Executive Summary

Kyle William Spitze, a 27-year-old original member and administrator of the nihilistic violent extremist group 764, was sentenced to 77 years in prison in January 2025, marking the longest federal sentence ever imposed on a nihilistic violent extremist. Spitze, operating under aliases including "Chrimhn" and "Criminal," led the 764 offshoot "Harm Nation" and coerced dozens of minors through threats of doxing and swatting to produce child sexual abuse material, self-mutilate, and torture animals. The FBI investigation began in December 2023 after Discord reported the group's activities, leading to Spitze's arrest and guilty plea to multiple federal charges including production and distribution of CSAM.

This sentencing represents a significant escalation in law enforcement's response to online extremist networks that exploit children, as FBI Director Kash Patel reported a 500% increase in arrests of nihilistic violent extremist offenders in 2024, highlighting the growing threat these decentralized criminal enterprises pose to vulnerable populations.

Why This Matters Now

The 764 network and similar nihilistic violent extremist groups represent an evolving cyber-enabled threat that combines traditional criminal exploitation with extremist ideologies, targeting thousands of vulnerable individuals aged 11-25 through encrypted platforms to foster social unrest and corruption of minors.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The 764 network is a nihilistic violent extremist group comprising thousands of individuals aged 11-25 who use encrypted platforms like Telegram and Discord to exploit vulnerable populations, particularly children, with the goal of fostering social unrest and destroying civilized society.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the operational reach and persistence of 764/Harm Nation's distributed criminal network by constraining lateral movement between platforms and limiting access to cloud storage repositories used for content distribution.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud-native visibility and monitoring would likely detect anomalous communication patterns and platform-hopping behaviors associated with coordinated recruitment campaigns across multiple social media endpoints.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-aware segmentation policies would likely limit the scope of administrative privileges and constrain access to sensitive victim data repositories, reducing the effectiveness of coercion campaigns.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Microsegmentation enforcement would likely constrain cross-platform communication pathways and reduce the network's ability to coordinate operations between geographically distributed affiliate groups and recruitment cells.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized policy enforcement across cloud environments would likely detect and constrain persistent administrative sessions and reduce the network's ability to maintain coordinated command structures across multiple platforms.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely constrain bulk data transfers to external storage repositories and limit the network's ability to systematically distribute illegal content across multiple cloud platforms.

Impact (Mitigations)

While victim harm would likely still occur, the reduced operational scale and constrained distribution capabilities could limit the network's reach to additional victims and reduce the proliferation of illegal content.

Impact at a Glance

Affected Business Functions

  • Platform Content Moderation
  • User Safety Systems
  • Trust and Safety Operations
  • Community Guidelines Enforcement
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Child sexual abuse material distributed across multiple platforms including Telegram and Discord. Personal information of dozens of minor victims compromised through doxing threats. Digital evidence included approximately 25 photo albums with victim identification data stored on perpetrator devices.

Recommended Actions

  • Implement egress security and policy enforcement to detect and block unauthorized data transfers to external platforms and cloud storage services
  • Deploy multicloud visibility and control systems to monitor anomalous interactions and suspicious automation patterns across communication platforms
  • Enable threat detection and anomaly response capabilities to identify covert tools and unauthorized remote access patterns in real-time
  • Establish zero trust segmentation with identity-based policies to limit lateral movement between user accounts and communication channels
  • Utilize encrypted traffic inspection capabilities to analyze communications while maintaining privacy compliance for legitimate users

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image