V For Vendetta Cyber Team (VFVCT) is a cybercrime actor associated with leak-site activity, underground forum promotion, Telegram-based coordination, and collaboration with other threat groups. The group has been linked to THE PERSEPHONE, a shared leak and announcement platform presented as a prototype for joint or "United Cyber Operations" involving VFVCT, RasCorp Group, and CrackRat Zone Clay. Available reporting indicates that VFVCT used this ecosystem not only to publicize leaked datasets but also to recruit participants, coordinate operations, and advertise future releases. VFVCT maintained a visible communications presence across underground forums and Telegram channels. A forum account using the VFVCT name referred to THE PERSEPHONE as the group’s website, while Telegram channels and groups associated with the actor were used for recruitment, operational messaging, leak promotion, and discussion of planned database releases. The group also referenced additional infrastructure such as a GitHub Pages presence and anonymous messaging platforms, indicating a distributed and disposable operational model. The actor has claimed campaigns affecting multiple countries in Asia and has been associated with publication of stolen datasets, indicating exfiltration-focused operations. Recruitment messaging referenced ransomware partnerships, suggesting involvement in or aspiration toward ransomware-related activity, but the strongest supported behavior is operation of a leak-centric collaborative hub rather than confirmed standalone ransomware deployment. VFVCT appears to function both as an operational participant and as part of a broader alliance structure in which RasCorp Group contributes business coordination and CrackRat Zone Clay contributes tooling. Known aliases include VFVCT and V For Vendetta Cyber Team.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Member of a Telegram-based cyber alliance with RasCorp and CrackRat Zone Clay, contributing operational and strategic capabilities to the broader ecosystem.
Operates and promotes THE PERSEPHONE leak platform, uses Telegram channels for recruitment, coordination, and promotion of leak activities, and seeks ransomware partnerships within a collaborative ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.