Operation High Five is a Philippines-origin influence operation focused on generating and distributing large volumes of short social-media comments. The activity has been associated with the use of AI assistance to produce bulk engagement content at scale rather than with malware deployment, ransomware, or destructive intrusion activity. Its operational profile aligns with coordinated online manipulation and amplification, using automated or semi-automated content generation to support influence objectives. High-confidence reporting supports Philippine origin, but does not provide sufficient corroborated detail on specific victim countries, industry targeting, or broader intrusion tradecraft beyond content-generation and social-media activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.