WikiLeaks is an anti-secrecy publishing organization best known for obtaining and releasing confidential, classified, and politically sensitive materials. It has been associated with Julian Assange and has been described by U.S. officials as a non-state hostile intelligence service following the 2017 publication of the CIA's Vault 7 materials. WikiLeaks has been central to multiple high-profile disclosures involving government surveillance, military and diplomatic reporting, and intelligence operations. The organization is not a conventional cyber intrusion group in the mold of an espionage or financially motivated threat actor, but it has played an operational role in the dissemination of stolen or leaked information. High-confidence reporting has linked WikiLeaks to the publication of materials that advanced Russian influence objectives during the 2016 U.S. election period, and it later published the Vault 7 leak, which triggered an aggressive U.S. counterintelligence response. Reported U.S. assessments and public findings indicate that WikiLeaks actively sought and amplified material tied to Russian intelligence operations. WikiLeaks' core activity is exfiltration-adjacent publication and dissemination of sensitive data rather than network intrusion itself. Its relevance in threat intelligence stems from its role in handling, curating, and releasing unlawfully obtained information, as well as its interactions with state-linked actors and its impact on intelligence, diplomatic, and political environments. It has been targeted by surveillance, disruption planning, and criminal prosecution efforts by the United States and allied services. Known associated figures include Julian Assange.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WikiLeaks is discussed as the central target of a U.S. intelligence campaign after publishing the CIA’s Vault 7 materials. The content portrays it as an organization viewed by U.S. officials as acting like a hostile intelligence service, with alleged links or coordination with Russian actors, and as involved in publishing stolen classified materials.
Organization designated in the content as a 'malicious foreign actor' and subjected to surveillance and prosecution efforts; discussed as a target rather than an operator.
Received and released hacked materials stolen by the GRU, timed disclosures for maximum political impact during the 2016 U.S. election, and coordinated communications with GRU personas regarding dissemination.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.