FSociety is a name associated with multiple unrelated contexts, including a fictional hacking collective from Mr. Robot and a real-world cybercrime and hacktivist label observed in 2024–2026. In the real-world threat landscape, FSociety has been identified as a ransomware-as-a-service operation linked to the Flocker ransomware. The group has used victim shaming and staged disclosure on leak infrastructure to pressure organizations during negotiations, indicating extortion-centric operations. FSociety has also appeared in politically charged messaging, including public threats calling for cyberattacks against Israel and the United States during the March 2026 Iran-Israel-US conflict, although no technical evidence of active operations accompanied those specific threats. Reporting has also associated personas linked to FSociety with Bjorka and references to Babuk2 ransomware, suggesting overlap or branding adjacency within broader cybercriminal and hacktivist ecosystems. Because the FSociety label is used inconsistently across fictional, criminal, and hacktivist contexts, attribution should be handled carefully. High-confidence reporting supports FSociety’s involvement in ransomware/extortion activity and public influence-oriented threat messaging, but does not establish a coherent nation-state designation or a fully resolved organizational structure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor that issued a coercive deadline threat during the conflict escalation.
Threat-signaling and mobilization-focused actor using conflict moments for recruitment and calls for cyberattacks against Israel and the US.
RaaS group operating Flocker and using staged victim exposure tactics; hinted at collaboration with Funksec.
Referenced as a linked hacktivist persona associated with individuals operating Babuk 2 and connected to FunkSec’s ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.