Threat Actor Characterization
Mzk
ID: eaaefc39fb86989c66d4d6b39d79410223923Actor Network Graph
Open Network GraphMITRE ATT&CK®
Mzk is a cluster-linked persona repeatedly associated with Sociedad Privada 157 in public reporting on public-sector website compromise, defacement, and possible data-exposure activity centered on Mexico.
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1491.001 | Internal Defacement | TA0040 |
|
| T1190 | Exploit Public-Facing Application | TA0001 |
|
| T1078 | Valid Accounts | TA0001 TA0003 TA0004 TA0005 |
|
| T1505.003 | Web Shell | TA0003 |
|
| T1567 | Exfiltration Over Web Service | TA0010 |
|
Mzk — Associated persona within Sociedad Privada 157
Classification: TLP:WHITE - Open Source Intelligence (OSINT)
Category: Cybercrime / Defacement and data-exposure ecosystem - Origin: Mexico (INFERENCE, confidence: medium)
Author: iQBlack CTI Team
Executive Summary
Mzk is assessed as a public-facing or semi-public alias associated with the Mexican cybercriminal cluster Sociedad Privada 157. Public reporting does not support a rich standalone profile for Mzk as an independent “brand”; instead, the observable pattern is repeated inclusion of the alias in defacement signatures, campaign warnings, and collaborator listings tied to attacks against public-sector digital infrastructure in Mexico and nearby regional targets.
[OSINT | B2] Publicly available reporting links Mzk to Sociedad Privada 157 activity through repeated appearance in incident imagery and actor lists tied to defacement campaigns affecting government or quasi-government portals. [OSINT | B3] Open reporting also suggests overlap between the broader Sociedad Privada 157 environment and the Chronus Team ecosystem, particularly where alerts describe possible joint or aligned activity rather than strict organizational unity.