Marak is a cybercriminal group investigated by French authorities for intrusions targeting healthcare establishments, medical-sector companies, and a messaging service used by French customs. The group’s activity came to prominence following a 2025 compromise of Hôpital privé de la Loire in Saint-Étienne. Investigators assessed that the attackers exploited a human weakness in authentication for dematerialized professional cards, compromised a physician account, and used the resulting access to exfiltrate patient information. Authorities attributed theft of data concerning hundreds of thousands of patients in the initial hospital intrusion and alleged that the group exfiltrated nearly four million patient records overall. French authorities announced five arrests connected to Marak; suspects were between 16 and 22 years old, and three were indicted for offenses involving automated data-processing systems. Marak has also been associated with targeting national health-insurance and e-health services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for compromising a doctor's account at a French hospital, using that access to reach the hospital's internal systems and exfiltrate sensitive records for more than 727,000 people. The actor reportedly attempted to sell the stolen data for €2,000–€5,000, though it was reportedly neither sold nor published.
Listed among the threat actors detected in the CTI research covering the spike in data-leak claims against French targets.
Cybercriminal group accused of targeting healthcare institutions, medical-sector companies, and a messaging service used by customs, including theft and exfiltration of large volumes of patient data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.