Andrew is the name used for a threat actor associated with the 2025 Oracle Health intrusion affecting legacy Cerner environments. The actor has been reported as attempting to extort Oracle Health customers by demanding cryptocurrency payments in exchange for not publishing stolen data. The intrusion was reportedly enabled through the use of stolen credentials and resulted in data theft from healthcare organizations using Oracle Health systems. Reported victim impact includes hospitals and health systems, with stolen information described as including sensitive patient and medical data. Based on the available facts, Andrew is linked to data-theft-driven extortion against healthcare-sector victims rather than ransomware encryption activity. High-confidence reporting supports exfiltration, initial access through compromised credentials, and extortion behavior; broader attribution, nationality, and additional tradecraft are not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.