Ares Leaks is an online criminal data-broker and espionage-as-a-service actor known for trafficking in stolen corporate databases and, more recently, sensitive government documents. The group has publicly advertised classified material for sale and has been linked to the transfer of an apparently authentic internal Russian FSB counterintelligence document to a major news outlet while simultaneously marketing additional stolen documents for purchase. Reporting also indicates the actor sought to buy data related to Hamas military personnel, showing opportunistic interest in conflict-related intelligence. The actor’s activity is characterized primarily by acquisition, brokering, and monetization of stolen information rather than publicly documented disruptive operations. Known behavior includes selling hacked datasets, offering sensitive state documents to buyers, and soliciting access to high-value intelligence. This places Ares Leaks closer to a criminal intelligence marketplace operator than a conventional hacktivist collective or ransomware crew. Available information supports data theft and exfiltration-related tradecraft and financially motivated operations, but does not directly substantiate ransomware deployment, destructive attacks, or a specific nation-state affiliation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Online crime group marketing an espionage-as-a-service style offering; sells hacked corporate databases and sensitive government documents (including alleged FSB materials) via Telegram, with pricing in Monero.
Online crime group offering “espionage-as-a-service,” advertising and selling stolen/hacked sensitive government documents (including Russian FSB materials) and hacked corporate databases, with sales conducted via Telegram and payments requested in Monero.
Threat actor involved in soliciting or purchasing sensitive data related to Hamas.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.