vultapower is a cybercriminal actor associated with Vulta Intelligence, a credential lookup and extraction service built around large-scale collections of stolen credentials in URL:Login:Password format. The operation advertises searchable access to billions of credential records reportedly aggregated from infostealer logs and combolists, and provides both a web-based interface and a Telegram-based workflow for querying datasets and retrieving extracted results. The actor’s activity is centered on credential-enabled crime rather than disruptive or destructive operations. Vulta Intelligence is marketed to let users search domains, email addresses, and keywords across stolen credential datasets, then purchase extracted subsets for downstream abuse. This supports credential theft monetization and facilitates follow-on misuse of valid accounts, including credential stuffing and unauthorized access attempts against online services. Operationally, the service emphasizes automation, rapid search, formatted output, and integrated delivery through web and Telegram channels. Telegram is used as both an access and delivery mechanism, indicating reliance on mainstream web services to support criminal operations. The actor is therefore best characterized as a provider or broker in the stolen-credential ecosystem, enabling other threat actors to operationalize compromised account data at scale. No high-confidence attribution to a specific country, state sponsor, or formal sub-group is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.