Saber is a little-documented threat actor name that has appeared in reporting about a public leak of data reportedly originating from the North Korea-linked Kimsuky espionage group. Available information indicates Saber was described as one of two unaffiliated actors associated with that leak activity. There is insufficient high-confidence information to characterize Saber’s origin, organizational affiliation, victimology, tooling, tradecraft, or broader campaign history. No corroborated evidence in the available material supports attributing Saber to a state, assigning specific targeting patterns, or assessing a dominant operational motivation beyond involvement in a data exposure incident linked in reporting to Kimsuky-related material.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.