Sorb is a cybercriminal data broker and breach seller active on underground forums and messaging channels, primarily associated with the advertisement and sale of alleged stolen databases rather than publicly documented ransomware or disruptive operations. The actor has been observed offering datasets tied to organizations in multiple countries, including Egypt, Kuwait, Brazil, and France, indicating opportunistic victim selection across both private-sector and public-sector targets. Observed activity links Sorb to the sale of alleged customer and citizen data from a fintech and gold-investment platform in Egypt, a consumer services mobile application in Kuwait, a Brazilian worker savings system, and references to French-targeting underground activity. The advertised datasets reportedly contained large volumes of personally identifiable information, account data, demographic records, financial information, location data, and in some cases password hashes, device tokens, or application access tokens. This pattern is consistent with a threat actor focused on monetizing unauthorized access to information repositories and exfiltrated databases. Sorb’s tradecraft, as directly supported by reporting on the advertised breaches, includes exfiltration of data from information repositories, theft and resale of credentials or password hashes, and in at least one case the claimed possession of application tokens that could enable session abuse. Reporting on the Alyna incident also mapped the intrusion to exploitation of a public-facing application, while reporting on the Taiseer listing suggested the seller may have retained ongoing access to the source environment rather than possessing only a one-time dump. The actor routinely markets data with escrow options and low-to-moderate pricing, behavior typical of financially motivated underground sellers seeking rapid monetization. No high-confidence attribution to a nation state is supported. Sorb is best characterized as a financially motivated cybercriminal actor engaged in breach monetization, data trafficking, and related post-compromise sale of sensitive records.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed among the threat actors detected in the CTI research covering the spike in data-leak claims against French targets.
Referenced in related content as offering personally identifiable information of Egyptian gold investors for sale.
Selling a stolen Taiseer database containing customer PII, bcrypt password hashes, national ID scans, and gold balance data, while implying continued access to the victim environment.
Selling an allegedly stolen Alyna user database containing personal data, MD5-hashed passwords, location data, booking addresses, device information, and Kfast tokens as an exclusive single-buyer sale.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.