ArcRaidersPlayer is a threat actor observed as a collaborator in a criminal data-theft and sale operation targeting Colombian government infrastructure. The actor was named alongside NyxarGroup, Petro_Escobar, and CryptoDead in a claimed breach involving the Department of Huila government extranet in Colombia. In that incident, the operation allegedly obtained government employee and municipal administrative records and offered the stolen dataset for sale, indicating participation in data exfiltration and monetization of compromised information. Available reporting directly ties ArcRaidersPlayer to activity affecting a government victim in Colombia and to a broader cluster of actors involved in selling stolen public-sector data. The observed tradecraft in the associated intrusion and monetization chain included exploitation of a public-facing application, collection of data from information repositories, gathering of employee identity information, and exfiltration or transfer of stolen data over web services. Based on the currently available facts, ArcRaidersPlayer is best characterized as a financially motivated cybercriminal actor involved in unauthorized access and data-theft operations against government entities. No high-confidence attribution to a nation state, formal sub-groups, or additional aliases is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.