The Com, short for The Community, is a loose, decentralized cybercriminal and violent online ecosystem composed largely of English-speaking minors and young adults. It is not a single centrally directed organization and has no unified ideology, but is commonly characterized by misanthropic, nihilistic, and in some factions accelerationist or violent extremist tendencies. The network operates through overlapping online groups and subcommunities across social media, messaging platforms, gaming services, and closed chats, where members recruit peers, groom victims, coordinate attacks, and trade status through increasingly harmful conduct. The Com has been linked to a broad spectrum of criminal activity spanning cyber intrusion, extortion, sextortion, swatting, fraud, SIM swapping, doxxing, and offline violence. Europol and other authorities describe internal subdivisions including Cyber Com, associated with network intrusions and ransomware activity; (S)extortion Com, associated with coercing minors into producing explicit material, self-harm, and abuse; Offline Com, associated with property damage, assaults, and other real-world violence; and 764, a notorious associated subgroup tied to grooming and blackmail of young victims. Scattered Spider is widely described as a subset or affiliated crew within the broader Com ecosystem, and the Pink extortion brand has also been linked to Com-affiliated activity. Operationally, Com-linked actors are strongly associated with social-engineering-led intrusion tradecraft, including phishing, voice phishing, SMS-based lures, SIM swapping, credential theft, and abuse of authentication workflows. Reported campaigns include enterprise intrusions against major organizations, compromise of cloud environments for large-scale data theft and extortion, and vishing-led Microsoft 365 account takeovers followed by exfiltration from collaboration and storage platforms. Authorities and researchers have also linked Com-affiliated actors to ransomware deployment, data extortion, and leak-site operations. Beyond cybercrime, The Com has been repeatedly associated with severe exploitation of minors. Law-enforcement reporting describes recruitment and grooming of children and teenagers into producing explicit material, self-harm imagery, animal abuse, violent acts, and other coercive content used for blackmail, status-building, and continued control. The ecosystem has also been tied to dissemination of violent propaganda, manuals for grooming, murder, improvised explosives, doxxing, and swatting, as well as livestreaming and redistribution of abuse and assaults. The Com has been linked to high-profile incidents involving retailers, casinos, transportation, telecommunications, and cloud-service customers, and is regarded by European and Anglo-American law enforcement as a global threat landscape rather than a conventional single threat group. Its dominant motivation is criminal and extortion-driven, although some factions also overlap with violent extremist milieus and pursue notoriety, coercion, and status through brutality.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loosely organized cybercriminal network whose members engage in violence, extortion, sextortion, online abuse campaigns, and other cybercrime. In this reference, it is tied to abuse of minors and broader Com-affiliated criminal activity in the U.K., U.S., and Canada.
A loose-knit online cybercrime collective that recruits and grooms children and teenagers through online platforms, coercing them into self-harm, violence, and the production of child sexual abuse material through blackmail. The group is also described as having subgroups involved in sextortion, terrorism-promoting activity, network intrusions, and ransomware attacks.
Cybercriminal collective involved in online blackmail and sextortion of minors, with sub-groups spanning physical violence, sextortion, and cyber intrusions including ransomware activity. The content also says it was previously linked to ransomware attacks against Las Vegas casinos and UK retailers including Marks & Spencer, Co-op, and Harrods.
A sprawling cybercriminal network associated with Moucka and his co-conspirators, involved in extortion, sextortion, violence, and other cybercrime.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.