RaidForums was a major English-language cybercrime forum used for trading breached data, facilitating criminal collaboration, and supporting a broader ecosystem of intrusion, fraud, and extortion activity. After law-enforcement seizure in 2022, BreachForums emerged as its successor. The forum name is sometimes used to refer not only to the platform itself but also to its community of users and associated criminal actors. RaidForums functioned as an online hub for the sale and distribution of stolen data and for interaction among threat actors involved in data breaches and related offenses. Its successor ecosystem overlapped with actors such as ShinyHunters and other rebranding offshoots tied to high-profile data theft and extortion operations. Activity associated with this ecosystem has included exfiltration of stolen information, publication or sale of breached datasets, and extortion based on threats to leak stolen data. Reporting also links associated actors to exploitation of compromised OAuth tokens and other post-compromise abuse. As a forum community rather than a single cohesive intrusion set, RaidForums does not map cleanly to one operator, country of origin, or unified command structure. Its user base was international and included administrators, moderators, and users from multiple regions. The broader ecosystem around its successor forums has been disrupted by arrests and law-enforcement action, but the community has shown persistent rebranding and migration behavior.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.