CrackRat Zone Clay is a cybercrime-associated group observed as part of a Telegram-based alliance with RasCorp Group and VFVCT (V For Vendetta Cyber Team). Within that alliance, CrackRat Zone Clay was described as contributing multifunctional tooling, while partner groups handled business coordination and operational strategy. The group appears to participate in a broader collaborative ecosystem rather than operating as a clearly delineated standalone intrusion set. Available reporting links CrackRat Zone Clay to malware tooling promotion and credential-related activity through personas associated with the group. One linked persona previously used names referencing RAT tooling and was observed promoting and discussing G-700 RAT in Telegram communities, alongside references to account logs and other credential-related material. The broader alliance around CrackRat Zone Clay has been associated with recruitment for ransomware-experienced personnel, malware development, networking, infrastructure management, and scripting, indicating an ecosystem oriented toward shared tooling, operator recruitment, and coordinated cybercriminal operations. At high confidence, CrackRat Zone Clay should be understood as a tooling-focused component of an emerging criminal partnership that overlaps with ransomware-oriented and credential-focused underground activity. Publicly available information in this context does not establish a confirmed nation-state affiliation, formal hierarchy, or independently attributed victimology for CrackRat Zone Clay beyond its role in this alliance.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.