Bastardaseller is a financially motivated fraud actor associated with the broader ASGARD fraud network, a structured criminal ecosystem focused on creating, verifying, and selling European business accounts for abuse as mule accounts. The actor has been linked to operations targeting freelancer-oriented fintech and digital banking platforms that offer rapid remote onboarding, streamlined identity verification, and cross-border payment capabilities. Bastardaseller has been observed distributing verified accounts through Telegram and dark web marketplaces. The operation follows a staged fraud workflow. It begins with phishing and social-engineering activity to obtain victims’ personally identifiable information. The stolen identity data is then used to register fraudulent business accounts on fintech platforms, with operators leveraging infrastructure designed to appear locally consistent during signup and verification. To satisfy know-your-customer requirements, victims are induced to complete identity checks under false pretenses, enabling the fraudulent accounts to pass verification using genuine identity documents and live checks. After verification, control of the accounts is transferred to devices operated by the fraud network, allowing the accounts to be used for laundering stolen funds. Bastardaseller’s activity demonstrates capabilities spanning initial access through phishing, spoofing of local presence during registration, and post-verification account takeover for financial fraud and fund movement. The actor’s role within ASGARD indicates specialization in the industrialized creation and sale of verified accounts rather than conventional intrusion operations. Confirmed targeting in the available reporting centers on France, with the broader abuse focused on European fintech account ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.