The Com, also known as The Community, is a loosely affiliated, predominantly English-speaking online criminal ecosystem rather than a single centrally directed threat group. It encompasses thousands of participants, commonly teenagers and young adults, with members operating in the United States, United Kingdom, Canada, and other Western countries. Participants form smaller groups that cooperate, compete, and exchange access, tools, and stolen data through platforms including Telegram and Discord. Its activities span financially motivated cybercrime, cryptocurrency theft, extortion, sexual exploitation, and physical violence; no single motivation characterizes the entire community. The ecosystem has three principal subdivisions: Hacker Com, In Real Life Com, and Extortion Com. Scattered Spider is a prominent cybercriminal subset, while BlackFile is an affiliated extortion group operating through the Redact, Pink, Helix, and Falcon brands. Scattered Lapsus ShinyHunters has also operated within the community. The affiliated 764 network and its offshoots, including Harm Nation and 8884, conduct coercive sexual exploitation and abuse, particularly against minors and other vulnerable people. In Real Life Com includes participants offering physical violence for hire. Cybercriminal participants specialize in social engineering, including help-desk impersonation, voice phishing, SMS phishing, SIM swapping, and abuse of password-reset and multifactor-authentication enrollment procedures. These methods enable credential theft, unauthorized access to enterprise identity and cloud services, lateral movement, data exfiltration, and cryptocurrency theft. Associated groups have deployed partner ransomware and conducted extortion involving stolen data. Victims include organizations in technology, telecommunications, hospitality, retail, financial services, healthcare, transportation, logistics, and consumer goods. Some participants intensify extortion through threats against employees and relatives, doxing, swatting, and physical intimidation. These activities vary substantially across the community and should not be attributed uniformly to every member or affiliated group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A global collective of loosely associated criminal groups with which 764 members are affiliated. Its activities are described as financially motivated, sexual and violent crime; no specific malware or exploitation techniques are identified.
A loose-knit cybercrime collective associated with cyber-enabled extortion, fraud, harassment, and physical violence. Alleged connections to ShinyHunters are disputed and are presented as part of ShinyHunters' stated motivation for pressuring the FBI.
Communauté criminelle citée en raison de l’assimilation contestée de ShinyHunters à celle-ci par le FBI.
Named as the larger self-designated group associated with Scattered Spider.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.