Sasha is a bulletproof hosting–backed cybercriminal infrastructure cluster associated with large-scale phishing and related illicit online operations. It has been linked to phishing campaigns impersonating public-service and parcel-delivery brands, including NHS Covid Pass and USPS-themed lures, to harvest victims’ personal information, payment card data, and billing details for fraudulent use. The infrastructure has also been associated with malware command-and-control hosting, Magecart-style web skimming activity, and cryptocurrency scams. Operationally, Sasha is characterized by rapid domain turnover, newly registered phishing domains, and hosting patterns consistent with resilient bulletproof hosting services. The infrastructure has been observed rotating IP addresses and moving domains between Russian hosting providers and registrars in ways that complicate takedown efforts and obscure backend systems. Reported phishing workflows commonly impersonate trusted organizations, present fake registration, tracking, or redelivery processes, and request small fees as a pretext for stealing payment information. Known activity includes campaigns targeting individuals in the United Kingdom through fake NHS Covid Pass registration pages and campaigns targeting parcel recipients through USPS-themed delivery and redelivery phishing pages. The cluster’s use across phishing, malware support infrastructure, web skimming, and cryptocurrency fraud indicates a financially motivated criminal ecosystem rather than a nation-state espionage actor. No verified sub-groups are established from the available information beyond the infrastructure label Sasha itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
70 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named phishing infrastructure cluster associated with NHS Covid Pass-themed credit card phishing domains, likely used to harvest personal and payment card data.
A named activity cluster associated with a bulletproof hosting network used to support phishing infrastructure, malware command-and-control domains, web skimming, and cryptocurrency scams.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.