LeakBase is a cybercriminal stolen-data marketplace associated with the sale of illicitly obtained information including banking data, login credentials, and corporate documents acquired through hacking operations. It has been described as a major online marketplace for stolen data and was the subject of an international law-enforcement operation that targeted its infrastructure, followed by the detention by Russian authorities of a suspected administrator. Available information supports characterization of LeakBase as a financially motivated criminal operation involved in trafficking compromised data rather than as a nation-state espionage actor. High-confidence reporting in the available material does not establish additional aliases, sub-groups, or a fuller operational profile beyond its role as a marketplace for hacked and stolen information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.