Edbitss is a cybercriminal malware vendor associated with the sale and development of DiamondFox and later GlitchPOS. The actor has been presented as the official DiamondFox vendor and is also linked to the development and promotion of GlitchPOS, a point-of-sale malware family built to steal payment card data from infected systems. Activity attributed to Edbitss spans at least 2015 through 2019, indicating sustained involvement in underground malware development and commercialization. DiamondFox is a modular malware-as-a-service botnet marketed to other criminals with plugin-based functionality supporting credential theft, keylogging, cryptocurrency theft, distributed denial-of-service activity, self-propagation, and tailored post-compromise operations. Its management panel provides infection statistics and per-victim plugin control, and the actor was noted for advertising updates, support, and ongoing product improvements. Edbitss appears to have operated as a vendor rather than merely an end-user, documenting feature changes and maintaining customer-facing sales activity across multiple underground venues. Edbitss is also linked to GlitchPOS, a separate Visual Basic point-of-sale malware project that scrapes payment card Track 1 and Track 2 data from process memory and exfiltrates stolen card data to command-and-control infrastructure. GlitchPOS can register infected hosts, receive tasks, execute commands, update configuration values, and remove itself, demonstrating a mature criminal toolset with both theft and post-exploitation functionality. Strong similarities between the GlitchPOS and DiamondFox administration panels, including reused panel code and interface conventions, support the assessment that the same developer or vendor was involved in both projects. The actor’s tradecraft reflects financially motivated cybercrime centered on malware development, resale, and enablement of downstream criminal operations. Reported capabilities associated with Edbitss-linked tooling include credential theft, keylogging, exfiltration, initial access enablement through malware deployment, post-exploitation tasking, persistence-oriented botnet functionality, distributed denial-of-service support, and cryptocurrency theft. Geographic attribution is uncertain: the actor reportedly claimed to be in Russia and appeared fluent in Russian, while separate infrastructure and web-presence details have also suggested a possible Mexico connection. That ambiguity prevents a definitive origin assessment beyond those possibilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Developer and seller of the GlitchPOS point-of-sale malware, linked in the content to prior development of the DiamondFox L!NK botnet and reuse of DiamondFox panel code for GlitchPOS.
Operator/vendor associated with selling and maintaining the DiamondFox malware-as-a-service offering, documenting updates, providing support, and enabling buyers to run credential theft, espionage, self-spreading, and DDoS-capable campaigns via plugins.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.