BYOD is an emerging ransomware-as-a-service (RaaS) and data-extortion operation active by October 2026. It maintains a data-leak site, publishes stolen information, and pressures organizations to establish contact by threatening further disclosure. Its victim listings include organizations in the United States, Singapore, and Malaysia, spanning telecommunications, financial services, professional services, and manufacturing. Named targets include Trump Mobile, TMobile, Gate, Standpointe / Trinite Solutions, Franklin Empire, and Royal Selangor; not all listed compromises have been independently verified. BYOD published a dataset containing 3,615 records associated with Trump Mobile, including names, contact information, postal addresses, and order details. Verification with affected individuals established the authenticity of some records, although some individuals were not customers. This incident demonstrates the group's use of stolen personal and transactional information for public disclosure and extortion. BYOD's public messaging also offers removal of victim listings after communication is established. Despite its RaaS designation, encryption of victim systems has not been confirmed in the documented incidents. Its precise intrusion methods, malware families, organizational structure, and country of origin remain unestablished.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly conducted a ransomware attack against a US-based organization, with the breach discovered on October 8, 2026. The accompanying statement claims Trump Mobile was breached and hints at additional compromised data, but the content provides no independent verification or technical details.
Reportedly attacked Singapore-based Gate | Crypto Exchange on October 7, 2026. The accompanying extortion claim describes data concerning 12 million users, including phone numbers, account identifiers, balances, VIP tiers, verification status, and two-factor authentication indicators. The group threatens disclosure and offers to remove the victim listing after communication is established. The content provides no independent verification of these claims or technical evidence of ransomware deployment.
BYOD is identified as responsible for a reported ransomware attack against TMobile, discovered on October 7, 2026. The attributed message claims possession of victim data, threatens eventual public disclosure, and urges the victim to establish contact. The content does not independently substantiate encryption, data theft, or a ransom demand.
BYOD claims that Trump Mobile was breached and references purported partial samples involving “Liberty X TMO.” The provided post contains no actual sample artifacts, data volume, ransom demand, or deadline.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.