Kurosh is a handle referenced in public claims associated with a loose cluster of cybercriminal personas that also named LAPSUS$, Scattered Spider, IntelBroker, Trihash, Yurosh, Clown, and Yukari. The available reporting ties Kurosh only to self-attributed statements posted through criminal-community channels and forums, including claims of intrusions, disruptive activity, and possible access to major commercial and government-related environments. Those statements included references to organizations in aviation, luxury retail, technology, and law-enforcement-related systems, but the claims were presented alongside indications of exaggeration or disinformation and are not sufficiently corroborated to attribute specific operations to Kurosh with high confidence. Based on the available evidence, Kurosh should be treated as an online alias or persona rather than a well-established standalone intrusion set. The material does not support a reliable assessment of organizational structure, nationality, victimology, tooling, or a distinct operational profile separate from the broader criminal milieu in which the name appeared. High-confidence attribution of concrete capabilities, ransomware tradecraft, or dominant motivation to Kurosh is currently not available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.