D1R is a newly emerged cybercriminal ransomware and data-theft extortion group active by mid-2026. The actor has operated a Tor-based leak site and publicly claimed intrusions involving Synopsys, Bosch, and ARM. Reported activity indicates a focus on stealing data and threatening publication to coerce payment, consistent with leak-site-driven extortion rather than confirmed large-scale encryption operations. D1R has claimed that it exploited a vulnerability or logic flaw in a Synopsys web registration workflow to obtain a large corporate client database, then used information derived from that access to pursue downstream victims including Bosch and ARM. In its public claims, the group alleged theft of engineering-related and intellectual-property material and attempted to pressure victims with deadlines for contact before publication. However, key elements of these claims remain disputed: Synopsys stated that its investigation found no evidence of unauthorized access to its systems or customer technical data, and some purported proof published by the actor appeared to match publicly available documentation. As a result, the full scope and authenticity of D1R’s claimed compromises are not independently verified. Despite those uncertainties, D1R is consistently characterized as part of the 2026 wave of newly appearing ransomware and extortion actors. Its observed tradecraft includes public victim shaming via a leak site, alleged exploitation of externally exposed application weaknesses for initial access, theft of sensitive data for leverage, and extortion through threatened disclosure. Known aliases and subgroup designations are not established beyond the name D1R.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly emerged data theft/ransomware group.
Claimed ransomware/data extortion activity involving alleged breaches of Synopsys and Bosch, including posting both organizations on a leak site and threatening publication of allegedly stolen data.
Claimed to have hacked Synopsys, accessed a database of 40,000 entries, and used that information to target Bosch, while allegedly exploiting a vulnerability in Synopsys' website and listing both companies on its Tor-based leak site as part of extortion activity.
New ransomware/extortion group that listed Synopsys and Bosch on its Tor leak site and claimed exploitation of a vulnerability in Synopsys' website to access a corporate client database, threatening to leak stolen data unless a ransom is paid.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.