Maple Forge is a Canadian-focused criminal fraud operator involved in the sale of custom synthetic identities designed to pass verification and support downstream financial and account-fraud activity. The operator has been observed marketing fabricated identities with established credit profiles and offering supporting services intended to make those identities operational and resilient during onboarding, recovery, and step-up verification processes. Reported add-ons include postal verification support, delivery of a physical bank card to a drop location, and provision of a SIM to facilitate two-factor authentication and account recovery workflows. Maple Forge operates within the broader underground market for verified access, KYC bypass, and synthetic identity services. Its offerings indicate capability in creating and maintaining fraudulent personas that can survive identity checks, age on platforms, and be used for abuse of accounts or financial services. The actor’s tradecraft is aligned with fraud enablement rather than disruptive intrusion, emphasizing synthetic identity creation, verification circumvention, and support for persistent access to services that rely on identity proofing and recovery controls. Available reporting supports characterization of Maple Forge as a financially motivated cyber-enabled fraud actor with a Canada-oriented focus. High-confidence evidence directly ties the actor to synthetic identity sales and associated verification support services; broader intrusion, malware, or ransomware activity is not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.