Eliasxy is a cybercriminal persona associated with alleged data-leak activity on underground forums. The actor has been publicly linked to claims of compromising Burger King France and Wendy’s UK and publishing purportedly stolen datasets. Reported sample data attributed to these claims included operational, personnel, and franchise-related information, but the alleged intrusions were not publicly confirmed by the named organizations at the time of reporting. Available reporting supports characterizing Eliasxy primarily as a data-leak actor rather than a ransomware operator. The observed activity is consistent with theft and publication of allegedly stolen information for notoriety or criminal exposure rather than encryption-based extortion. There is no high-confidence evidence in the available material tying Eliasxy to a specific nation-state sponsor, formal intrusion set, or broader malware family. No reliable attribution to a country of origin is currently available. Known alias: Eliasxy.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed among the threat actors detected in the CTI research covering the spike in data-leak claims against French targets.
Allegedly compromised Burger King France and Wendy's UK and posted purportedly stolen datasets on the dark web, including employee contact information and senior staff data; one sample also contained a Sentry API key that could enable further compromise. Breach not confirmed by victims; samples appear structurally legitimate but require verification.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.