Recursion Team was a cybercriminal group active around 2020 to 2021. It is associated with SIM swapping and swatting activity, and reporting has also linked members of the group to fraudulent emergency data requests used to obtain subscriber information from service providers. The group is notable primarily as an antecedent network tied to individuals later associated with LAPSUS$, including WhiteDoxbin, who has been described as a founding member. Recursion Team appears to have operated as a criminal collective rather than a state-sponsored actor. Its known tradecraft centers on telecom-focused account compromise and abuse of social-engineering-enabled access rather than malware-heavy intrusion operations. Known aliases include Recursion and recursion_team.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier cybercriminal group tied to some LAPSUS$ members, specializing in SIM swapping, swatting, and fraudulent law-enforcement data request services.
Cybercriminal group associated with SIM swapping and swatting activity prior to the formation of LAPSUS$.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.