GenesisGroup is a cybercriminal threat actor observed in underground data-leak activity targeting French entities during the late-2025 to early-2026 surge in leak claims against France. The actor has been attributed to France in reporting that analyzed francophone underground communities and leak-posting behavior. GenesisGroup appeared among a cluster of predominantly French or francophone actors active on cybercrime forums and related chat ecosystems, where activity was characterized as opportunistic, notoriety-driven, and focused on publicizing alleged stolen data rather than ransomware or hacktivist operations. The broader campaign environment in which GenesisGroup was observed centered on alleged data leakage and exfiltration claims against French targets, with activity amplified by underground-forum dynamics and media attention. High-confidence reporting supports GenesisGroup’s association with targeting in France, but does not provide actor-specific evidence in this record for additional victim geographies, sector specialization, or a fuller set of bespoke tactics beyond participation in the data-leak ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed among the threat actors detected in the CTI research covering the spike in data-leak claims against French targets.
Listed among the top 30 threat actors most frequently associated with activity against French targets; exclusively focused on French targets during the period.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.