Joker's Stash was a long-running cybercriminal carding marketplace focused on the sale of stolen payment card data. Active from 2014 until its announced closure in January 2021, it became one of the most prominent underground shops for card-present and card-not-present records and was widely used to monetize large retail and payment-card breaches. The marketplace was known for advertising major breach datasets and for operating resilient infrastructure, including Tor-based access and blockchain-linked domain services that complicated disruption efforts. Law-enforcement action temporarily seized some proxy infrastructure, but the marketplace reportedly maintained alternate access paths and continued operating until its eventual shutdown announcement. Joker's Stash's activity centered on trafficking compromised financial data for fraud, making it a financially motivated criminal enterprise rather than a state-linked intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prolific carding dump shop that sold stolen payment card data and announced closure after alleged law-enforcement action.
Operates a major underground carding marketplace for buying and selling stolen payment card data, advertising large breach datasets and facilitating CP and CNP fraud.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.