berz0k is a cybercrime-associated threat actor persona observed advertising a purported zero-day Linux local privilege escalation exploit on underground forums for a high price. Public reporting ties the persona to the attempted sale of an exploit claimed to provide stable privilege escalation to root across multiple major Linux distributions while avoiding system crashes. The available evidence supports characterization of berz0k as an exploit seller operating in criminal marketplaces rather than a clearly attributed intrusion set or nation-state actor. The actor’s known activity centers on monetizing offensive capability related to Linux privilege escalation. The advertised capability indicates post-exploitation utility by enabling elevation from an unprivileged local context to root, which would support follow-on actions such as persistence, defense evasion, credential access, and broader post-compromise operations. However, there is no high-confidence public evidence in the supplied facts that berz0k personally conducted intrusions, deployed ransomware, or targeted specific countries or industry sectors. No corroborated aliases, sub-groups, or national affiliation are established from the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.