ModernStealer is an underground leak-sale identity active on dark web forums and Telegram that has advertised alleged military, government, nuclear, aerospace, and defense-related material from multiple countries. The activity is best characterized as illicit brokering or sale of purported sensitive data rather than a confirmed malware campaign, and the available evidence does not independently verify that the named victim organizations were actually breached. Reported listings referenced entities in Pakistan, Bangladesh, Sri Lanka, the United States, China, Türkiye, Ukraine, and Central Asia, including alleged military procurement records, government documents, aerospace-related material, and nuclear-sector data. ModernStealer has been operationally linked through reused contact infrastructure to the aliases Zu1f1q4r and PriorOps and to the Telegram persona Sassoon Don. Those overlaps indicate a connected cluster of actors or shared infrastructure, but do not conclusively establish whether they are the same individual, a coordinated group, or separate sellers reusing common contact channels. Known associated aliases and personas include Zu1f1q4r, PriorOps, and Sassoon Don. The actor’s observed behavior centers on underground marketplace advertising, solicitation, and attempted monetization of allegedly stolen or classified information, with a strong emphasis on defense and government themes. High-confidence evidence supports data-sale and leak-claim activity, but not confirmed intrusion tradecraft, malware deployment, or verified compromise of the organizations named in the listings.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An underground data-broker/leak-claim actor advertising alleged military, government, nuclear, and aerospace material on dark web forums and Telegram. The reporting links the alias to reused contact identifiers and possible overlap with other seller identities, but stresses the activity consists of alleged data sales and unverified leak claims rather than confirmed intrusions or a disclosed malware campaign.
Underground actor/identity advertising alleged military, defence, government, nuclear, and aerospace-related stolen data and classified documents across forums, including Pakistan-focused and broader military-related offerings.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.