GordonFreeman is an alias used by a forum-based cyber threat actor associated with the advertisement and sale of allegedly stolen or aggregated sensitive data. Activity attributed to this handle includes offering what was claimed to be the complete electoral roll of Chile, allegedly sourced from SERVEL, and separately claiming responsibility for a cyberattack against Spain’s Ministry of Science, Innovation and Universities while offering purportedly stolen ministry data for sale. Reported sample data tied to these claims included large volumes of personal information and administrative records. The actor’s observed operations center on monetizing access to sensitive datasets through underground forum postings and bidder-based sales. In the Chile case, the advertised material was described as a single large database containing nationwide voter information, but the claim was explicitly unverified and could reflect aggregation of legally published electoral data rather than a confirmed intrusion. In the Spain case, the actor claimed to have exploited an IDOR vulnerability to obtain credentials and administrative access, then exfiltrated ministry data and published samples as proof; however, the authenticity of the stolen data and the intrusion details were not independently confirmed. Spanish authorities reportedly linked the ministry disruption to a cyberattack, but public confirmation of the actor’s specific claims was limited. Based on the available reporting, GordonFreeman is best characterized as a financially motivated data broker or intrusion actor operating in criminal forums. Directly supported behaviors include attempted sale of sensitive data, public release of sample records to support sale claims, and alleged acquisition of information from institutional repositories. High-confidence attribution to a nation state, a specific malware family, or a broader organized cluster is not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Advertising an alleged complete Chilean electoral roll database on a forum; no intrusion method is described and the claim remains unverified.
Claims to have breached Spain’s Ministry of Science, Innovation and Universities, leaked sample data on underground forums, and attempted to sell allegedly stolen data to the highest bidder.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.