PoodleCorp was a hacking group active in the mid-2010s that became known primarily for disruptive distributed denial-of-service operations against online gaming services and related platforms. It is closely associated with Lizard Squad and with DDoS-for-hire infrastructure including Poodle Stresser and Shenron Stresser. Public reporting tied members of the group to attacks against gaming ecosystems including Pokémon GO as well as services supporting major console and online game platforms such as PlayStation, Xbox, World of Warcraft, and League of Legends. The group’s activity was principally disruptive and criminal rather than espionage-oriented. Law-enforcement actions in the United States and the Netherlands linked alleged members to computer crime offenses involving DDoS attacks, operation or sale of booter/stresser services, and trafficking in stolen payment-card data. Reporting identified teenage or young adult members and overlap with personas used by Lizard Squad operators, indicating a loosely organized actor set centered on gaming-community notoriety and monetized attack services. PoodleCorp’s demonstrated capabilities center on network-layer service disruption and the commercialization of attack infrastructure. Its operations fit a pattern of targeting high-visibility consumer gaming services for impact and publicity, while also leveraging booter services as a criminal business model. No high-confidence evidence in the supplied facts supports ransomware, extortion, espionage, or advanced intrusion tradecraft beyond DDoS-related activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historical DDoS-focused group mentioned as an example of gaming-related disruption.
Apparent successor or heir to Lizard Squad, associated with DDoS attacks against gaming services and operation of DDoS-for-hire infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.