Executive Summary
Between June and July 2026, Europol coordinated 'Referral Action Days' involving investigators from nine countries to target 'The Com,' a decentralized network of nihilistic violent extremist groups. This operation led to the identification and referral of 4,340 URLs containing content that promotes self-harm, child sexual exploitation, and violent attacks. The initiative aimed to disrupt The Com's online ecosystem and limit the dissemination of extremist propaganda.
This crackdown underscores the persistent threat posed by decentralized extremist networks exploiting online platforms to radicalize and victimize individuals, particularly minors. The operation highlights the necessity for continuous international collaboration to monitor and mitigate the spread of such harmful content.
Why This Matters Now
The recent Europol operation reveals the evolving tactics of extremist groups like The Com, emphasizing the urgent need for enhanced monitoring and intervention strategies to protect vulnerable populations from online radicalization and exploitation.
Attack Path Analysis
The Com initiated the attack by exploiting misconfigured cloud storage to gain initial access. They then escalated privileges by exploiting IAM role misconfigurations, allowing broader access. Utilizing this access, they moved laterally across cloud services to identify sensitive data. Established command and control channels were set up using encrypted outbound communications. Sensitive data was exfiltrated to external servers. Finally, the attackers disrupted services by deploying ransomware across compromised systems.
Kill Chain Progression
Initial Compromise
Description
The Com exploited misconfigured cloud storage to gain unauthorized access to the cloud environment.
MITRE ATT&CK® Techniques
Phishing
Valid Accounts
Command and Scripting Interpreter
System Information Discovery
Brute Force
Obfuscated Files or Information
Exfiltration Over C2 Channel
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing system and network security are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
Network security providers must enhance egress filtering and threat detection capabilities to combat The Com's sophisticated organized crime operations targeting encrypted traffic and lateral movement.
Primary/Secondary Education
Educational institutions face critical risks from The Com's targeted recruitment of minors through gaming platforms, requiring enhanced zero trust segmentation and monitoring protocols.
Gambling/Casinos
Gaming sector remains vulnerable to The Com ransomware attacks as demonstrated in Las Vegas breaches, necessitating improved multicloud visibility and anomaly detection systems.
Retail Industry
Retail organizations face ongoing threats from The Com network following Marks & Spencer and Co-op breaches, requiring strengthened egress security and policy enforcement measures.
Sources
- Europol flags 4,340 URLs for removal in 'The Com' crackdownhttps://www.bleepingcomputer.com/news/security/europol-flags-4-340-urls-for-removal-in-the-com-crackdown/Verified
- Europol-led action against nihilistic violent extremist network 'The Com'https://www.europol.europa.eu/media-press/newsroom/news/europol-led-action-against-nihilistic-violent-extremist-network-comVerified
- Project COMPASS: first operational results against The Com networkhttps://www.europol.europa.eu/media-press/newsroom/news/project-compass-first-operational-results-against-com-networkVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to exploit misconfigurations, escalate privileges, and move laterally, thereby reducing the overall blast radius.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit misconfigured cloud storage may have been limited, reducing the likelihood of unauthorized access.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges may have been constrained, limiting their access to sensitive resources.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement across cloud services may have been restricted, reducing their ability to access sensitive data.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels may have been detected and disrupted, limiting their control over compromised systems.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data may have been hindered, reducing the risk of data loss.
The attacker's ability to deploy ransomware may have been limited, reducing the potential disruption to services.
Impact at a Glance
Affected Business Functions
- Online Content Moderation
- Cybersecurity Operations
- Law Enforcement Investigations
Estimated downtime: N/A
Estimated loss: N/A
n/a
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent lateral movement.
- • Utilize Egress Security & Policy Enforcement to monitor and control outbound communications, mitigating command and control channels.
- • Deploy Inline IPS (Suricata) to detect and prevent known exploit patterns and malicious payloads.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Regularly audit and remediate IAM role configurations to prevent privilege escalation.



