Mosad is an underground data seller and leak-market operator active across multiple cybercrime forums and Telegram communities. The alias has been associated with a coordinated cross-platform ecosystem used to advertise and broker alleged access to government, military, intelligence, law-enforcement, and corporate data. Activity attributed to Mosad has appeared on numerous underground forums, with those forums functioning primarily as visibility and lead-generation channels, while Telegram served as the principal communication and community hub. The actor’s tradecraft is characterized by consistent cross-platform branding, reuse of the same communication identities, and deliberate promotion of linked personas and communities to reinforce a single operational identity. Advertisements attributed to Mosad have included alleged datasets and purported access to compromised corporate environments, including large enterprises. The actor also maintained Telegram channels and grouped communities under Mosad-themed branding, and used those communities to promote additional underground forum profiles. High-confidence reporting supports Mosad as a cybercriminal seller focused on trafficking in allegedly stolen or illicitly obtained data rather than as a confirmed nation-state intrusion set. Although the authenticity of all advertised material has not been independently verified, the operational infrastructure behind the alias appears extensive, deliberate, and consistently maintained. Known associated branding includes Mosad-themed communities such as Mosad Intelligence Agency and InsideMossad.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.