CryptoDead is a threat actor associated with intrusions and public data leaks targeting Colombian government-related entities. Reported activity links the actor to the large-scale leak of data from ICFES, Colombia’s national education testing institute, and to collaboration in the attempted sale of data allegedly exfiltrated from the Department of Huila government extranet. The actor has been presented as operating under a hacktivist or politically motivated persona, with stated grievances tied to Colombian governance and public services, although the observed operations also include straightforward theft and public release of sensitive data. Known activity indicates a focus on Colombian public-sector targets and government-administered data repositories, including education-related records and departmental government systems. In the ICFES incident, CryptoDead allegedly released a large archive containing personal, academic, examination, contact, and demographic information affecting a substantial portion of the Colombian population. In a separate incident, CryptoDead was named as a collaborator alongside NyxarGroup, ArcRaidersPlayer, and Petro_Escobar in the marketing of allegedly stolen records from the Huila departmental government, including employee and municipal office data. Observed tradecraft includes collection from information repositories, theft of large structured datasets, archiving of collected data, exfiltration over web-based channels, and public leaking or sale of stolen information. Reporting also mapped the actor’s activity to exploitation of public-facing applications and possible use of valid accounts in at least some incidents. The actor’s operations are most consistently characterized by exfiltration and disclosure of sensitive government-held data rather than ransomware deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Collaborator in the sale of exfiltrated Huila government data and previously associated in the content with the ICFES Colombia data leak, indicating repeated targeting of Colombian government entities.
Hacktivist/politically motivated data leak operation targeting ICFES in Colombia, with the actor publicly releasing allegedly stolen data affecting more than 30 million Colombians.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.