NullCrew, also seen as null_crew and sometimes branded as NullCrew FTS, is a hacktivist-oriented hacking collective known for publicized intrusions, data leaks, and taunting of victims through social media. The group became known for claiming compromises of high-profile organizations and government-related entities, and later resurfaced in campaigns focused on internet service providers and telecommunications companies. Activity attributed to NullCrew includes claimed or reported compromises affecting Comcast in the United States, Bell Canada in Canada, and Orange in France and the United Kingdom. In these operations, the group publicly announced attacks, released stolen or exposed data, and used leak-style publication to maximize visibility. Reported exposed information across incidents included usernames, passwords, email-related data, database structure information, employee-related records, user preferences, and in at least one Bell Canada breach, credit card data. NullCrew has been associated with exploitation of web application weaknesses, including a claimed Local File Inclusion vulnerability affecting mail infrastructure. Its operations show a pattern of initial access through exposed internet-facing systems, followed by credential theft and data exfiltration, with public disclosure used as a pressure and publicity mechanism. The group also demonstrated reconnaissance against service providers and repeatedly framed its operations around internet service provider targets. The actor's behavior aligns most closely with hacktivism: public messaging, ideological campaign branding such as OpFreeAssange, victim shaming, and encouragement of abuse of leaked contact data. NullCrew is best characterized as a publicity-driven intrusion and leak collective rather than a covert espionage actor or ransomware operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the Bell Canada data breach that exposed email addresses, usernames, user preferences, unencrypted passwords, and credit card data.
Claimed compromise of Comcast mail infrastructure, publishing what appeared to be Zimbra LDAP and MySQL passwords and a list of email servers, allegedly via a Local File Inclusion vulnerability.
Conducting intrusions and data leaks involving internet service providers; previously dumped data stolen from defense.gov, NSA, Mastercard, and BB&T, and later claimed responsibility for a large leak affecting a Canadian ISP (Bell).
Conducted a data theft and leak operation against Orange, publicly announcing the breach and releasing database information, system account details, encrypted passwords, and employee-related email data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.