funds and to broader patterns of political corruption and organized-crime infiltration. Known aliases include ndrangheta and 'ndrangheta. The actor is best understood as a transnational mafia organization driven primarily by profit, using corruption, financial crime, and narcotics trafficking rather than cyber operations as its core means of power projection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.