Who's moving, and how fast. Mallory tracks named threat actors across vendor reports, researcher analysis, and underground chatter, then surfaces the ones picking up momentum right now.
Ranked by Mallory's mention-velocity model across sources.
Storm is a purported ransomware threat group associated with a series of publicly reported victim claims in August and September 2026. Its activity has been linked to organizations in the United States, Australia, Canada, and the United Kingdom, including entities in financial services, health care, technology, government, defense contracting, agriculture, construction, and transportation. Reported victims include municipal government, defense-sector, insurance, auto-financing, health-care, agricultural, automotive-dealership, aerospace-services, and petroleum-facility construction organizations. Storm appeared among the more active groups in weekly ransomware-claim tracking during August 2026. Available reporting does not establish the malware family used, intrusion methods, use of encryption, data theft or publication, ransom demands, payment outcomes, or other technical tradecraft. The victim claims and attribution to Storm are not independently validated.
SALTY SPIDER is a financially motivated Russian cybercrime group assessed to operate from the Republic of Bashkortostan, Russia. It develops and operates Sality, a long-running polymorphic file-infector that evolved into a peer-to-peer botnet and malware-delivery platform. SALTY SPIDER is also associated with the community identifiers Kukacka, KuKu, SalLoad, Kookoo, and SaliCode. Sality propagated through infected executable files, network shares, removable media, and file-sharing systems. The botnet has distributed payloads supporting credential theft, spam delivery, proxy services, network exploitation, and distributed denial-of-service attacks. In its later operations, its principal payload was EggJagger, a cryptocurrency clipboard hijacker that substitutes copied cryptocurrency wallet addresses to divert payments. The actor has conducted financially motivated activity against cryptocurrency-related services and has also used Sality-delivered DDoS payloads against targets in Ukraine and Russia. In August 2026, an international law-enforcement and private-sector operation disrupted Sality’s peer-to-peer control infrastructure and prevented the operator from issuing new commands or delivering further payloads; previously compromised systems and payloads still require remediation.
Luna Moth, also known as Silent Ransom Group (SRG), Silent Ransom, Chatty Spider, Storm-0252, and UNC3753, is a financially motivated, Russia-linked extortion group. The group conducts social-engineering campaigns, including fraudulent subscription-renewal lures and telephone-based impersonation, to persuade targets to install legitimate remote monitoring and management or remote-access software. It uses this access to conduct reconnaissance, collect and exfiltrate data, and extort victim organizations. FBI reporting has also associated SRG with impersonating IT personnel to gain physical access to victim offices, steal files, deploy malware, escalate privileges, and return later to extort victims. Luna Moth has targeted organizations in the United States, including law firms and other professional-services organizations. Its operations are principally associated with data-theft extortion rather than confirmed file-encryption activity.
ChenLun is the operator of Outsider, a Phishing-as-a-Service platform also known as 局外人. Outsider supplies affiliates with customizable phishing templates, campaign administration, real-time victim interaction, stolen-data storage, redirect controls, and configurable multi-factor-authentication collection flows. From December 2025 through May 2026, the operation generated more than 100,000 phishing pages targeting victims in at least 54 countries, principally through SMS phishing. Its template library impersonates financial and brokerage services, telecommunications providers, postal and shipping services, government and toll services, and e-commerce and technology brands. Outsider supports adversary-in-the-middle phishing workflows that collect account credentials, payment-card data, personal information, PINs, and SMS-, email-, application-, and PIN-based MFA challenges. The platform can capture victim input before form submission, maintain live communications between victim pages and operator panels, track victim and device activity, and solicit additional payment cards. It also incorporates browser-analysis disruption, bot and security-crawler detection, and test-card filtering. A Singapore-focused campaign impersonated the Land Transport Authority to collect vehicle-registration and telephone data before presenting fraudulent payment workflows; collected phone numbers were intended to facilitate later interception of SMS authentication codes. ChenLun marketed and supported Outsider through a Telegram ecosystem comprising update, affiliate, discussion, sales, and support channels. Law-enforcement and private-sector disruption activity in June 2026 targeted Outsider infrastructure and associated assets, but affiliates continued deploying new phishing pages afterward.
Vexy Ransomware is a ransomware threat actor reported to have targeted organizations in Ecuador and Brazil, including a fast-food franchise operation and an adhesive-tape and adhesives manufacturer. Publicly available reporting attributes ransomware attacks against these organizations to the group. Its origin, operating location, malware implementation, intrusion methods, extortion model, and other operational capabilities are not established.
The Gentlemen is a Russia-linked ransomware-as-a-service (RaaS) operation, tracked by Sophos as GOLD SHERWOOD and also known as Storm-2697. Publicly active since 2025, it is assessed to have emerged from ArmCorp, a former Qilin affiliate operation, following disputes over ransom-payment handling. The operation is associated with the handles hastalamuerte and zeta88, which are assessed as belonging to its leader and administrator. The Gentlemen recruits and supports affiliates that conduct high-volume enterprise ransomware and extortion operations. The group primarily conducts double-extortion attacks: affiliates obtain access through exposed or unpatched firewall and remote-access infrastructure and stolen VPN credentials; escalate privileges; map systems, data stores, and backup infrastructure; exfiltrate selected data; impair security products and recovery capabilities; and encrypt victim environments. Affiliates use legitimate credentials and RDP for lateral movement, establish fallback remote access, alter privileged accounts, disable or weaken endpoint protections, tamper with backup services, and may clear event logs. The operation has used vulnerable drivers to disable endpoint defenses and has deployed ransomware locally, through network shares, and domain-wide. Associated activity also includes credential dumping, DLL sideloading, and the TukTuk cross-platform remote-control framework, which supports command execution, file management, host reconnaissance, screen capture, and credential collection through deceptive prompts. The Gentlemen has claimed victims globally, with particular activity against organizations in the United States and United Kingdom. Manufacturing, technology, and healthcare are prominent targeted sectors. Its criminal leak site is used to publish victim claims and threaten release of stolen data. Victim totals and some individual victim attributions are based on self-reported criminal claims and are not necessarily independently verified.
Hamas is a Palestinian Islamist militant and political organization that has controlled the Gaza Strip since 2007. Its military wing, the Izz ad-Din al-Qassam Brigades (also known as the Al-Qassam Brigades), conducts armed operations against Israel. Hamas claimed responsibility for the October 7, 2023 attacks on Israel and has used rocket attacks and propaganda to threaten Israeli targets and influence public perceptions of the conflict. Hamas has conducted cyber-enabled intelligence collection against Israeli military personnel. A documented mobile espionage campaign used fabricated social-media personas and trojanized Android applications themed around dating and sporting events to target Israeli soldiers. The malware collected device-resident information and enabled remote activation of cameras and microphones, yielding intelligence on military facilities and armored vehicles. Hamas has also been attributed to a satellite-broadcast hijacking operation that inserted Hebrew- and Arabic-language threats and propaganda into an Israeli television broadcast. The organization operates cryptocurrency-based fundraising infrastructure supporting the Al-Qassam Brigades. Investigations have identified donation, operational, consolidation, and transaction-fee funding wallets, as well as use of cross-chain bridges, single-use donation wallets, over-the-counter brokers, and exchanges to move and obscure funds. Hamas-linked online infrastructure has also been used to solicit donations, recruit supporters, and communicate with adherents. Hamas has attempted to activate operational networks in Europe and has been linked to attempted activity in Germany and Denmark. It has received support and financial connections from Iranian-aligned networks, including reported transactions involving the Islamic Revolutionary Guard Corps.
Kimsuky is a North Korean state-aligned cyberespionage group primarily focused on South Korean interests, with documented targeting in Japan and the United States. It is also tracked as APT43, Black Banshee, Emerald Sleet, SharpTongue, Sparkling Pisces, Springtail, TA406, TA427, Thallium, and Velvet Chollima. The group conducts spearphishing operations using topical and business-themed lures, commonly delivering malicious Windows shortcut files that present decoy documents while executing scripts and payloads in the background. Kimsuky has targeted personnel associated with the nuclear-power sector, cryptocurrency organizations, groupware developers and their customers, and organizations of strategic interest. Kimsuky operations use PowerShell, VBScript, JavaScript, scheduled tasks, cloud services, and legitimate remote-access software to establish persistence and maintain control. Documented activity includes host and security-product discovery, process discovery, collection and exfiltration of Thunderbird, Outlook, and Gmail data, keylogging, and deployment of malicious browser extensions for webmail surveillance. The group has abused Chrome Remote Desktop and AnyDesk, including using UAC-bypass techniques and concealment of remote-access tooling. It also deletes artifacts, obfuscates scripts, rotates command-and-control infrastructure, and uses cloud-hosted services for command delivery and data exfiltration. In 2026, Kimsuky-linked activity included a trojanized cryptocurrency trading platform that delivered a customized Xeno RAT and used staged, memory-resident payload execution. Kimsuky's dominant mission is espionage, though its cryptocurrency-focused activity reflects an expansion into financially oriented targeting.
FulcrumSec is a financially motivated data-extortion group active since at least 2025. Also associated with the alias SeesawSec, it conducts data-theft operations and pressures victims through ransom demands and threatened or actual public disclosure of stolen information, rather than relying on system encryption. The group has claimed attacks against organizations including Manchester Airports Group, Novo Nordisk, LexisNexis, Avnet, and Global Schools Group. Its claimed thefts have included customer, business, research, and other confidential data, which it has published through a leak site when victims did not meet extortion demands. FulcrumSec has reportedly used large language models to analyze complex exfiltrated datasets, identify high-value information for negotiation leverage, and prepare more persuasive English-language extortion communications. In the Manchester Airports Group incident, the group claimed access through exposed third-party platform credentials embedded in client-side web resources; that claimed access vector was not independently verified.
Earth Berberoka, also known as GamblingPuppet, is a Chinese-speaking threat cluster documented since 2022 for intrusions against online gambling platforms serving Chinese-speaking users. The cluster has deployed Linux backdoors including Xnote and has been associated with HelloBot and CoinLess-related tooling. Its operations have used gambling-focused lures and infrastructure masquerading as trusted technology brands. Gambling Goblin, a Chinese-speaking cybercrime cluster that compromises Brazilian web servers to serve gambling-related phishing and search-fraud content, has been assessed with medium-to-high confidence as linked to Earth Berberoka based on overlapping tooling, operator artifacts, infrastructure, Chinese-language material, and operational tradecraft. Associated post-compromise tooling supports remote administration, credential harvesting, reconnaissance, tunneling, SSH credential attacks, persistence, and defense evasion on Linux systems.
Gambling Goblin is a Chinese-speaking cybercrime cluster conducting gambling-focused phishing and search-engine-optimization fraud. Active since at least mid-2025, it has compromised Linux Apache web servers belonging primarily to Brazilian government and educational organizations, as well as commercial, health-care, and media entities. The group abuses the reputation of compromised domains to selectively reverse-proxy visitors to fraudulent, localized gambling and sports-betting pages impersonating major application-distribution platforms. Its infrastructure also supports Vietnamese-, Spanish-, and English-language content and rapid domain rotation. The group installs custom Apache modules compiled directly on compromised servers. These modules selectively proxy or inject attacker-hosted content, remove Content Security Policy protections, and cloak responses according to request paths, referrers, browser attributes, and client characteristics. Deployment includes removal of build artifacts and timestamp manipulation to evade detection. Associated Linux tooling includes downloaders, backdoors, remote-access malware, credential-harvesting utilities, SSH credential-testing tools, and reconnaissance agents. These capabilities support remote command execution, file transfer, tunneling and pivoting, SSH-key and shell-history collection, credential theft, service-based persistence, process and service masquerading, network scanning, and post-compromise payload delivery. Gambling Goblin is assessed with medium-to-high confidence to be connected to Earth Berberoka, a Chinese-speaking cluster previously associated with gambling-sector operations and Linux remote-access tooling.
Marak is a cybercriminal group publicly linked to intrusions against French healthcare and related public-service ecosystems. French authorities announced arrests of five suspects associated with the group, with reported ages ranging from 16 to 22. The group has been accused of targeting healthcare establishments, medical-sector companies, and a messaging service used by French customs. The investigation associated with Marak began after a July 2025 intrusion into a private hospital in Saint-Étienne. Authorities stated that the attackers exploited a human weakness in the authentication process for dematerialized professional cards, compromised a physician account, and used that access to steal large volumes of patient data. The activity was further linked to targeting of the national health-insurance system, e-health services, and customs-related users, with authorities alleging exfiltration of nearly four million patient records overall. Marak’s known activity, based on high-confidence reporting, is centered on unauthorized access and theft of sensitive data rather than ransomware deployment or public extortion operations. The group’s victimology indicates a focus on French healthcare and adjacent government-linked services, and its operations demonstrate initial access through social engineering or impersonation-related abuse of authentication workflows followed by data theft and post-compromise exploitation.
Mushr00w is a financially motivated threat actor identity associated with website defacements and a Telegram-based marketplace for webshell access, exploits, and related services. The identity has been linked to defacements of Malaysian and Ukrainian government websites and to the private ZeroDay Commerce Telegram community, where participants advertised access to compromised websites, including education- and government-themed domains. Marketplace posts offered webshell access with capabilities such as terminal use and file upload, modification, and deletion, and used commercial practices including escrow, short-term guarantees, and refunds. Mushr00w was also jointly presented with other marketplace participants in offers for shell access and related services, although a later public dispute indicated a separation from one associate. Mushr00w branding appeared on a PHP webshell used in exploitation of CVE-2026-14894, but branding alone does not conclusively attribute that exploitation activity to Mushr00w. Known associated identities include the ZeroDay Commerce contacts and affiliates operating under the handles VX-encoded and a separate co-seller identity.
Nightmare Eclipse is an anonymous exploit developer and uncoordinated vulnerability-disclosure actor focused primarily on Windows, Microsoft Defender, and adjacent Windows security components. Known aliases include Chaotic Eclipse, Dead Eclipse, and MSNightmare. The actor has publicly released proof-of-concept tools including BlueHammer, RedSun, UnDefend, YellowKey, MiniPlasma, GreenPlasma, RoguePlanet, GreatXML, LegacyHive, and ShieldBreak, often shortly after Microsoft Patch Tuesday releases and without coordinated vendor disclosure. Public identity and country of origin are unknown. The releases demonstrate local privilege escalation, abuse of privileged Microsoft Defender scanning, remediation, quarantine, and update workflows, NT Object Manager manipulation, Cloud Files abuse, opportunistic-lock race control, reparse-point redirection, offline registry-hive modification, and Windows Error Reporting task abuse. BlueHammer was associated with access to local credential material and elevation to SYSTEM. RedSun, RoguePlanet, and ShieldBreak demonstrate SYSTEM-level execution through Defender-related privileged file operations and Windows workflow abuse. LegacyHive demonstrates cross-user registry-hive redirection through Windows profile-loading behavior. GreatXML is a post-compromise BitLocker recovery-environment bypass and persistence technique requiring prior administrative access. UnDefend targets Defender update and protection mechanisms for defense evasion. Several releases were assigned CVEs or subsequently addressed by Microsoft, including CVE-2026-33825, CVE-2026-41091, CVE-2026-45498, and CVE-2026-50656. Earlier tools attributed to the actor, including BlueHammer, RedSun, and UnDefend, have been reported in real-world intrusion activity. Nightmare Eclipse has also published alleged local privilege-escalation proof-of-concepts affecting third-party endpoint-security products.
Krybit is a ransomware threat group active in 2026. It has made ransomware and extortion claims involving organizations in multiple regions and sectors, including healthcare, financial services, public administration, wholesale distribution, transportation and logistics, professional services, education, and retail. Reported victims include healthcare and cancer-care providers in India and Guatemala, a financial-services company in India, a Gabonese public administrative institution, and organizations in Thailand, Vietnam, and Bhutan. Krybit was reported to have made 25 ransomware claims in July 2026 and 13 claims during late August 2026. Available reporting does not establish Krybit's origin, malware implementation, access methods, encryption activity, data theft, or operational model. Individual victim claims have not been independently verified.
ShinyHunters is a financially motivated cybercrime and data-extortion group, also known as Bling Libra, UNC6040, and UNC6240. It has conducted identity-focused social-engineering operations against organizations’ cloud and SaaS environments, with significant reported activity against healthcare-sector entities. Its observed and reported tradecraft includes reconnaissance of employees and business functions; voice phishing, voicemail, and email phishing; impersonation of internal IT or help-desk personnel; and use of look-alike corporate login sites. The group has been linked to reverse-proxy phishing workflows intended to capture credentials, MFA approvals or tokens, and authenticated web sessions. Following identity compromise, operators pivot through identity-provider single sign-on dashboards to connected SaaS services, including Microsoft 365, SharePoint, Salesforce, and Snowflake, and exfiltrate sensitive data and internal communications. ShinyHunters operates principally as an encryption-less pay-or-leak extortion actor: it threatens public disclosure of stolen data, uses a leak site, and has publicly claimed intrusions involving healthcare, medical-technology, software-and-services, and food-production organizations. Multiple high-profile victim claims, including claims involving healthcare companies, remain subject to victim-side forensic confirmation of attribution, access paths, data scope, and record counts.
Dark Caracal is a Lebanon-linked cyberespionage threat group associated with Lebanon’s General Directorate of General Security. Active since at least 2012, it has targeted government and military entities, businesses, journalists, activists, and individuals across multiple regions, including Latin America, Europe, Asia, and North America. The group has used phishing, malicious websites, trojanized mobile applications, document lures, and malicious attachments to gain access. Its malware ecosystem includes Bandook, Pallas, and the Go-based GoCaracal framework. GoCaracal supports host profiling, encrypted command-and-control, remote shell access, payload delivery and execution, process injection, file and directory discovery, browser credential and cookie collection, keylogging, SOCKS proxying, concealed browser activity, remote desktop access, and persistence. GoCaracal can obtain replacement off-chain command-and-control configuration from Ethereum smart contracts after repeated primary command-and-control failures. Dark Caracal has also used Windows Registry Run-key persistence, HTTP-based command-and-control, screenshot capture, and collection of files and image folders. In June 2026, the group was assessed with medium confidence to have compromised a Venezuelan communications organization using Spanish-language financial and tax-themed phishing lures, weaponized SVG attachments, GoCaracal, a Delphi loader, and Bandook.
Exilware is a Brazilian, Portuguese-speaking cybercriminal initial access broker (IAB) that operates the Infect Marketplace, also known as Infected Marketplace and Banco de Infects. Active since at least February 2026, it monetizes access to compromised Windows hosts, enabling purchasers to deploy their own payloads and conduct follow-on operations. Exilware is attributed with high confidence as the operator of the BraZetsu framework, which is also assessed to be the same initial-access malware framework tracked as AgenteV2. BraZetsu is a modular Python-based Windows framework used to establish and maintain access, profile victims, and identify commercially valuable systems. It performs host and network reconnaissance; enumerates system, process, application, network-service, browser, and enterprise-environment data; captures screenshots; and supports interactive command execution and deployment of additional worker modules. It collects browser histories, digital certificates, financial remittance files in Brazil’s CNAB format, recently opened files, and active-window information. The framework searches for indicators of banking, ERP, e-commerce, industrial-control, backup, development, and security environments, and uses collected intelligence to assess and price compromised hosts for marketplace sale. It maintains persistent command-and-control connectivity through WebSocket communications and has used dead-drop configuration retrieval. Reports indicate server-side AI-assisted triage and victim-value assessment, while the full role of AI in the operation is not established. Exilware has principally targeted Brazilian organizations and broader Iberian and Latin American entities, including financial, e-commerce, industrial, government, law-enforcement, healthcare, logistics, insurance, ISP, and technology environments. Compromised hosts in the United States have also been advertised, but this does not establish a sustained geographic focus outside its primary regional targeting. Initial delivery has not been conclusively determined; social-engineering lures masquerading as routine software or notifications have been assessed as the likely access vector.
Blind Eagle, also known as APT-C-36, is a Spanish-speaking, likely Colombia-based cybercriminal threat actor active since at least 2018–2019. It primarily targets organizations in Colombia and other South American countries, using sustained Spanish-language spam and spearphishing campaigns against government, financial, health care, telecommunications, and energy organizations. Other reported aliases include APT-Q-98 and TAG-144. Blind Eagle commonly uses impersonation lures themed around Colombian government, judicial, tax, traffic-enforcement, banking, and personal matters. Its delivery chains have included password-protected archives, malicious documents containing embedded scripts or macros, and location-filtered shortened links that redirect selected victims to malware downloads while presenting benign content to others. The group has repeatedly rotated delivery infrastructure, URL-shortening services, and payload families to hinder detection. The actor has deployed commodity and open-source remote-access tooling including AsyncRAT, BitRAT, LimeRAT, njRAT, Remcos, DcRat, Quasar RAT, and related loaders and crypters. Observed tradecraft includes scheduled-task persistence disguised as legitimate software activity, hidden PowerShell execution, VBScript-based document execution, process hollowing, and DLL side-loading. Blind Eagle has also used commercial or publicly available packers, crypters, and remote-access tools, including HeartCrypt, PureCrypter, and HijackLoader. Its campaigns are assessed as primarily financially motivated rather than espionage-oriented.
Panzer is an emerging purported ransomware-as-a-service (RaaS) operation. It has advertised affiliate recruitment on Russian-speaking cybercriminal forums, an affiliate revenue-sharing model, automated administration, ransomware builds for Windows, Linux, ESXi, and FreeBSD, and victim-negotiation and leak-site capabilities. Its advertised platform includes data-publication features intended to pressure victims and configurable locker functionality with anti-detection features. No public malware sample has been available, and Panzer’s operational claims and reported victim attributions have not been independently verified or linked to confirmed attacks.
Nexus Team is a relatively unknown, provisionally identified IoT-botnet operator associated with a Mirai-derived malware family named Nexcorium. The attribution is based on a self-identifying custom HTTP request header observed during exploitation activity; the operators’ identity, origin, and broader affiliations remain unconfirmed. The campaign compromises vulnerable TBK digital video recorders through CVE-2024-3721, an OS command-injection vulnerability, and deploys payloads built for multiple Linux architectures. Nexcorium also propagates through Telnet brute forcing using common default credentials and incorporates exploitation of CVE-2017-17215 affecting Huawei HG532 devices. The malware uses scanner, watchdog, and attack components; establishes redundant persistence through init configuration, startup scripts, systemd services, and cron; performs integrity checks and self-replication; and deletes its initially executed binary to hinder analysis. Compromised devices receive commands from centralized infrastructure and can conduct distributed denial-of-service attacks using multiple UDP and TCP flood methods, as well as application-layer and query-flood techniques.
Wallstreet is a ransomware group first observed emerging in 2026. It has claimed or been attributed with ransomware and associated data-breach incidents against organizations in the United States and Ecuador. Reported U.S. victims span grocery retail, municipal and law-enforcement bodies, hospitals, education services, manufacturing, and automotive-service administration. Its reported Ecuadorian victim operated medical-assistance and health-insurance services with operations in Ecuador and Colombia. Public reporting does not establish Wallstreet’s geographic origin, malware implementation, initial-access methods, whether it encrypts victim environments, or whether it operates a leak site or uses data-theft extortion.
UTA0533 is an unattributed threat cluster tracked by Volexity for zero-day exploitation of SonicWall Secure Mobile Access (SMA) 1000 appliances beginning in June 2026. The actor chained CVE-2026-15409 and CVE-2026-15410 to obtain unauthenticated access to localhost-restricted services, execute commands, and gain root-level control of compromised appliances. No public attribution links UTA0533 to a known threat group or country, and its motivation remains undetermined. UTA0533 deployed appliance-specific tooling including KNUCKLEBALL, ROOTRUN, the Suo5 proxy, and the ORANGETAIL Behinder-like Java web shell. Its tradecraft included injecting malicious Java payloads into legitimate SonicWall processes, modifying startup and web-routing configurations for persistence and concealment, and maintaining privileged execution capability. The actor captured unencrypted LDAP traffic to collect credentials, accessed stored or cached credentials and authentication material on affected gateways, and attempted lateral movement into victim networks. Available evidence indicated stronger capability in compromising and persisting on SMA appliances than in successfully expanding access to downstream systems. Later ransomware exploitation of the same vulnerability chain, including activity associated with INC Ransomware, has been reported, but UTA0533 itself remains separately tracked and unattributed.