Infraud was an internet-based cybercriminal enterprise and carding forum active from 2010 until its disruption by law enforcement. Founded by Sergey Medvedev and Svyatoslav Bondarenko, it functioned as a major marketplace and community for the acquisition, sale, and dissemination of stolen identities, compromised payment card data, personally identifiable information, financial and banking information, malware, and other illicit goods. The group promoted itself as a premier destination for carding and operated supporting criminal services including escrow for digital-currency transactions, vendor screening, and referrals to member-operated automated vending shops. Infraud victimized financial institutions, merchants, and private individuals at large scale. U.S. authorities attributed more than $568 million in actual losses and approximately $2.2 billion in intended losses to the enterprise over roughly seven years, with more than ten thousand registered members by 2017. Members included malware developers and operators; Valerian Chiochiu, an Infraud member, admitted authoring the FastPOS malware and providing guidance to other members on malware development, deployment, and use to harvest stolen data. Infraud’s core activity centered on financially motivated cybercrime, especially trafficking in stolen payment and identity data and enabling fraud against the financial ecosystem. Known associated figures and aliases include co-founder Sergey Medvedev and co-founder Svyatoslav Bondarenko, also known as Obnon, Rector, and Helkern. The enterprise has also been linked in U.S. charging documents to other cybercriminal actors associated with carding forums. Infraud is best understood as a transnational organized cybercrime operation rather than a state-sponsored threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a notorious malware and carding forum tied to Andrey Novak in prior U.S. charges.
Cybercriminal enterprise focused on carding and trafficking in stolen identities, payment card data, banking information, malware, and other illicit goods; it also operated escrow services and vendor screening for criminal marketplace activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.