ByteToBreach is a financially motivated cybercriminal persona active since at least June 2025 that operates as a data thief, leak trader, and access broker across underground forums and messaging platforms. The actor has been linked with high confidence by KELA to Zakaria Mahdjoub of Oran, Algeria, although some individual incident attributions remain based on the actor’s own claims. ByteToBreach has maintained a presence on DarkForums, Dread, Telegram, Signal, Session, Pastebin, and a public WordPress site branded as “Pentesting Ltd.” used for self-promotion, victim shaming, and monetization. The actor’s victimology is broad and opportunistic rather than politically constrained, with reported targeting of government entities, financial institutions, airlines, telecommunications providers, universities, healthcare and insurance organizations, and other large enterprises across multiple regions. Publicly associated incidents and claims include activity affecting Romania’s ANCPI, Eurofiber France, Viking Line, CGI Sverige AB and Sweden’s e-government ecosystem, National Oil Ethiopia, Hungarian public-sector entities including the State Treasury, and other organizations in Europe, Africa, Asia, and the Americas. ByteToBreach’s access methods include exploitation of known vulnerabilities in internet-facing enterprise software, reuse of credentials obtained from infostealers and phishing, brute-force activity, and abuse of exposed misconfigurations. Reported post-compromise behavior includes reconnaissance of Active Directory trust relationships, use of valid accounts, credential harvesting, lateral movement, access to databases and backups, theft of source code and internal documents, and exfiltration of sensitive data for sale or public release. Multiple reports also associate the actor with ransomware deployment or ransomware claims in some intrusions, including incidents involving ANCPI and National Oil Ethiopia, and extortion pressure in the Eurofiber case. The actor has also advertised ancillary criminal services such as hash cracking. Operationally, ByteToBreach appears to emphasize credibility-building through detailed breach narratives, screenshots, selective leaking, and publication of technically rich datasets. The actor’s tradecraft and victim selection are consistent with profit-driven intrusion activity focused on monetizing stolen access and data rather than espionage or destructive strategic objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Serveur ciblé : esb.mvh.allamkincstat.gov.hu Vulnérabilité exploitée : CVE-2017-10271 (WebLogic RCE) Méthode : envoi d’une SOAP envelope déclenchant l’exécution d’un reverse shell Python
Step 1: Initial Foothold : Gained entry through a basic Exchange ProxyLogon exploit.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercriminal group claiming the compromise of Hungarian public-sector entities, using CVE-2017-10271 for initial access, pivoting through Active Directory trust relationships, extracting credentials from Oracle Identity Manager, accessing VMware infrastructure, encrypting smaller business storage, and exfiltrating critical state databases.
Persistent data leak operator and cybercriminal actor conducting intrusions against high-impact organizations, stealing and exfiltrating sensitive data, publishing or selling stolen datasets, and in at least one reported case deploying ransomware against a Romanian government agency.
Financially motivated initial access broker activity targeting poorly protected systems, claiming responsibility for the ANCPI intrusion and offering allegedly stolen data for sale.
Allegedly compromised Romania’s ANCPI, claims theft of citizen and agency data, copying GitLab servers/source code, deploying ransomware, and attempting to sell the stolen data on a dark web forum. The actor is also described as known for selling data stolen from organizations worldwide.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.