The Com, short for The Community, is a decentralized, primarily English-speaking criminal and violent extremist ecosystem composed of loosely connected online groups rather than a single centrally directed organization. It is widely associated with young participants, including minors, and spans overlapping cybercriminal, sextortion, swatting, and real-world violence networks. Reporting and law-enforcement assessments describe it as lacking a unified ideology, but many factions are bound by a misanthropic and nihilistic worldview; some subsets also incorporate accelerationist, violent right-wing extremist, satanic, or neo-Nazi symbolism and rhetoric. The Com operates as an online social environment in which status is often earned through increasingly harmful acts, including cyber intrusions, extortion, doxxing, swatting, coercion, self-harm exploitation, child sexual abuse, animal cruelty, and physical violence. Recruitment, grooming, and radicalization commonly occur through social media, messaging applications, gaming platforms, and private chat communities. Victims, often minors, may be coerced through sextortion and manipulated into producing abusive material or committing acts that are then used for blackmail, propaganda, or internal prestige-building. Authorities and researchers describe multiple overlapping subsets and affiliated milieus within The Com. These include Cyber Com or Hacker Com, associated with network intrusions, ransomware, SIM swapping, phishing, and data extortion; (S)extortion Com, associated with coercion of minors, self-harm encouragement, and sexual exploitation; Offline Com or IRL Com, associated with violence-as-a-service, swatting-for-hire, kidnappings, assaults, shootings, arson, and intimidation; and the 764 network, which has been linked to grooming and child exploitation. The boundaries between these subsets are porous, and participants frequently move across cybercrime, fraud, harassment, and physical violence. The Com has been linked by multiple incident-response and intelligence teams to prominent English-speaking cybercriminal crews and brands, including Scattered Spider and Pink, and has also been discussed in connection with overlapping actors around Lapsus$ and ShinyHunters. In the cyber domain, actors associated with this ecosystem are known for aggressive social engineering, especially voice phishing, help-desk impersonation, credential theft, MFA bypass, SIM swapping, SaaS and cloud account compromise, data theft, and extortion. Targeting has included enterprises across sectors such as retail, technology, healthcare, aviation, finance, and telecommunications, with a focus on identity platforms, collaboration suites, and cloud-hosted business data. Law-enforcement and counterterrorism bodies increasingly characterize The Com as a hybrid threat environment that blurs the line between organized cybercrime, violent extremism, and terrorism-adjacent activity. Europol has identified it as an evolving global threat, particularly because minors appear both as victims and perpetrators, and because its online ecosystems facilitate propaganda dissemination, grooming, and mobilization into offline harm. The network’s decentralized structure, fluid membership, multilingual online reach, and convergence of cyber-enabled extortion with real-world violence make it difficult to disrupt through traditional actor-centric approaches.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A decentralized extremist network whose online ecosystem was targeted by Europol for distributing harmful content including material encouraging self-harm, child sexual exploitation, violent acts, and extremist manuals; the content also states it has been linked to high-profile ransomware attacks against major retailers and casinos.
A decentralized extremist network whose affiliated groups recruit and groom victims online, coerce them into self-harm, violence, and child sexual abuse material production, and whose Cyber Com subgroup orchestrates network intrusions and ransomware attacks.
A loose online extremist ecosystem involved in propaganda dissemination, grooming and extorting minors, encouraging self-harm, animal torture, violent attacks, production of child sexual abuse material, and distributing manuals covering grooming, murder, improvised explosives, doxing, and swatting.
A loosely knit online criminal network involved in hacking, swatting, digital extortion, propaganda and recruitment of minors, as well as facilitating or glorifying real-world violence including shootings, stabbings, arson, grooming, doxxing, and violence-as-a-service activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.