All Egyptian Cyber Warriors is a self-identified threat actor name associated with a suspected compromise of the Argentine Football Association (AFA). The activity appears to have involved the use of stolen credentials, likely originating from an earlier infostealer infection affecting an AFA software developer, to obtain broad administrative access across AFA systems. Reported access included database administration interfaces, internal management portals, media infrastructure, and competition-management systems. The intrusion became publicly visible through mass emails sent from legitimate AFA infrastructure carrying politically charged messaging tied to Egypt’s elimination from the World Cup, indicating a likely retaliatory or nationalist theme. The actor’s observed behavior includes initial access through compromised credentials, post-compromise access to multiple internal platforms, and exfiltration or attempted monetization of stolen data through cybercrime forum advertisements. Reported exposed information included staff and club-related records, contact information, user-role data, registration metadata, subdomain access listings, and some passwords, with weak password reuse across internal systems reportedly amplifying the impact. Based on the available facts, the group is best characterized as an opportunistic or politically themed intrusion set rather than a well-established nation-state cluster. Attribution beyond the self-claimed name is not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.