Fulcrumsec
Also known as FulcrumSec, SeesawSec
Reports
6
First seen
Jun 10, 2026
Last seen
Sep 1, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Victim regions
×1×2
United Kingdom×2
Denmark×1
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1041 Exfiltration Over C2 Channel ×3T1078 Valid Accounts ×3T1110 Brute Force ×2T1566 Phishing ×2T1005 Data from Local System ×2T1566.002 Phishing: Spearphishing Link ×1T1592 Gather Victim Identity Information ×1T1537 Transfer Data to Cloud Account ×1T1195 Supply Chain Compromise ×1T1003 OS Credential Dumping ×1T1190 Exploit Public-Facing Application ×1T1555 Credentials from Password Stores ×1
Indicators
domain ×13email ×10cve ×8ip_v4 ×2
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
High