Crimson Collective is an emerging cyber extortion group first observed in September 2025. The group is associated with data-theft extortion rather than confirmed ransomware encryption activity, and has publicly claimed intrusions affecting Red Hat Consulting, Nissan Fukuoka Sales through a Red Hat-managed environment, and Brightspeed. Reporting also links the group to targeting AWS and other cloud-centric environments to steal data and pressure victims into payment. Observed tradecraft centers on credential abuse, cloud and SaaS exploitation, and large-scale secret discovery. In one documented intrusion, the actor leveraged an exposed GitHub personal access token, used TruffleHog to scan repositories for credentials and sensitive data, accessed Azure resources with discovered client secrets, and used Microsoft Graph API calls to authenticate, enumerate, and exfiltrate data. The same activity included attempts to modify repositories to harvest secrets committed in the future. Separate reporting ties the group to abuse of leaked cloud credentials in AWS environments, privilege escalation through creation of new privileged identities, reconnaissance via native cloud APIs, and exfiltration using cloud-native storage and snapshot mechanisms. Across incidents, Crimson Collective has relied heavily on valid accounts and legitimate administrative tooling rather than bespoke malware. The group’s operations are characterized by theft of sensitive enterprise and customer data followed by public coercion, sale offers, or auction-style monetization. It has used public leak and messaging channels to advertise stolen datasets, threaten disclosure, and pressure victims. Crimson Collective has also been associated with adjacent criminal clusters including CryptoChameleon and with collaboration claims involving the ShinyHunters-linked Scattered Lapsus$ Hunters collective during extortion activity against Red Hat. High-confidence reporting supports Crimson Collective as a financially motivated cyber extortion actor focused on cloud-hosted data, secrets, and enterprise repositories.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromised Red Hat Consulting’s GitLab instance and obtained customer credentials and secrets committed to the repository.
Cyber extortion activity involving compromise via an exposed GitHub Personal Access Token, use of TruffleHog to scan repositories for secrets, access to Azure cloud storage through discovered client secrets, Microsoft Graph API-based authentication/enumeration/data exfiltration, and attempted malicious code injection into GitHub repositories to harvest future secrets.
Data-theft/extortion group using Telegram to announce breaches, post samples as proof, and threaten to release/sell large customer datasets.
Cybercrime group claiming intrusions and data theft, including alleged theft of large volumes of residential PII; previously associated (per the article) with breaching Red Hat private GitHub repositories.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.