Second Group is a threat actor associated with the theft of Ubisoft source code and software development materials. The group has been linked to exploitation of CVE-2025-14847, also referred to as MongoBleed, to obtain unauthorized access and read server memory without authentication, after which it allegedly pivoted into internal Git repositories. Reported objectives centered on exfiltration of large volumes of intellectual property, including source code, SDKs, and multiplayer-related code. The activity attributed to this actor is distinct from separate disruptive intrusions against Ubisoft’s live game services by other groups. Based on the available reporting, Second Group’s known behavior is consistent with initial access through vulnerability exploitation followed by post-exploitation access to internal development resources and data exfiltration. Attribution to any nation state or specific country is not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.