Masters of Destruction (MOD) was a U.S.-based early 1990s hacker and phone-phreak collective associated with teenagers from Brooklyn and the Bronx and linked socially and technically to Mark Abene, better known as Phiber Optik. The group emerged from the bulletin-board and phreaking underground and became known for unauthorized manipulation of telephone services before expanding into intrusions against major corporate and government computer networks. Phiber Optik is described as an influential mentor and collaborator, although he reportedly denied formal membership in the group. MOD’s activity began with telephone-system abuse and prank-oriented operations, including taking over telephone accounts, altering services, and harassing selected targets. The group later moved into broader computer intrusions affecting prominent U.S. organizations in the defense, financial, industrial, government, and consumer sectors. Reported victim organizations included TRW, Martin Marietta, Bank of America, the National Security Agency, and Chiquita. Wiretap reporting also linked MOD members to discussion of a fraudulent scheme involving creation of a fake credit bureau to alter credit histories for payment, indicating interest in financially motivated abuse beyond prank activity. The group is best characterized as an early underground intrusion crew with strong capabilities in initial access, post-exploitation, spoofing and manipulation of telecommunications services, and unauthorized access to enterprise and government systems. Its historical significance lies in its role in the U.S. hacker underground of the early 1990s, its association with prominent phreaking figures, and its transition from disruptive experimentation and harassment toward more serious criminal intrusion and fraud-related conduct.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A hacker group involved in telephone network intrusions and broader computer break-ins, including unauthorized access to major corporate and government networks and schemes to manipulate telephone services and potentially credit histories.
Named hacker group discussed in connection with prior criminal hacking activity and law-enforcement action against members such as Mark Abene (Phiber Optik).
A named hacker group referenced as part of the modem-connected hacker underground involved in hacking culture and bulletin board activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.