Exodus is a Roblox-focused account takeover and virtual-item theft actor associated with the underground "beaming" ecosystem. The name has been observed in victim-profile defacements following compromises, indicating involvement in unauthorized access to Roblox accounts and theft of valuable in-game assets. Activity attributed to this actor aligns with financially motivated theft of limited items and Robux for resale through off-platform communities and unauthorized marketplaces. The broader tradecraft associated with this actor includes phishing that impersonates Roblox, social engineering conducted through Discord and in-game interactions, theft and abuse of Roblox session material from exported browser data, and fraudulent account-recovery attempts using forged payment evidence. Victims are typically high-value Roblox users with valuable inventories, including prominent traders and players. The operational objective is rapid transfer and liquidation of stolen virtual goods before platform enforcement or recovery actions can occur. Exodus appears to operate within a criminal ecosystem rather than as a state-linked intrusion set. Reported behavior includes credential theft, session hijacking, initial access through phishing and social engineering, post-compromise transfer of assets, and exfiltration or monetization of stolen digital property. Public reporting directly ties the name "exodus" to profile defacement after account compromise, but does not provide high-confidence attribution to a specific country, formal group structure, or broader alias set beyond the observed name itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named beaming group associated with Roblox account takeovers and theft of valuable in-game items from victim accounts.
A named beaming group or persona associated with Roblox account takeovers and theft of valuable in-game items from victim accounts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.