"The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware distribution, extortion, and predatory recruitment — Threadlinqs Intelligence
As of 2026-08-26, "The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware distribution, extortion, and predatory recruitment is a high-severity threat intel threat attributed to The Com, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-2155 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: The Com · UNKNOWN
Flashpoint documents a decentralized, FBI-tracked criminal ecosystem known as "The Com" that operates across mainstream platforms rather than the dark web: Discord's CDN and webhook infrastructure are
The Com ("The Community") is a decentralized, primarily English-speaking online ecosystem of loosely affiliated cybercriminal and predatory subgroups, operating chiefly through Discord, Telegram, Roblox, Minecraft, and X rather than dark-web infrastructure. The FBI and IC3 describe thousands of participants, disproportionately minors and young adults aged roughly 11-25, organized into recognized subsets: Hacker Com (financially motivated cybercrime, malware development, ransomware-as-a-service affiliation), IRL Com (violence-for-hire, armed robbery, shootings), Extortion Com (sextortion and CSAM production targeting minors), and 764 (a violent, ideologically-tinged network that coerces minors into self-harm, suicide attempts, animal cruelty, and CSAM production, with documented overlap into neo-Nazi/accelerationist networks such as M.K.U.). Scattered Spider (also tracked by MITRE as Octo Tempest/UNC3944/Roasted 0ktapus, G1015), the syndicate behind the 2023 MGM Resorts breach, the 2024 Snowflake customer-data extortion campaign, and 2025 UK retail ransomware intrusions (including DragonForce ransomware deployment), is publicly linked by the FBI to The Com's Hacker Com subset.
On the malware-distribution side, security vendors (Morphisec, Zscaler, Trend Micro, Trellix, Centripetal, Intel 471) have independently documented threat actors abusing Discord's CDN (cdn.discordapp.com / media.discordapp.net) to host and serve infostealers and remote access trojans, exploiting the fact that corporate network defenses commonly allowlist Discord domains, letting malicious traffic blend with legitimate application activity and bypass perimeter controls. The "SYK Crypter" service has been used to package and deliver AsyncRAT, njRAT, QuasarRAT, Warzone RAT, and NanoCore RAT via Discord-hosted payloads; separate campaigns push RedLine Stealer and Lumma Stealer via Discord CDN links, and a mid-2025 campaign abusing expired/recycled Discord invite links delivered AsyncRAT, Skuld Stealer, and the ChromeKatz cookie/session-token harvester to exfiltrate credentials, browser cookies, and Discord session tokens — in some cases using Discord's own webhook/API infrastructure as an exfiltration and C2 channel. Researchers have counted roughly 10,000 malware samples that leverage Discord infrastructure for distribution or C2.
On the predatory-recruitment side, Flashpoint and multiple child-safety/legal analyses describe a repeatable pipeline: (1) scouting — recruiters identify socially isolated, depressed, or attention-seeking minors on Roblox, Minecraft, and public Discord servers; (2) trust-building — "love bombing" through gifted in-game currency, subscriptions, or a romantic facade to create psychological obligation; (3) migration — moving the target from a platform's public, moderated spaces into private Discord servers or encrypted apps, isolating them from safety tooling (a documented "public-to-private" strategy). Once isolated, victims are coerced into producing sexual imagery or self-harm content, which is then used for blackmail, doxxing threats, and further extortion. Extortion Com has specifically operated fake "suicide-prevention" Telegram support chats to social-engineer isolated minors into disclosing identifying information later used to doxx and extort them. Discord alone forwarded 489,782 suspected child-exploitation reports to NCMEC in 2025 (over 1,300/day).
Other documented Com tactics weaponize consumer-facing infrastructure for both cybercrime and real-world violence: SIM swapping and IP-grabbing to deanonymize and locate victims; OSINT-based doxxing; DDoS-for-hire; swatting and hoax bomb threats; cryptocurrency theft and money laundering; and, on the Scattered Spider/Hacker Com side, telephone- and SMS-based helpdesk impersonation to obtain credential resets and MFA transfers ahead of ransomware deployment. X (Twitter) is used post-compromise to publicly broadcast proof of breaches and amplify pressure on ransomware/data-leak-
Target sectors: consumer, gaming, hospitality, retail, insurance, airline, financial services, government administration, education minors
Target regions: North America, united states of america, canada, united kingdom, Europe, Global
Timeline
- Com subgroup 6996 authors and distributes 'The Bible,' a criminal tradecraft manual, on Telegram.
- FBI issues a tradecraft alert on 764's doxxing practices used against minors.
- Connor Riley Moucka is arrested in Kitchener, Canada, in connection with the Snowflake customer-data extortion campaign, later linked to Com/Scattered Spider circles.
- Five individuals are charged in the United States under the Scattered Spider cybercrime syndicate, a subset publicly linked to The Com's Hacker Com.
- 764 operator Richard Anthony Reyna Densmore ('Rabid') is sentenced to 30 years in prison for sexually exploiting a child via Discord 'Sewer' communities.
- FBI/IC3 publish Public Service Announcement PSA250723-3, warning that The Com poses a rising threat of theft, extortion, and violence to youth online.
- FBI issues a follow-on alert explicitly tying The Com's cybercrime activity to physical violence, building on the July 23 PSA.
- A joint cybersecurity advisory update details Scattered Spider's evolving tactics, including DragonForce ransomware deployment.
- FBI Director Kash Patel discloses roughly 300 active investigations into the 764 network nationwide, with prior arrests spanning 23 countries.
- Flashpoint publishes 'Understanding Illicit Ecosystems,' documenting The Com's abuse of Discord, Telegram, Roblox, Minecraft, and X across malware distribution, extortion, and minor recruitment.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1589, T1598.004, T1585.001, T1608.001, T1566.003, T1204.002, T1684.001, T1451, T1539, T1005