EndZone is a purported ransomware and data-extortion group associated with public claims of compromises affecting U.S. organizations, including AT&T and Accela. The group has claimed to possess sensitive data and threatened public disclosure in an apparent effort to compel victim engagement. Claims of the underlying intrusions, data theft, and attribution have not been independently corroborated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed ransomware intrusion targeting AT&T. The claim states that initial access came through a contractor, followed by prolonged access to VPN and virtual desktop environments, certificate export, and access to Salesforce data using employee and contractor accounts.
Claimed ransomware and data-extortion attack against Accela, alleging theft of more than 50 GB of data, including PII from government-related users and citizen-engagement requests.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.