Zu1f1q4r is an underground data-sale persona operationally linked to a broader cluster that includes the aliases ModernStealer, PriorOps, and the Telegram identity Sassoon Don. The cluster has advertised alleged military, government, intelligence, nuclear, aerospace, and defense-related material on dark web forums and Telegram, with repeated overlap in contact infrastructure indicating an operational relationship. Available evidence supports linkage through reused contact identifiers, but does not conclusively establish whether these aliases represent a single operator, a coordinated group, or multiple actors sharing communications channels. Posts attributed to Zu1f1q4r advertised alleged Pakistan military procurement data, Intelligence Bureau material, and Federal Investigation Agency documents. Across the wider linked cluster, listings also referenced alleged material connected to Pakistani defense and science institutions, Bangladesh military entities, Chinese military personnel data, U.S. defense-related bodies, and other government or military subjects. The activity is best characterized as underground leak-sale and solicitation activity rather than a confirmed malware campaign or a verified series of intrusions. The available reporting explicitly does not confirm that the named organizations were actually breached or that the advertised data was authentic. The actor cluster’s tradecraft, as directly supported, centers on underground marketplace operations, use of persistent contact identifiers across multiple aliases, and solicitation or offering of purported sensitive data. This demonstrates reconnaissance of illicit markets, spoofing or misrepresentation risk in leak claims, and an apparent focus on acquiring or monetizing sensitive government and defense information. The dominant motivation appears financial, based on repeated sale-oriented postings for alleged stolen or classified material.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A related underground seller identity tied by a shared Session/contact trail to listings involving Pakistan military procurement and government documents. The content explicitly cautions that the overlap does not prove Zu1f1q4r and ModernStealer are the same operator.
Forum identity operationally linked to ModernStealer through a shared Session ID, used in multiple Pakistan-focused listings involving alleged military procurement, intelligence, and law-enforcement documents.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.