JunkyTDS is a traffic distribution system operator associated with the criminal malware delivery ecosystem around SocGholish. It has been identified as an affiliate that sold web traffic to the SocGholish framework, helping route selected victims from compromised websites into staged malware delivery chains. In this role, JunkyTDS functioned as part of the traffic acquisition and filtering layer used to monetize or operationalize compromised web traffic for downstream malware deployment. The actor’s observed role is tied to initial access and malware delivery rather than a standalone ransomware brand or named intrusion set. Its activity is consistent with reconnaissance and filtering of inbound victim traffic, selective redirection, and support for broader post-compromise ecosystems operated by other criminal actors. The available evidence directly supports JunkyTDS as an affiliate or enabling component in the SocGholish ecosystem, alongside other traffic sellers such as TA2726 and Parrot TDS. High-confidence public attribution to a specific country, named sub-groups, or independently documented victimology beyond this affiliate role is currently not available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.