Cybernox is a cybercriminal persona observed in connection with underground data-leak activity. The actor has been publicly associated with a collaborator using the alias ChimeraZ in a claimed leak involving the member database of Lancy FC, a football club in Geneva, Switzerland. In that incident, the actors allegedly exposed a database containing extensive personally identifiable information on club members, including data that may pertain to minors and their guardians. The claim was presented as a free leak on an underground forum, but its authenticity was not independently verified. Available reporting supports characterizing Cybernox as involved in data exposure and criminal leak operations rather than ransomware or hacktivist activity. The observed behavior is consistent with exfiltration and post-exploitation use of stolen information for notoriety or downstream abuse such as phishing and fraud. Attribution beyond the alias is currently not available, and there is no high-confidence evidence in the supplied facts tying Cybernox to a specific country of origin, malware family, or broader intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed among the threat actors detected in the CTI research covering the spike in data-leak claims against French targets.
Collaborated in the claimed leak of Lancy FC member database data posted to an underground forum.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.