MindHunter is an underground cybercrime persona active across multiple illicit forums and messaging platforms over a period spanning at least 2022 through 2026. The actor has been associated with the sale of compromised accounts, premium subscription access, proxies, and other illicit digital goods. Correlated activity indicates persistent reuse of the MindHunter branding, contact identities, profile imagery, and cryptocurrency infrastructure across communities including Breached, Altenens, Cracked, Telegram, and Discord. Known aliases and related handles include MindHunter, MINDHUNTER, MINDHUNTER, and a historically linked Telegram identity previously using the Mindhunter_xdd name before later adopting another handle. A Telegram channel associated with the actor, Leak Zone, advertised premium account credentials and access to online subscription services. Forum activity also included advertisements for doxxing-related services or methods. The actor appears to operate primarily as a cybercrime-market seller rather than as a state-directed intrusion set. Available evidence supports involvement in trafficking unauthorized digital access and related services, but does not establish attribution to any nation state. Community accusations of fraud and resale scams have circulated in Telegram, but those allegations remain unverified and should not be treated as established fact.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.