HerbalKing was a prolific spam gang active since at least 2005 and widely regarded as one of the most significant spam operations on the Internet during 2007 and 2008. The group is associated with large-scale fraudulent pharmaceutical spam, especially deceptive male-enhancement marketing, and operated through a coordinated criminal enterprise involving multiple co-conspirators, shell companies, offshore financial infrastructure, and highly automated delivery systems. Known members publicly associated with HerbalKing include Lance Atkinson, Shane Atkinson, Roland Smits, and Jody Smith. The operation has also been linked in reporting to broader spammer ecosystems and repeat spam offenders. Geographic ties in legal and investigative reporting connect the group primarily to Australia, with coordinated enforcement action involving the United States and New Zealand and possible links extending to India. HerbalKing's operational model relied on mass unsolicited email distribution at very high volume, supported by botnet-enabled spam infrastructure that was resilient enough to continue operating even after public legal disruption. The group was noted for rotating large numbers of domains and maintaining an industrialized spam pipeline designed for persistence and continuity. Its activities centered on fraudulent marketing and monetization rather than espionage or destructive objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.