"The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware distribution, extortion, and predatory recruitment

"The Com" cross-platform criminal ecosystem (TL-2026-2155), also tracked as The Community, is a high-severity tracked intrusion set, first published 2026-08-26. It is attributed to The Com with high confidence, affects Discord Inc. Discord (CDN, invite links, webhooks/API), maps to 13 MITRE ATT&CK techniques (T1005, T1102.002, T1204.002), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-2155

Threat ID
TL-2026-2155
Also known as
The Community
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-08-26
Last reviewed
2026-08-26
Attribution
The Com
Attribution confidence
HIGH
Motivation
UNKNOWN
Target sectors
consumer, gaming, hospitality, retail, insurance, airline, financial services, government administration, education minors
Target regions
North America, united states of america, canada, united kingdom, Europe, Global
Detection rules
9
Indicators of compromise
23

Malware and tooling in "The Com" cross-platform criminal ecosystem

Malware and tooling: AsyncRAT, Ave Maria, ChromeKatz, DragonForce, Lumma Stealer - S1213, NJRat, Nanocore RAT, Quasar RAT, RedLine Stealer - S1240, Skuld Stealer, telegram, SYK Crypter

Flashpoint documents a decentralized, FBI-tracked criminal ecosystem known as "The Com" that operates across mainstream platforms rather than the dark web: Discord's CDN and webhook infrastructure are abused to distribute RATs/infostealers and bypass corporate security perimeters, Telegram serves as a marketplace and coordination hub, Roblox and Minecraft are scouting grounds for a predatory recruitment pipeline that grooms isolated minors before migrating them to encrypted channels for sextortion, and X is used to amplify ransomware data-leak extortion. Subgroups including 764, Extortion Com, and the FBI-tracked Scattered Spider syndicate have driven federal prosecutions, a July 2025 FBI/IC3 nationwide alert, and ~300 active FBI investigations as of late 2025.

How "The Com" cross-platform criminal ecosystem works

The Com ("The Community") is a decentralized, primarily English-speaking online ecosystem of loosely affiliated cybercriminal and predatory subgroups, operating chiefly through Discord, Telegram, Roblox, Minecraft, and X rather than dark-web infrastructure. The FBI and IC3 describe thousands of participants, disproportionately minors and young adults aged roughly 11-25, organized into recognized subsets: Hacker Com (financially motivated cybercrime, malware development, ransomware-as-a-service affiliation), IRL Com (violence-for-hire, armed robbery, shootings), Extortion Com (sextortion and CSAM production targeting minors), and 764 (a violent, ideologically-tinged network that coerces minors into self-harm, suicide attempts, animal cruelty, and CSAM production, with documented overlap into neo-Nazi/accelerationist networks such as M.K.U.). Scattered Spider (also tracked by MITRE as Octo Tempest/UNC3944/Roasted 0ktapus, G1015), the syndicate behind the 2023 MGM Resorts breach, the 2024 Snowflake customer-data extortion campaign, and 2025 UK retail ransomware intrusions (including DragonForce ransomware deployment), is publicly linked by the FBI to The Com's Hacker Com subset.

On the malware-distribution side, security vendors (Morphisec, Zscaler, Trend Micro, Trellix, Centripetal, Intel 471) have independently documented threat actors abusing Discord's CDN (cdn.discordapp.com / media.discordapp.net) to host and serve infostealers and remote access trojans, exploiting the fact that corporate network defenses commonly allowlist Discord domains, letting malicious traffic blend with legitimate application activity and bypass perimeter controls. The "SYK Crypter" service has been used to package and deliver AsyncRAT, njRAT, QuasarRAT, Warzone RAT, and NanoCore RAT via Discord-hosted payloads; separate campaigns push RedLine Stealer and Lumma Stealer via Discord CDN links, and a mid-2025 campaign abusing expired/recycled Discord invite links delivered AsyncRAT, Skuld Stealer, and the ChromeKatz cookie/session-token harvester to exfiltrate credentials, browser cookies, and Discord session tokens — in some cases using Discord's own webhook/API infrastructure as an exfiltration and C2 channel. Researchers have counted roughly 10,000 malware samples that leverage Discord infrastructure for distribution or C2.

On the predatory-recruitment side, Flashpoint and multiple child-safety/legal analyses describe a repeatable pipeline: (1) scouting — recruiters identify socially isolated, depressed, or attention-seeking minors on Roblox, Minecraft, and public Discord servers; (2) trust-building — "love bombing" through gifted in-game currency, subscriptions, or a romantic facade to create psychological obligation; (3) migration — moving the target from a platform's public, moderated spaces into private Discord servers or encrypted apps, isolating them from safety tooling (a documented "public-to-private" strategy). Once isolated, victims are coerced into producing sexual imagery or self-harm content, which is then used for blackmail, doxxing threats, and further extortion. Extortion Com has specifically operated fake "suicide-prevention" Telegram support chats to social-engineer isolated minors into disclosing identifying information later used to doxx and extort them. Discord alone forwarded 489,782 suspected child-exploitation reports to NCMEC in 2025 (over 1,300/day).

Other documented Com tactics weaponize consumer-facing infrastructure for both cybercrime and real-world violence: SIM swapping and IP-grabbing to deanonymize and locate victims; OSINT-based doxxing; DDoS-for-hire; swatting and hoax bomb threats; cryptocurrency theft and money laundering; and, on the Scattered Spider/Hacker Com side, telephone- and SMS-based helpdesk impersonation to obtain credential resets and MFA transfers ahead of ransomware deployment. X (Twitter) is used post-compromise to publicly broadcast proof of breaches and amplify pressure on ransomware/data-leak-site victims during extortion negotiations.

Federal response has been active and sustained: a May 2024 FBI tradecraft alert on 764 doxxing practices; the November 2024 sentencing of 764 operator Richard Anthony Reyna Densmore ("Rabid") to 30 years for child sexual exploitation; the October 2024 arrest and subsequent guilty plea of Connor Riley Moucka for the Snowflake-linked extortion campaign; a July 23, 2025 FBI/IC3 public service announcement (PSA250723-3) and a July 28, 2025 follow-on alert tying Com cybercrime to physical violence; a July 29, 2025 updated joint advisory on Scattered Spider tactics; FBI Director Kash Patel's November 2025 disclosure of roughly 300 active investigations into the 764 network with arrests across 23 countries; and continued congressional oversight pressure on the FBI's response into 2026.

MITRE ATT&CK techniques used in TL-2026-2155

Collection

T1005 Data from Local System

Command and Control

T1102.002 Bidirectional Communication

Execution

T1204.002 Malicious File

initial-access

T1451 SIM Card Swap

Credential Access

T1539 Steal Web Session Cookie

Initial Access

T1566.003 Spearphishing via Service

Exfiltration

T1567.002 Exfiltration to Cloud Storage

Resource Development

T1585.001 Social Media Accounts; T1608.001 Upload Malware

Reconnaissance

T1589 Gather Victim Identity Information; T1598.004 Spearphishing Voice

Impact

T1657 Financial Theft

Defense Evasion

T1684.001 Impersonation

Affected products and versions in "The Com" cross-platform criminal ecosystem

  • Discord Inc. — Discord (CDN, invite links, webhooks/API)
    Vulnerable versions: N/A — platform-abuse campaign, not a software vulnerability; CDN/invite/webhook features abused as designed
    Fixed in: N/A
  • Telegram FZ-LLC — Telegram (channels, groups, bots)
    Vulnerable versions: N/A — abused as a marketplace and operational coordination hub
    Fixed in: N/A
  • Roblox Corporation — Roblox
    Vulnerable versions: N/A — abused as a minor-recruitment scouting surface
    Fixed in: N/A
  • Mojang Studios / Microsoft — Minecraft
    Vulnerable versions: N/A — abused as a minor-recruitment scouting surface
    Fixed in: N/A
  • X Corp. — X (Twitter)
    Vulnerable versions: N/A — abused to amplify ransomware data-leak extortion pressure
    Fixed in: N/A

Remediation for "The Com" cross-platform criminal ecosystem

Patches

  • N/A — this is a platform-abuse and criminal-ecosystem campaign, not a software vulnerability; no vendor patch applies

Immediate actions

  • Do not blanket-allowlist Discord/Telegram CDN and domain traffic at the network perimeter (cdn.discordapp.com, media.discordapp.net) — apply content inspection to files downloaded from them rather than trusting the domain alone
  • Restrict or monitor outbound traffic to Discord's webhook/API endpoints (discord.com/api/webhooks) from endpoints with no legitimate business use for Discord, since stealer malware abuses webhooks as an exfiltration/C2 channel
  • Train helpdesk and IT support staff to resist phone- and SMS-based identity-verification bypass attempts (documented Scattered Spider vishing pattern) before performing password resets or MFA transfers
  • Report suspected child grooming, sextortion, or CSAM activity immediately to NCMEC's CyberTipline (report.cybertip.org) and the FBI's IC3 (ic3.gov / 1-800-CALL-FBI)
  • Enable carrier-level SIM-swap protections (port-freeze/PIN) for accounts and personnel with access to sensitive systems, given SIM swapping is a documented Com credential-access vector

Workarounds

  • Scope corporate network trust of Discord/Telegram traffic to specific vetted business use cases instead of blanket allowlisting
  • Educate minors and guardians on the documented 'public-to-private migration' grooming red flag: in-game gifting/love-bombing followed by pressure to move to Discord DMs or encrypted chat

Longer-term hardening

  • Deploy EDR/network monitoring tuned to detect RAT/infostealer behavior distributed via trusted-CDN channels rather than relying on domain-reputation allowlisting alone
  • Establish parental controls and platform-safety monitoring for minors' use of Discord, Roblox, Minecraft, and Telegram, with attention to unsolicited DMs and requests to migrate off-platform
  • Adopt phishing-resistant MFA (FIDO2/hardware security keys) to blunt helpdesk social-engineering and SIM-swap-enabled account takeover used by Scattered Spider/Hacker Com
  • Participate in law-enforcement information-sharing channels (FBI/IC3, NCMEC) given The Com's cross-jurisdictional, cross-platform, minor-heavy membership structure

Timeline of "The Com" cross-platform criminal ecosystem

  • Com subgroup 6996 authors and distributes 'The Bible,' a criminal tradecraft manual, on Telegram.
  • FBI issues a tradecraft alert on 764's doxxing practices used against minors.
  • Connor Riley Moucka is arrested in Kitchener, Canada, in connection with the Snowflake customer-data extortion campaign, later linked to Com/Scattered Spider circles.
  • Five individuals are charged in the United States under the Scattered Spider cybercrime syndicate, a subset publicly linked to The Com's Hacker Com.
  • 764 operator Richard Anthony Reyna Densmore ('Rabid') is sentenced to 30 years in prison for sexually exploiting a child via Discord 'Sewer' communities.
  • FBI/IC3 publish Public Service Announcement PSA250723-3, warning that The Com poses a rising threat of theft, extortion, and violence to youth online.
  • FBI issues a follow-on alert explicitly tying The Com's cybercrime activity to physical violence, building on the July 23 PSA.
  • A joint cybersecurity advisory update details Scattered Spider's evolving tactics, including DragonForce ransomware deployment.
  • FBI Director Kash Patel discloses roughly 300 active investigations into the 764 network nationwide, with prior arrests spanning 23 countries.
  • Flashpoint publishes 'Understanding Illicit Ecosystems,' documenting The Com's abuse of Discord, Telegram, Roblox, Minecraft, and X across malware distribution, extortion, and minor recruitment.

Sources cited for "The Com" cross-platform criminal ecosystem

More in threat intel

Detection coverage for TL-2026-2155

As of 2026-08-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2155 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats