DeathNoteHackersPH, also tracked as DNH, is a threat actor associated with a claimed data leak targeting Viva Communications, Inc. in the Philippines. The actor publicly asserted that it had obtained and released internal corporate information from the victim organization, including business documents and email-related data. The reported activity aligns with data exposure and theft-oriented intrusion behavior rather than ransomware deployment, with the actor allegedly distributing the material freely rather than using encryption-based extortion. Based on the available reporting, the incident remains unverified, and there is insufficient high-confidence information to attribute the actor to a nation state, define a broader campaign history, or establish additional sub-groups. The observable behavior in this case supports assessment of exfiltration and post-compromise publication of stolen information, with potential downstream risks including phishing, impersonation, and social-engineering abuse against the victim and its partners.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.