Hollow is a French-linked cybercriminal actor associated with the BreachForums ecosystem. The actor was publicly identified as one of four prominent BreachForums administrators arrested in Paris in June 2025 alongside ShinyHunters, Noct, and Depressed, during a broader law-enforcement disruption of the forum’s administration. Available reporting ties Hollow to the French-speaking underground scene rather than to a state-sponsored intrusion set. High-confidence public information about Hollow’s individual operations, malware usage, or distinct tradecraft remains limited. The strongest corroborated association is with BreachForums administration and with the broader surge of underground data-leak claims targeting French entities observed after the June 2025 arrests and subsequent disruption of BreachForums infrastructure. That wider activity was characterized as opportunistic, notoriety-driven, and concentrated on alleged data leakage rather than ransomware or hacktivist operations. Within that context, Hollow is best understood as a French-linked actor embedded in the cybercrime data-brokerage and leak-forum milieu surrounding BreachForums.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of four prominent French actors linked to BreachForums whose arrests are described as an initial trigger for the later surge in data-leak claims against French entities.
Referenced as one of the prominent French threat actors arrested in June 2025, part of the background trigger for subsequent France-focused underground activity.
Named as one of the additional BreachForums administrators arrested in June 2025 as part of the broader disruption of the stolen data marketplace.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.