SnowTeam is a cybercriminal actor associated with the operator “Snow,” known for advertising Leak Bazaar, a criminal post-exfiltration data-processing and brokerage service, on the Russian-speaking TierOne forum in March 2026. Leak Bazaar is designed to transform stolen corporate archives into structured, marketable intelligence rather than simply host raw data dumps. Its advertised workflow includes ML-assisted text analysis, automated removal of extraneous system data, database reverse engineering, ERP-data parsing, and human analyst validation. The service claims to categorize and package data according to criminal-buyer demand, including financial reporting, mergers and acquisitions material, research and development information, personal data, security information, regulatory material, and organizational data. It offers both exclusive sales and repeat sales to multiple buyers, creating a mechanism for continued monetization of stolen data after an initial extortion attempt or leak. SnowTeam has sought large, unpublished corporate datasets, particularly predominantly English-language data, for this processing and resale model.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An indexing-as-a-service provider that processes stolen corporate data into multilingual, category-segmented products for resale to ransomware operators, fraud actors, social engineers, espionage buyers, and other criminal customers.
Operating Leak Bazaar, a post-exfiltration processing service that cleans, parses, analyzes, and packages stolen corporate data into organized, sellable intelligence for criminal buyers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.