iah6477 is a threat actor associated with reported ransomware-related breaches affecting organizations in the United States. Incidents attributed to the actor during August and September 2026 involved Veritiv, Swagelok, TRC Companies, ProAmpac, MAT Holdings Inc., Marvin, Acima, and Regency Centers. Its reported targets span manufacturing, professional services, technology, financial services, and retail and e-commerce. The incidents carried reported breach volumes ranging from approximately 148 GiB to 4.2 TiB, but these figures do not independently establish data exfiltration. Technical details establishing initial-access methods, malware families, encryption, persistence, or other intrusion techniques are unavailable. The actor's geographic origin, organizational affiliations, additional aliases, and subgroups are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly conducted a ransomware attack against Veritiv, with an alleged 1.9 TiB data breach discovered on September 15, 2026.
The iah6477 ransomware operation claims to have compromised Veritiv in the United States and lists 1.9 TiB of data. The post provides no ransom demand, deadline, attack details, or data samples.
Reportedly conducted a ransomware attack against Swagelok, resulting in a claimed 881.2 GiB data breach discovered on August 29, 2026.
Conducted a ransomware attack against TRC Companies, reportedly involving 4.2 TiB of data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.