xMetah is a threat actor alias associated with the alleged publication and monetized offering of stolen data. The actor has been observed claiming possession of a database purportedly taken from Région Occitanie in France, including a separate collection described as student facial photographs. The claimed victim set indicates targeting of a French regional public-sector entity with education-related data holdings, and the exposed information reportedly included large volumes of personally identifiable information affecting students and family members, including minors. Based on the observed activity, xMetah demonstrates data theft and exfiltration behavior followed by attempted commercialization of the stolen dataset through a restricted-access forum. The actor's known activity in this case is consistent with financially motivated breach trading or leak-market behavior rather than ransomware deployment. High-confidence reporting supports the actor's involvement in advertising or distributing allegedly stolen data, but does not establish broader tooling, intrusion methods, malware usage, persistence mechanisms, or attribution to a nation-state or organized intrusion set. No corroborated sub-groups or additional aliases are established beyond xMetah.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.