ProbablyOnion is the name associated with a 2014 intrusion into the job site bigmoneyjobs.com. The activity attributed to this actor consists of exploitation of a SQL injection vulnerability that led to unauthorized access to the site’s user database and exposure of more than 36,000 accounts. Compromised information reportedly included usernames, email addresses, and passwords, with the passwords stored in plain text by the victim service. Publicly available information in this context is limited to this single intrusion, and there is insufficient high-confidence evidence to characterize broader targeting patterns, organizational affiliation, geographic origin, or sustained operational tradecraft beyond the initial web-application compromise and resulting data theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.