nxe is a threat actor name associated with the attempted sale of allegedly stolen aerospace intellectual property and export-controlled technical data. The actor has been observed advertising a large dataset purportedly taken from SEKISUI Aerospace Corporation, a U.S. aerospace supplier tied to commercial Boeing programs and military-related work. The advertised material was described as including engineering documentation, CAD data, bills of materials, tooling information, process documentation, and assembly models associated with aerospace manufacturing. The activity attributed to nxe is consistent with financially motivated cybercrime centered on data theft and monetization of sensitive proprietary information. Reported behavior indicates post-compromise collection, staging, and exfiltration of internal technical data followed by attempted resale to third parties. The targeting profile in this case aligns with the aerospace and defense supply chain, particularly organizations handling controlled technical information and high-value manufacturing intellectual property. Based on the reported conduct, nxe demonstrates capabilities related to data theft, exfiltration, and post-exploitation. The available information supports characterization as a data-breach-and-sale actor rather than a ransomware operator. No high-confidence evidence in the available facts establishes broader attribution, state sponsorship, or additional aliases beyond the name nxe.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.