Circles is a commercial surveillance vendor associated with telecom-signalling exploitation and mobile subscriber tracking. It has been publicly linked alongside other interception and location-tracking vendors in discussions of sanctions and telecom surveillance oversight. Activity consistent with this ecosystem includes long-term exploitation of SS7 and Diameter weaknesses to obtain subscriber identifiers, query subscriber location, manipulate routing paths, rotate operator identities across multiple countries, and evade signalling firewalls. Observed tradecraft also includes spoofing signalling metadata, use of third-party interconnect or transit relationships, and multi-stage location-tracking operations against high-profile targets. Related surveillance activity attributed to commercial telecom-surveillance-style operators has also included SIMjacker-style zero-click SIM exploitation using binary SMS delivered through the S@T Browser, followed by covert exfiltration of cell-location data and additional Diameter-based probing. The operational pattern is consistent with centralized, multi-tenant surveillance platforms used to support government intelligence or security customers rather than conventional cybercrime. Circles is widely discussed as part of the commercial spyware and lawful-intercept market centered on covert mobile surveillance, especially against individuals of intelligence interest. High-confidence public reporting supports characterization of the actor as espionage-oriented rather than financially motivated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.