764 is a nihilistic violent extremist network and child-exploitation-focused offshoot within the broader Com ecosystem, a loose transnational milieu of predominantly English-speaking young offenders involved in cybercrime, extortion, harassment, and real-world violence. U.S. authorities have described 764 as operating in the United States and abroad and as pursuing social destabilization through the corruption, coercion, and exploitation of vulnerable people, especially minors. Reporting and law-enforcement actions consistently place its participant base largely in adolescence and young adulthood, with many members and associates falling roughly within the 11-to-25 age range. The group is primarily known for the grooming, manipulation, sextortion, and coercive control of children and other vulnerable victims. Members have been accused of forcing victims to produce child sexual abuse material and increasingly extreme abuse content, including self-harm, animal abuse, sibling abuse, humiliation, and other violent acts. Victimization commonly relies on social engineering, blackmail, threats, doxing, swatting, cyberstalking, and sustained psychological abuse. Authorities and researchers have also linked 764 and adjacent communities to broader criminality including harassment campaigns, extortion, fraud, and overlap with cybercriminal subcultures inside The Com. 764 is associated with a wider online harm ecosystem in which status is earned through producing and circulating abuse, shock content, and coercive exploitation rather than through a coherent formal ideology. Nevertheless, multiple official characterizations describe the network as nihilistic violent extremist in nature, and some cases have alleged racially motivated violent extremist elements among certain members or splinters. The network has been tied to online spaces used for recruitment, grooming, and coordination across social, messaging, gaming, and chat platforms. Known subgroups and affiliated splinters include 764 Inferno, 8884, 7997, and other numerically branded cells. 764 Inferno has been identified by prosecutors as a core subgroup involved in directing the grooming and extortion of minors. 8884 and 7997 have been described as splinter or offshoot communities within the same copycat culture of coercive abuse and notoriety-seeking. The network has also been described as associated with neo-Nazi sextortionist elements in some reporting, but the strongest consistent characterization is as a decentralized nihilistic violent extremist and child-exploitation network embedded in The Com. Law-enforcement actions in the United States and internationally have targeted alleged leaders and members tied to 764-linked child exploitation, coercion, and violent abuse offenses. These cases, along with Europol’s broader Project Compass activity against The Com ecosystem, indicate that 764 is treated by authorities as a serious cross-border threat at the intersection of online extremism, child sexual exploitation, cyber-enabled coercion, and violent criminality.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as part of the nihilistic violent extremist threat landscape, combining sadistic online exploitation, cybercrime, self-directed violence, animal abuse, school-violence threats, and terrorist or violent-extremist conduct.
A violent extremist collective and sprawling nihilistic network linked to child exploitation, sextortion, coercion, and abuse, with multiple offshoots and members facing arrests and long prison sentences.
An associated network described as neo-Nazi sextortionists, with some members later moving into corporate extortion.
Sub-group within The Com described by DOJ as a nihilistic violent extremist network; per Europol, known for recruitment/grooming of minors, coercion into violent acts, production of explicit content/CSAM, and blackmail/extortion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.