Skip to main content
Mallory

HYFLOCK

Also known asHYFLOCK

HYFLOCK is a previously unreported ransomware-as-a-service (RaaS) operation active in 2026 and operating exclusively on Tor at e5hdifgit6ua7k4ggmltume7kbyryksdnlrkc55we33fnshgxfeqgsyd[.]onion. It was observed as part of the criminal RaaS ecosystem and publicly recruited affiliates. On May 14, 2026, an actor using the handle hyflock123 opened a recruitment thread on the Duty-Free forum to launch Hyflock and claimed prior work for LockBit and Qilin; that claimed lineage is self-reported and was not independently corroborated in the content. The operation was described as an all-in-one RaaS platform with affiliate management, a payload builder, victim negotiation chat rooms, payment tracking, and a data leak site. Publicly exposed platform elements indicated a dual-portal model separating attacker and victim access, open registration for affiliate recruitment, and support for Bitcoin, Zcash, and Monero payments. The leak site was described as including screenshot previews of stolen data, file listings by category, selective public/private disclosure controls, and ZoomInfo-based victim company enrichment. Hyflock advertised integrated initial-access purchasing, an access-broker marketplace, automated negotiation rooms, automated revenue sharing, AI-driven victim analysis, and red-team support. It advertised a sliding operator cut of 20% on the first job and 15% on the second job, stabilizing thereafter. Hyflock also claimed its encryptor used an AES-128-CTR and RSA-4096 hybrid scheme and ran at roughly twice the speed of LockBit 3.0, but the performance claim was not independently verified. Researchers reported that HYFLOCK’s public login page exposed an 8,112-line CSS file containing 94 lines of Simplified Chinese developer comments that revealed internal platform components and workflow. The panel UI rendered in English and Russian, with Russian appearing to be the primary interface language, while the Chinese comments were assessed as likely native developer documentation. The reporting also noted otherwise strong operational security controls, including CSP, CSRF protections, X-Frame-Options, authentication redirects, and CAPTCHA-based DDoS protection, undermined by the exposed stylesheet. Known alias in the provided content: hyflock.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

9 of 15 tactics20 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1583.003
Virtual Private Server
T1587
Develop Capabilities
T1587.001
Malware
TA0002
Execution
1 technique
T1204
User Execution
TA0004
Privilege Escalation
1 technique
T1484
Domain or Tenant Policy Modification
T1484.001
Group Policy Modification
TA0112
Defense Impairment
1 technique
T1484
Domain or Tenant Policy Modification
T1484.001
Group Policy Modification
TA0008
Lateral Movement
1 technique
T1570
Lateral Tool Transfer
TA0009
Collection
1 technique
T1005
Data from Local System
TA0011
Command and Control
2 techniques
T1090
Proxy
T1090.003
Multi-hop Proxy
T1573
Encrypted Channel
TA0010
Exfiltration
2 techniques
T1041×2
Exfiltration Over C2 Channel
T1567
Exfiltration Over Web Service
TA0040
Impact
4 techniques
T1486×3
Data Encrypted for Impact
T1496
Resource Hijacking
T1565
Data Manipulation
T1657
Financial Theft
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping14

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.