Zestix, also known as Sentap, is a financially motivated cybercriminal and initial access broker associated with credential-driven intrusions into enterprise file-sharing and collaboration environments. The actor has been linked to the compromise of approximately 50 organizations worldwide, using credentials harvested by information-stealing malware—including RedLine, Lumma, and Vidar—to authenticate to ShareFile, Nextcloud, and ownCloud services. The activity relied on valid accounts, frequently where multifactor authentication was absent, rather than exploitation of software vulnerabilities. Zestix identifies corporate credentials in infostealer logs, uses them to access exposed cloud repositories, exfiltrates sensitive material, and sells either access or stolen datasets through underground forums. Reported victim material has included defense and engineering designs, aviation documentation, health records, legal files, financial archives, infrastructure data, and other corporate records. The actor has also divided stolen datasets into separately priced categories for resale, suggesting post-exfiltration review and indexing of valuable content. Some credentials used in the campaign had remained available in criminal log collections for years, reflecting the reuse of unrotated passwords and active sessions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An initial-access broker and data-extortion actor that applies commodity AI/LLM tools to index stolen data, surface high-value information, and sell segmented data tranches to different criminal buyers.
Conducted credential-based intrusions into cloud file-sharing platforms using credentials harvested by infostealers, leading to theft of defense, healthcare, legal, and financial data without exploiting software flaws.
Initial access broker of Iranian origin, selling access to compromised corporate file-sharing portals, motivated by financial gain and linked to ransomware group FunkSec.
Zestix is known for stealing and selling corporate data obtained by breaching file-sharing platforms such as ShareFile, Nextcloud, and ownCloud, using credentials harvested by infostealer malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.