Rabid is a threat actor name associated with the advertisement of allegedly stolen data from the Chartered Institute of Bankers of Nigeria, a major professional body serving Nigeria’s banking and finance sector. The reported activity centers on monetizing a large-scale data breach by offering purported access to a full organizational database, indicating a financially motivated intrusion or brokerage role focused on the sale of compromised information rather than publicly stated ideological or espionage objectives. The advertised dataset reportedly included extensive personal and professional records relating to members and applicants, such as identity documentation, academic and professional certification materials, membership records, internal documents, and source code tied to online systems. If authentic, this combination of personal data and technical material would create downstream risk for identity fraud, professional impersonation, credential abuse, and targeted social engineering against banking-sector personnel, while also increasing the likelihood of follow-on compromise through analysis of exposed application logic and embedded secrets. Based on the available facts, Rabid has demonstrated data theft and monetization behavior consistent with breach-market actors engaged in exfiltration and post-compromise exploitation. There is not enough high-confidence information to attribute Rabid to a nation state, link the actor to a broader intrusion set, or confirm additional aliases, sub-groups, or operational history beyond this reported breach-sale activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.