Yurosh is an online criminal persona named alongside LAPSUS$, Scattered Spider, IntelBroker, Trihash, Kurosh, Clown, and Yukari in a public statement claiming those identities were "going dark." Available reporting ties the name to the same broader cybercriminal milieu associated with high-profile intrusion and extortion claims, but the specific role, membership, and operational history of Yurosh are not independently established at high confidence. The surrounding claims include alleged disruptive activity, intrusions against major enterprises, observation of victims, and possible access to law-enforcement-related data, but those assertions were also assessed as likely containing disinformation. Based on currently available corroborated facts, Yurosh should be treated as an alias or persona associated with a loosely defined criminal ecosystem rather than a well-attributed standalone threat actor with confirmed infrastructure, victimology, or tradecraft. No high-confidence evidence in the available material supports a definitive country attribution, target set, ransomware modus operandi, or specific ATT&CK-level capabilities uniquely attributable to Yurosh.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.