PriorOps is an underground data-sale persona operationally linked to a broader cluster of aliases involved in advertising alleged military, government, and defense-related information on criminal forums and Telegram. High-confidence reporting ties PriorOps to the same Telegram contact infrastructure used by the aliases ModernStealer, Zu1f1q4r, and the Telegram identity Sassoon Don, indicating an operational relationship among these identities, although available evidence does not conclusively establish whether they are the same individual, a coordinated group, or separate actors sharing communications channels. PriorOps is specifically associated with a listing claiming to offer a database of People’s Liberation Army personnel. More broadly, the connected cluster has advertised alleged material relating to military, intelligence, aerospace, nuclear, and government entities across multiple countries, including Pakistan, Bangladesh, China, Sri Lanka, Ukraine, Central Asian states, and the United States. The activity is characterized by underground marketplace postings and broker-style solicitation for purported sensitive data rather than a confirmed malware campaign or publicly verified intrusion set. The actor’s observed behavior centers on offering or soliciting allegedly stolen information through dark web forums and Telegram, using persistent contact identifiers across multiple posts to maintain continuity between aliases. This supports assessment of capabilities in reconnaissance of underground markets, initial access claims, and exfiltration-related posturing, but the available evidence does not independently confirm the underlying compromises advertised in the listings. The cluster’s targeting pattern is heavily oriented toward government, military, and defense-adjacent organizations, suggesting an espionage-aligned interest profile, though the documented activity itself is primarily the sale and brokerage of purported sensitive data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A related seller identity that used the same Telegram handle associated with the Sassoon Don contact trail, claiming to offer a database of PLA personnel.
Forum identity linked to ModernStealer through use of the same Telegram contact account (Sassoon Don) while advertising alleged PLA personnel data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.