rose87168 is a cybercriminal threat actor first observed in early 2025 in connection with the sale and extortion of data allegedly stolen from Oracle’s legacy cloud authentication environment. The actor publicly claimed to have compromised Oracle Cloud single sign-on and LDAP infrastructure and to possess roughly 6 million records affecting a large multi-tenant customer base. Reported stolen material included identity and authentication-related data, credential artifacts, and cryptographic keying material. Multiple independent assessments cited structurally consistent samples and judged that a significant compromise likely occurred, although Oracle publicly disputed aspects of the incident and stated that Oracle Cloud Infrastructure was not breached. The actor’s activity is characterized by monetization of stolen enterprise identity data through underground forum sales and coercive payment demands for data removal, indicating a primarily financially motivated operation. Reporting also indicates the actor sought assistance to decrypt or crack protected credential material, which would increase the downstream risk of account compromise and broader enterprise intrusion. Researchers assessed the intrusion as likely multi-stage rather than a single-action breach, with CVE-2021-35587 in Oracle Access Manager identified as a plausible initial access vector against outdated Oracle Fusion Middleware components. Post-compromise behavior reportedly included exfiltration of SSO and LDAP data and exposure of materials that could facilitate follow-on access, lateral movement, and supply-chain-style pivoting into interconnected environments. Known behavior associated with rose87168 includes initial access via exploitation of a public-facing vulnerability, exfiltration of large identity datasets, attempted extortion tied to stolen data, and possible post-exploitation activity against authentication infrastructure. The actor has been described as new to criminal forums but comparatively sophisticated in tradecraft for a newly observed persona. No high-confidence attribution to a nation-state or specific country of origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the actor allegedly behind a breach of Oracle legacy Gen 1 cloud servers resulting in compromise of approximately 6 million records.
Posted stolen Oracle-related data for sale on BreachForums and claimed access to Oracle's traditional servers; associated in the content with compromise of outdated Oracle servers and theft from Oracle Identity Manager data.
Alleged threat actor claiming access to Oracle-related legacy/Gen1 (Oracle Cloud Classic) data and attempting to sell ~6M records; claims to have obtained SSO authentication data and encrypted LDAP passwords and that decryption may be possible using stolen files.
Claimed compromise of Oracle Cloud identity infrastructure, including SSO/LDAP systems, with exfiltration of approximately 6 million user records. The actor allegedly used a multi-stage intrusion after initial access to extract database, LDAP, and key/configuration data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.