Adversary tracking
We follow infrastructure rather than names. Domain impersonation patterns, JARM fingerprints, ASN correlation and hosting reuse — the artefacts an actor cannot easily discard between campaigns.
Evidence — Scattered Spider暁 AKATSUKI · DAYBREAK
We are an independent research collective. We track adversary infrastructure, take apart intrusion campaigns, and publish the methodology alongside the findings so defenders can reproduce the work, not just read about it.
3 published reports Independent Open methodology & indicators
Powered by Hunt.io
Akatsuki Legion is an independent community of threat intelligence researchers focused on adversary infrastructure: tracking how actors provision, reuse, and burn through their assets over time.
Our work combines open source intelligence with a small set of carefully chosen commercial platforms. Hunt.io is one of the few we rely on: it gives us historical infrastructure visibility, archived open directories, and pivotable context that turns OPSEC mistakes into leads, not anecdotes.
Their support helps us keep the research independent and reproducible: every hunt we publish is something defenders can rerun, adapt, and extend inside their own environments.
We follow infrastructure rather than names. Domain impersonation patterns, JARM fingerprints, ASN correlation and hosting reuse — the artefacts an actor cannot easily discard between campaigns.
Evidence — Scattered SpiderEnd-to-end reconstruction of intrusion campaigns: initial access, lure design, execution chain, and the detection opportunities each stage leaves behind.
Evidence — Operation Black MirrorPost-incident analysis of financial-sector compromise, including on-chain tracing of stolen funds and reconstruction of the attacker's path through internal systems.
Evidence — NobitexHunting queries and detection logic released with every report, so a finding becomes something you can run rather than something you have to trust.
In progress — release date not yet setA financially motivated collective that weaponises social engineering over malware — mapped through domain impersonation, JARM pivoting and IOC clustering.
Multi-campaign analysis of ClickFix operations run by both APT actors and crimeware crews, focused on Win+R lures and infrastructure-level hunting.
How a cryptocurrency exchange was taken apart from the inside, and what its internal architecture revealed once the attackers published it.
We are open to research partnerships, sponsorship of published work, conference collaboration, and applications from analysts who want to publish under their own name.