Demetrius is a seller persona observed advertising an alleged corporate dataset purportedly taken from SMSA Express, a major Saudi courier and logistics company. The activity is associated with the attempted sale of claimed stolen shipment data and is best characterized as a data-broker or cybercriminal marketplace identity rather than a well-established intrusion set or nation-state actor. The advertised dataset was described as containing large-scale shipment records with sender and recipient personal details, contact information, addresses, shipment tracking information, package status and scan data, package characteristics, declared values, currencies, and commodity descriptions. If authentic, such data could support downstream fraud, social engineering, and privacy harms, including convincing parcel-delivery scams and mapping of personal or commercial relationships. At high confidence, Demetrius has been linked to the sale of allegedly stolen corporate data and associated extortion-adjacent criminal monetization behavior. However, the underlying breach claim was explicitly unverified, no sample records were published, and the claimed archive and record count were not independently corroborated. There is no high-confidence evidence here establishing broader tooling, intrusion tradecraft, malware usage, or attribution to a specific country, organization, or state sponsor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.