Skip to content

Threat actor

Anomaly Six

Last fetched

Anomaly Six is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

Anomaly Six (A6) is a Virginia-based company founded in 2018 by two ex-military intelligence officers. The company claims to have the capability to track approximately 3 billion devices in real time through GPS data collected via smartphone apps. According to a report by The Intercept, their surveillance system operates by gathering location data through partnerships with "thousands" of apps using software development kits (SDKs). The company also claimed to have the capability to unmask and track intelligence agency (CIA and NSA) personnel during a pitch to Zignal Labs, a social media monitoring company. The company proposed a joint venture with Zignal Labs that would enable the U.S. government to conduct seamless surveillance operations on adversaries. Anomaly Six's capabilities are largely made possible through the advertising industry's data collection practices, highlighting the connection between commercial data brokers and surveillance techniques. U.S. Special Operations Command (SOCOM) paid $589,500 to Anomaly Six in September 2020 for a "Commercial Telemetry Feed." The company's co-founder, Brendan Huff, previously managed Defense Department relationships of another U.S surveillance company called Babel Street.

Techniques by tactic

No ATT&CK techniques are recorded for Anomaly Six in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to Anomaly Six today — this states the absence of a published link, not that Anomaly Six has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from Anomaly Six into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.