alameda_slim is a threat actor associated with the theft and public exposure of sensitive medical data. The actor has explicitly presented themselves as specializing in stealing healthcare-related information and has been linked to a breach of a Mexican clinical laboratory in which patient records were allegedly exfiltrated and released publicly. Reported victim data included highly sensitive diagnostic and personal information, indicating a focus on healthcare-sector data theft rather than disruptive or destructive operations. Observed behavior indicates capabilities centered on initial compromise of victim environments, data exfiltration, and post-compromise publication of stolen information. The actor has also claimed to have released stolen data without charge as retaliation after an alleged ignored paid penetration-testing offer, suggesting coercive or retaliatory behavior adjacent to extortion, but there is not sufficient high-confidence evidence to classify the activity as a confirmed ransomware or extortion operation under the available taxonomy. No reliable evidence in the available facts supports attribution to a nation state, a broader intrusion set, or additional sub-groups or aliases beyond the name alameda_slim. Known targeting in the available reporting is concentrated on the healthcare sector in Mexico, specifically a clinical laboratory handling patient test records. The actor’s publicly stated specialization and the nature of the exposed records indicate an emphasis on acquiring and leaking sensitive medical information for financial or retaliatory purposes.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.