Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-02

The Com

Also known as:Cyber Com

As of 2026-08-26, The Com is a threat actor tracked by Threadlinqs Intelligence across 9 threats spanning threat intel, data breach, threat actor. Also known as Cyber Com. ATT&CK coverage spans 92 techniques across 16 tactics in 9 of 9 tracked threats. Most-observed techniques: T1657 (Financial Theft), T1078 (Valid Accounts), T1530 (Data from Cloud Storage).

Tracked threats
91 critical · 8 high
First seen
2026-02-02
Last seen
2026-08-26
ATT&CK techniques
92across 9 of 9 threats
Related CVEs
0None referenced
9 tracked threat(s) · Categories: THREAT_INTEL, DATA_BREACH, THREAT_ACTOR, CAMPAIGN

Activity timeline

The Com appears in 9 tracked threats between and ; the busiest month was 2026-02 with 6 reports.

ATT&CK techniques observed

92 techniques observed across 9 of 9 tracked threats · Credential Access (14), Resource Development (11), Initial Access (10), Discovery (8), Impact (7), Persistence (7)
  • T1657 Financial Theft — Impactobserved in 9 of 9 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 8 of 9 tracked threats
  • T1530 Data from Cloud Storage — Collectionobserved in 8 of 9 tracked threats
  • T1566 Phishing — Initial Accessobserved in 8 of 9 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 8 of 9 tracked threats
  • T1589 Gather Victim Identity Information — Reconnaissanceobserved in 8 of 9 tracked threats
  • T1213 Data from Information Repositories — Collectionobserved in 7 of 9 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 7 of 9 tracked threats
  • T1588 Obtain Capabilities — Resource Developmentobserved in 7 of 9 tracked threats
  • T1621 Multi-Factor Authentication Request Generation — Credential Accessobserved in 7 of 9 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 6 of 9 tracked threats
  • T1098 Account Manipulation — Persistenceobserved in 6 of 9 tracked threats
  • T1204 User Execution — Executionobserved in 6 of 9 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 6 of 9 tracked threats
  • T1539 Steal Web Session Cookie — Credential Accessobserved in 6 of 9 tracked threats

Tracked threats