Rayzone is an Israeli commercial surveillance company associated with telecom-signaling-enabled mobile surveillance activity. Investigative reporting has linked the company to leasing access to global telecom signaling networks, a capability consistent with covert tracking of mobile subscribers through SS7 and Diameter abuse. Activity associated with this ecosystem has been assessed as consistent with a centralized, multi-tenant commercial surveillance platform serving government intelligence customers rather than a conventional financially motivated intrusion set. Operations linked to this surveillance model have included long-term location tracking of mobile subscribers by abusing weaknesses in the global telecommunications roaming and signaling trust model. Observed tradecraft includes SS7 and Diameter probing to obtain subscriber identifiers and location data, manipulation of routing metadata to conceal origin and influence message paths, rotation across multiple operator identities and transit networks, and use of spoofed signaling attributes to evade screening and attribution. Related activity has also included SIMjacker-style zero-click SIM exploitation using binary SMS to silently query handset location information and exfiltrate it through the mobile network. The broader activity cluster tied to this ecosystem has targeted subscribers across multiple countries over a multi-year period, including high-profile individuals. The operational pattern reflects espionage-oriented mobile surveillance and post-compromise tracking rather than disruptive or extortion-based operations. Known naming associated with the entity includes Rayzone and Rayzone Group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.