RasCorp Group is an emerging cybercriminal collective associated with ransomware-oriented activity and collaborative leak-site operations. It has been publicly referenced alongside V For Vendetta Cyber Team (VFVCT) and ClayRat as part of a cooperative ecosystem operating under the banner of “United Cyber Operations,” with THE PERSEPHONE serving as a shared platform for publishing datasets and announcements. Available reporting indicates RasCorp functions less as a fully independent intrusion set and more as a coordinating and business-facing component within a broader alliance structure. RasCorp has been linked to Telegram-based recruitment, coordination, and partner outreach. Its communications have sought individuals with experience in malware development, networking, infrastructure management, scripting, and specifically ransomware operations. Within the alliance model described in observed communications, RasCorp was presented as handling business operations and coordination, while partner groups contributed tooling and operational capabilities. This suggests a role centered on relationship management, recruitment, and operational support rather than attribution to a distinct malware family or a clearly documented standalone campaign set. Known aliases include RasCorp and rascorp_group. RasCorp has also been associated with personas tied to administrative and business-lead functions in Telegram communities, including individuals involved in ransomware-team recruitment, credential-related discussions, and promotion of remote-access tooling such as G-700 RAT through adjacent channels. The group appears to rely on shared underground infrastructure and interconnected communication channels rather than a single centralized organization. High-confidence evidence supports characterizing RasCorp as an early-stage collaborative cybercrime actor with ransomware-oriented recruitment and leak-platform participation, but currently available information does not establish a confirmed nation-state affiliation, a definitive country of origin, or a fully documented victimology profile.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-focused group operating primarily through Telegram, promoting recruitment, partnerships, and coordination. It appears to serve as the business and coordination arm within a broader alliance.
Named as one of the groups collaborating on THE PERSEPHONE shared leak platform under a joint operational environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.