AntiBrok3rs, also known as Nam3L3ss, is a financially motivated access broker and data leaker active against the energy sector. The actor published data associated with at least 15 energy-sector victims affected by the 2023 MOVEit supply-chain exploitation. The exposed utility-related data was traced to a compromise of CLEAResult, a North American energy-efficiency and sustainability-program consultant used by multiple utilities, rather than demonstrated direct compromises of each affected utility. AntiBrok3rs publicly denied affiliation with the Cl0P ransomware operation despite the data’s association with the Cl0P MOVEit campaign. Known affected organizations included CenterPoint Energy, Entergy, Nevada Energy, and Appalachian Power. The actor's country of origin and operating location are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An access broker that reportedly targeted several energy companies, including CenterPoint Energy, in 2024.
Access/data broker persona leaking MOVEit-derived victim data (including energy utilities) on forums; suspected by some to be Cl0P-adjacent but denies ties.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.