xNov is a threat actor associated with data-breach and leak activity targeting organizations in Morocco. Reported victims include Moroccan educational institutions and a Morocco-based digital platform operated for L'Oreal Morocco, with the actor explicitly framing one intrusion as a continuation of an earlier campaign against Moroccan education-sector entities. Known activity links xNov to the compromise of SUPTECH SANTE and to the Smarteez / L'Oreal Morocco breach. Observed operations center on theft and public exposure of sensitive data, including student records, business data, sales analytics, account information, application secrets, session data, and administrative records. In the education sector, xNov has been associated with the theft and monetization of student dossiers, including partial public leaking and offering additional records for sale. In the commercial breach attributed to the actor, exposed information reportedly included production database contents tied to pharmacy networks, sales operations, merchandising records, competitive intelligence material, and authentication-related data. Technique mappings associated with xNov activity include exploitation of public-facing applications, collection of data from information repositories and local systems, and exfiltration over web services. The actor’s behavior demonstrates initial access, post-exploitation data collection, exfiltration, and financially motivated sale or release of stolen information. Available reporting supports xNov as a financially motivated data-leak actor focused on Moroccan targets rather than a ransomware operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting data breach and extortion-style operations targeting Moroccan educational institutions, including SUPTECH SANTE, and linked in the content to the OFPPT breach campaign and the Smarteez / L'Oreal Morocco breach.
Leaked the complete production database of Smarteez/L'Oreal Morocco, exposing sales operations, pharmacy network data, product catalog and pricing, competitive intelligence, user accounts, OAuth2 client secrets, session records, and administrative logs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.