888, also indexed as threat_actor_888, is a financially motivated cybercrime forum persona active since at least 2024. Its activity centers on advertising and distributing datasets presented as stolen corporate information, application databases, and source code. The persona has posted on BreachForums, PwnForums, and DarkForums, offering one-time sales payable in Monero as well as free or forum-points-gated downloads. Advertisements commonly include sample records, repository listings, or screenshots as purported evidence of access. Organizations named in its listings include Accenture, the European Space Agency, Ledil Immobilier, Explorest, MyNewTerm, Diner en Blanc, Metropolis Technologies, and ACRE Africa. This activity spans information technology, real estate, travel and events, recruitment platforms, agricultural insurance, and public-sector scientific collaboration. Accenture confirmed a security incident following an associated sale listing in July 2026, while the European Space Agency confirmed an incident affecting a small number of external servers supporting unclassified collaborative engineering in December 2025. Neither confirmation established the full volume or contents advertised by the persona. Accenture also disputed the scale of an earlier employee-data listing in 2024. The operator's identity, geographic origin, and initial-access methods are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Advertises a purported Explorest dataset containing records for 263,900 unique users from 2017–2026, including names, email addresses, password-related values, countries and device tokens. The listing offers a one-time sale payable in Monero (XMR). The dataset's authenticity, source, scope and acquisition method have not been independently verified; the content does not establish whether the handle represents an individual or a group.
Claimed responsibility for an unverified September 2026 breach of Metropolis Technologies and offered allegedly stolen company source code through a forum download restricted by a points requirement.
Advertised an unverified, purported MyNewTerm applicant database for a one-time Monero sale. The samples allegedly include non-public applicant records, such as email addresses, roles applied for, application outcomes, start dates, and recruiter free-text notes, creating risks of targeted recruitment- and onboarding-themed fraud.
Forum user allegedly offering and publishing an unverified ACRE Africa breach dataset containing farmer records, source code, configuration files, access tokens, private keys, and hardcoded credentials.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.