ExtortionLord is an underground threat actor identity associated with the advertised sale and distribution of allegedly compromised corporate data and access on criminal forums. The persona surfaced in a sales post offering source code, database access, and network access related to KakaoTalk. Investigative reporting links ExtortionLord to a persistent communication identifier that also appeared with the alias Mansoryx on XSS and in Telegram activity, indicating a broader presence across multiple underground platforms. Additional adjacent aliases and identities observed in the same investigative trail include flex and Molot, but available evidence does not support treating all of these names as the same individual or as a single cohesive threat actor cluster. ExtortionLord is best characterized as a cybercriminal access-and-data broker or extortion-adjacent actor rather than a clearly attributed ransomware operator. The actor demonstrated use of underground forums and encrypted or pseudonymous messaging platforms to market purportedly stolen assets and maintain contact channels. The known activity supports capabilities related to initial access and extortion-linked data monetization, specifically the sale of compromised network and database access and sensitive internal materials. Although the ExtortionLord name was found in leaked data associated with LockBit administrative infrastructure, that artifact alone does not establish that ExtortionLord was a LockBit affiliate, administrator, or operator. The actor's precise identity, organizational role, and any formal relationship to LockBit remain unresolved.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.