KaruHunters
KaruHunters is a threat actor observed posting underground listings offering compromised data and/or unauthorized access for sale. In the referenced reporting, KaruHunters is described as highly active and sophisticated, specializing in data leaks, and is associated with offering a compromised database for sale (priced at $200). The actor’s sales activity is noted as being offered privately via Telegram, including claims of responsibility for an unauthorized access sale related to “LinkUMKM.” No additional high-confidence details on tooling, TTPs, victimology beyond the cited incidents, or attribution to a nation-state are provided in the available content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Software & Services
Where they target
Geographies tied to known operations.
- 🇮🇳 India
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated data-leak actor/group advertising stolen databases for sale on underground forums; described as highly active and linked to multiple breaches.
Financially motivated data-leak group advertising stolen databases for sale on underground forums; associated with repeated unauthorized access and illicit sale of exfiltrated data.
Financially motivated data-leak group associated (per report) with repeated unauthorized access and sale of stolen databases on underground forums; example incident involves alleged sale of ~35,000 records from an India-based IT services firm (Leora Infotech).
Financially motivated data-leak actor advertising stolen databases for sale on underground forums; described as responsible for multiple breaches and illicit sale of stolen data.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.