Kiberphant0m is the cybercriminal persona used by Cameron John Wagenius, a U.S. Army soldier stationed in South Korea during the relevant activity. Wagenius pleaded guilty to hacking, data-theft, and extortion offenses and was sentenced in U.S. federal court to 70 months’ imprisonment and ordered to pay restitution. His activity included compromising telecommunications-related data held by Snowflake customers whose accounts used exposed credentials and lacked enforced multi-factor authentication. The theft included AT&T mobile call and text metadata affecting more than 100 million customers, including telephone numbers, timestamps, and call durations. Kiberphant0m publicly extorted telecommunications victims by demanding payment in exchange for withholding stolen data, and Wagenius admitted to re-extorting victims and threatening disclosure of national-security information. The persona was associated with claimed compromise of Verizon Push-to-Talk services and the offering of SIM-swap services targeting personnel of U.S. government agencies and emergency services. Reported associates in the Snowflake-related activity include Conor Riley Moucka, known as Judische, Kenneth Schuchman, and John Erin Binns. The activity was investigated as a serious potential insider-threat matter because Wagenius was an active-duty service member with a U.S. security clearance.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cybercriminal identity used by Cameron John Wagenius in intrusions into telecommunications companies. The activity involved accessing Snowflake accounts with exposed credentials and no MFA, stealing call and text metadata affecting more than 100 million AT&T customers and data from other telecom targets, and attempting extortion.
Financially motivated data theft and extortion activity targeting telecommunications companies and Snowflake customers with exposed credentials and no enforced MFA. The actor stole and advertised sensitive call/text metadata, threatened public disclosure of stolen data and alleged national-security material, and re-extorted victims.
A cybercriminal persona operated by U.S. Army soldier Cameron Wagenius. The actor participated in Snowflake-related data thefts using exposed credentials without MFA, stole telecommunications metadata, publicly extorted victim companies, and threatened disclosure of sensitive data and purported national-security material.
Conducted data theft and extortion operations against telecommunications companies and other Snowflake customers. The actor used exposed credentials on Snowflake accounts lacking MFA, stole call and text metadata affecting more than 100 million AT&T customers, and extorted victims while threatening public disclosure of stolen data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.