sub21 is a forum persona associated with the alleged public release of a database purportedly stolen from ExpoEmpleo, a Uruguayan employment platform. The actor was observed posting what was described as a free leak rather than offering the data for sale, indicating activity centered on unauthorized disclosure and data exposure rather than a documented ransomware operation. The claimed dataset allegedly contained a large volume of personally identifiable information relating to job seekers, creating potential downstream risks including identity theft and recruitment fraud. Available reporting attributes the incident to a weakly secured platform, but the breach claim and the authenticity and scope of the leaked data were not independently verified. No high-confidence evidence links sub21 to a broader intrusion set, malware family, nation-state program, or established criminal group, and no corroborated information is available on the actor’s origin, infrastructure, or wider operational history.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.