hackboy is a threat actor name associated with the claimed sale of allegedly stolen banking data tied to KBank Vietnam, part of Kasikornbank’s operations in Vietnam. The actor has been observed advertising a purportedly large financial dataset containing credit registration information for accepted and pending loan applications. The claimed data exposure involves highly sensitive personal, employment, and credit-risk information, indicating an interest in monetizing stolen financial records. Available reporting supports characterization of hackboy as a financially motivated data seller rather than a clearly attributed nation-state or established intrusion set. The activity is consistent with theft and attempted commercialization of data from financial-sector information repositories. Claimed tradecraft associated with the incident includes access to internal repositories, collection of locally stored data, and exfiltration over web-based channels, but the underlying intrusion details and attribution remain limited. There is no high-confidence evidence in the available material to support broader operational history, sub-groups, or additional aliases beyond the single observed name. The actor’s known targeting in this context is the banking and financial services sector in Vietnam, with the apparent objective of profiting from compromised customer financial identity data. If the claims are authentic, the operation would enable downstream fraud, identity theft, and targeted financial scams against affected individuals.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.