Defentek is an Israeli telecom surveillance vendor named alongside other commercial interception and location-tracking providers. It has been publicly associated with the market for surveillance capabilities against mobile subscribers, including systems relevant to telecom-based tracking and interception. Available information in this record does not directly attribute specific intrusion campaigns, malware operations, or signaling attacks to Defentek itself, nor does it establish confirmed victim countries, sectors, or operational tradecraft beyond its identification as a surveillance vendor in that ecosystem. The actor is therefore best characterized here as a commercial surveillance company linked to lawful-intercept and mobile surveillance capabilities rather than a directly attributed intrusion set or nation-state threat group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.