NullBulge is a cybercriminal threat group that emerged in the first half of 2024, targeting AI-focused applications, gaming communities, and associated software supply chains. It presents itself as a pro-artist, anti-AI hacktivist collective, but its ransomware deployment and sales of stolen credentials, infostealer logs, and OpenAI API keys demonstrate substantial financially motivated activity. Its targets include technology users and entertainment organizations; it publicized leaks of Disney internal Slack data in July 2024. NullBulge distributes malicious code through GitHub and Hugging Face repositories, trojanized Python dependencies, and gaming modifications promoted through community platforms. Its campaigns abused the ComfyUI_LLMVISION extension and distributed malicious BeamNG modifications. Trojanized dependencies masqueraded as legitimate OpenAI and Anthropic libraries, collecting browser data, system information, installed applications, security-product information, and financial data. Python payloads exfiltrated collected information through Discord webhooks, while malicious Lua scripts executed encoded PowerShell to download and run AsyncRAT or Xworm. The group uses these remote-access tools before deploying customized ransomware generated with the leaked LockBit 3.0, also known as LockBit Black, builder. Its ransomware configurations support encryption of local disks and network shares, process and service termination, event-log deletion, and self-deletion. NullBulge also operates data-leak sites and underground profiles to publicize compromises and monetize stolen data and access. Use of the leaked LockBit builder does not establish membership in the LockBit ransomware operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example within a discussion of hacktivism tiers and the concept of state-sponsored proxy operations masquerading as grassroots activism.
NullBulge is known for conducting sophisticated supply chain attacks by weaponizing open-source repositories, particularly targeting AI tools and gaming software. Their operations include exfiltrating data and deploying ransomware through compromised code in popular platforms.
Cybercriminal group targeting AI-centric application and gaming communities through software supply-chain poisoning, trojanized GitHub and Hugging Face repositories, malicious BeamNG mods, credential theft, data exfiltration, and later-stage LockBit ransomware deployment. The group also operated leak sites and claimed responsibility for Disney-related data theft and leaks.
Mentioned as one of several threat actors known to use VenomRAT and AsyncRAT.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.