iah6477 is a ransomware threat actor associated with multiple reported intrusions against U.S.-based organizations. Reported victims include entities in the financial services, information technology, and consumer-facing retail sectors. The actor has been linked to ransomware incidents that also involved theft of victim data, indicating extortion activity tied to data exfiltration in addition to ransomware deployment. Based on the available reporting, iah6477 has targeted organizations in the United States and has affected sectors including financials, information technology, and consumer discretionary. Publicly available facts in this dataset do not establish the actor's country of origin, broader tooling, or any confirmed aliases beyond the name iah6477.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against marvin, with reported stolen data size of 2.2 TiB.
Conducting a ransomware attack and associated data breach against Acima.
Conducting a ransomware attack and associated data breach against Regency Centers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.