Global kOS
Global kOS is described in archived 1997 material as a small, independent hacker group active in the 1990s. It is listed among hacking groups in Wikipedia’s "Hacking in the 1990s" navigation template. The group was primarily known for the "Up Yours" email bomber, which the content claims was used in mailbombing attacks against targets including Rush Limbaugh, the White House, politicians, AOL, Prodigy, and Captain Crunch. The content states that Global kOS designed its mailbombing software to be anonymous, including discussion of changing email headers and avoiding SMTP servers that altered headings. The group is linked to offensive tooling and planned releases beyond Up Yours. Archived write-ups state that Global kOS planned a "Digital Destruction Suite" that would incorporate Up Yours 4 and might include a virus creation lab and other destructive utilities; a "Hacking Suite" intended to automate intrusion activity for inexperienced users, including "Hacking 101" and a new version of "kOS Krack" for password-file cracking; a "Phreaking Suite"; and a "Security Suite" with tools and advice for system administrators, including a claimed 10,000-bit encryption program. Global kOS is also associated with the planned 1997 release of Up Yours 4.0, a denial-of-service and email-flooding tool attributed to Acid Angel and described as a Global kOS release rather than a Technophoria release. Content tied to that release claims intended or proposed capabilities including automated SYN flood attacks, resource-exhaustion attacks, identity-hiding features, a Usenet spammer, and a POP3 hacking feature. Acid Angel is described as associated with a loosely aligned Global kOS group, and Bronc Buster is described as contributing ideas while Acid Angel handled coding. Members named in the content include The Shadow Hunter, Acid Angel, Glitch, Silicon Toad, The Raven, That Guy, Spidey, Zaven, Materva, and Swine. The content states Materva and Swine were the latest and last members added and that the group was not accepting new members at that time. Known aliases and associated names directly mentioned in the content include Acid Angel and Bronc Buster as figures tied to Global kOS activity and the Up Yours project.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
4 malware families attributed to this actor across reporting.
Observables
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a named hacking group in the historical timeline/navigation content.
Named hacking group listed in the content's 1990s timeline/navigation material.
Named as a hacking group in a 1990s hacking timeline/sidebar; no specific operations, malware use, or targeting details are provided in the content.
Referenced only as a named hacking group in a navigational list; no operational details are provided in the content.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.