Fly is a cybercriminal threat actor assessed to be closely linked to Russian Market and likely to be its administrator. Russian Market is an underground marketplace focused on the sale of credentials stolen by infostealer malware, placing Fly within the credential-theft and cybercrime ecosystem rather than a state-sponsored intrusion set. Public reporting associates Fly’s online presence with Russian Market’s infrastructure and with promotion of the marketplace under the handle FLYDED, described as an earlier name associated with Russian Market. High-confidence reporting further links the actor to cryptocurrency flows involving non-KYC exchanges and mixing services, consistent with operational security and monetization practices common in credential-trafficking communities. Based on the available evidence, Fly’s role appears centered on operating, promoting, or supporting a criminal marketplace for stolen credentials rather than conducting disruptive or espionage-driven campaigns directly against named sectors or countries.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Fly is the administrator of Russian Market, a cybercriminal marketplace for selling credentials stolen via infostealers. The actor is involved in promoting and managing the marketplace.
Individual threat actor persona linked to the Russian Market cybercrime marketplace; associated with promotion/operation signals and with wallet infrastructure tied to non-KYC exchanges and mixing services.
Fly is a threat actor associated with the administration of Russian Market, a marketplace for credentials stolen via infostealers.
A threat actor named Fly is discussed in the context of having links to Russian Market’s infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.