KING is a cybercriminal persona associated with the Telegram handle Real_King_Engine and the ISAL Framework, a paid training program focused on operationalizing WordPress intrusion workflows at scale. The actor is linked to instruction and enablement of students who build attack infrastructure, automate exploitation, deploy web shells, and conduct large-scale credential harvesting and account takeover operations against WordPress sites. Available reporting indicates that a recovered WordPress attack toolkit and botnet infrastructure were operated by a student rather than directly by KING, but the tooling and exploit workflow were promoted through KING’s course ecosystem and branding. The activity associated with KING centers on internet-scale targeting of WordPress environments. Reported tradecraft includes reconnaissance and username enumeration, brute-force attacks against administrator accounts, exploitation of CVE-2025-15001 in the FS Registration Password plugin for unauthenticated account takeover, deployment of PHP web shells, disabling of security plugins, and database-resident persistence within WordPress. The operational model also used distributed worker nodes, multiple command-and-control channels, and automation for shell redeployment and credential collection. The ecosystem tied to KING promoted the use of commercial AI assistants to accelerate exploit generation and attack development. Victimology linked to this activity spans more than 100 countries, with especially prominent impact reported in Brazil, India, and the United Kingdom. Affected sectors included government, education, healthcare, and finance. The actor’s role is best characterized as a cybercrime enabler and trainer whose course material appears to have lowered the barrier for less-skilled operators to reproduce full intrusion chains involving brute force, exploitation, persistence, and credential theft. High-confidence aliases directly supported here are limited to KING.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.