Soyjak Party, also referred to as The Party, is an online hacker collective associated with the imageboard ecosystem around Soyjak.st. The group publicly claimed responsibility for the April 2025 compromise of 4chan. In that incident, it asserted that it had infiltrated 4chan’s systems, maintained long-term access, restored and defaced a board, and obtained internal site code and personal information relating to site staff and subscribers. Reporting on the breach indicated that at least some exposed moderator data was authentic, lending credibility to the group’s claims of unauthorized access. The activity attributed to Soyjak Party in this operation reflects a mix of initial access, persistence, post-exploitation, internal system access, and data theft. Claimed access included administrative and moderation interfaces, site logs, database-management tooling, and operational controls for site boards, indicating substantial compromise of backend systems. The group also demonstrated public defacement and exposure of internal materials, suggesting an intent to embarrass the victim and publicize the intrusion rather than conduct covert espionage or financially motivated extortion. No high-confidence attribution to a nation-state or specific country is established. Based on the confirmed and claimed behavior in the 4chan intrusion, Soyjak Party is best characterized as a non-state online collective engaged in disruptive and publicity-driven offensive activity against online platform infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for the compromise of 4chan, including access to administrative panels, reopening and defacing /qa/, leaking staff personal data, and publishing site source code.
Claimed intrusion into 4chan’s systems, alleging compromise of site code and staff personal information and asserting the administrators took the site offline to mitigate damage.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.