ASGARD is a fraud network associated with the creation and sale of verified European business accounts used as mule accounts for laundering stolen funds. The network has been linked to the actor Bastardaseller, which appears to operate as part of the broader ASGARD ecosystem and to distribute accounts through Telegram and dark web marketplaces. ASGARD specializes in abusing freelancer-focused fintech and digital banking platforms by registering business accounts with stolen identities, completing know-your-customer checks through social engineering, and then transferring operational control of the accounts to the fraud operators. Observed tradecraft follows a structured lifecycle. Initial access is obtained through phishing campaigns designed to collect personally identifiable information from victims. The stolen identity data is then used to fraudulently register fintech accounts, with operators using infrastructure intended to mimic local French network characteristics during signup. To satisfy KYC requirements that require a real person and authentic identity documents, victims are socially engineered into completing verification steps such as selfie or video checks under false pretenses. After verification succeeds, the accounts are taken over on operator-controlled mobile devices and used as mule accounts to move illicit proceeds rapidly, including cross-border transfers. ASGARD’s activity is centered on financial fraud rather than espionage or disruptive operations. Its core capability is the industrialized provisioning of verified accounts that can support payment fraud and money laundering workflows. High-confidence behaviors include phishing-based collection of victim data, social-engineering-enabled account verification, account takeover and post-verification control transfer, and the exfiltration or monetization of stolen identity information in support of fraudulent account creation. France is directly implicated as a targeted geography in the observed activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.