CL-CRI-1116 is a financially motivated, Com-affiliated cybercrime activity cluster active against retail and hospitality organizations since February 2026. It conducts voice-phishing operations in which operators impersonate IT helpdesk personnel, spoof calling information, and direct employees to counterfeit corporate single-sign-on pages. The group captures credentials and time-based one-time passwords, and may enroll attacker-controlled devices in identity platforms to circumvent multifactor authentication. Following account compromise, CL-CRI-1116 uses antidetect browsers, residential proxies, and authenticated SaaS sessions to reduce detection. It expands from employee accounts to privileged and executive accounts through internal-directory collection and further social engineering. The group collects data from SaaS and enterprise repositories, including SharePoint and Salesforce, using Microsoft Graph permissions, SaaS search functions, browser downloads, and API exports. Stolen information is exfiltrated directly or staged through file-sharing services. CL-CRI-1116 conducts data-theft extortion, issuing typically seven-figure ransom demands from external or compromised employee email accounts. It has also used SWATting against company personnel, including senior executives, as a coercive pressure tactic. It is associated with infrastructure patterns also linked to the Com-affiliated actor Bling Libra, although the two are tracked as distinct named entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
39 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Potentially linked to newly created infrastructure, including brand-impersonation domains, that may support vishing campaigns.
Likely associated with passkey-themed infrastructure that may support vishing campaigns against organizations across numerous industries.
Conducting vishing-led credential theft and extortion operations targeting retail and hospitality organizations, abusing compromised SaaS and identity platforms to collect and exfiltrate sensitive data, then issuing ransom demands and using SWATting for coercion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.