ChimeraZ is a forum-based threat actor active since at least April 2026, primarily associated with claims to possess, sell, and freely distribute alleged databases from French organizations. The actor's purported victims span real estate, retail, e-commerce, industrial equipment, renewable-energy suppliers, legal services, travel, municipal services, emergency services, and recruitment platforms. ChimeraZ has also claimed activity affecting a Swiss football club. The actor has repeatedly advertised alleged datasets through underground forums, using free releases, reply-gated downloads, forum-point access, and sales denominated in cryptocurrency. Claimed datasets commonly contain personal, customer, employee, business, property, order, CRM, invoice, or operational records. Several claims have involved French real-estate organizations, including platforms, agencies, and property-management-related services. ChimeraZ has been linked publicly to collaborators using the aliases misere, Cybernox, and NightBroker; misere and ChimeraZ jointly claimed breaches affecting legal-services and vehicle-inspection organizations. Many of ChimeraZ's intrusion and data-theft claims remain unverified, and public confirmation by the named victim organizations was generally unavailable. A confirmed data-exfiltration incident affecting an Aveyron recruitment platform was attributed by its operator to compromise of a recruiter account's credentials; ChimeraZ subsequently claimed and distributed part of the allegedly stolen data, though attribution of the credential theft itself to ChimeraZ has not been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed to be selling an unverified 1.92 GB Citya Immobilier dataset allegedly containing personal, property-management, and building-access information, including approximately 50,000 digicodes, in exchange for XMR.
Cybercriminal actor claiming responsibility for the exfiltration of recruitment-platform data belonging to the Département de l’Aveyron. It reportedly uses stolen recruiter-account credentials to access candidate databases and releases stolen data publicly. It claims recurrent targeting of public-sector, emergency-service, health-care, and transport-related organizations in Occitanie.
Cybercrime actor allegedly selling stolen customer data from a French baby retailer on a forum, including personal information, addresses, order history, and sensitive delivery-note details such as building entry codes and interphone instructions.
Selling an allegedly stolen database from French baby goods retailer madeinbebe.com on a cybercrime forum, with sample records published for free across multiple file hosts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.