exfilar is a cybercriminal persona associated with the advertisement and sale of allegedly exposed or extracted data from internet-facing backends, particularly cloud-hosted application environments. The actor has been linked to multiple 2026 disclosures involving organizations in recruitment, food delivery, hospitality, art-market services, and mobile application infrastructure. Reported activity indicates a high operational tempo and a focus on monetizing sensitive data access through underground forum sales, often with cryptocurrency payment and escrow. The actor’s claimed operations center on identifying misconfigured backend services, especially publicly accessible Firebase or Firestore deployments lacking effective authentication or security rules. In several cases, exfilar asserted the ability to read entire production datasets and associated cloud storage contents without authorization; in at least one case, the actor claimed writable access, implying potential for tampering in addition to theft. Another observed offering involved sale of live production API keys for a shared deep-linking platform, presented as a phishing-enablement capability rather than a direct breach of the platform itself. This pattern suggests emphasis on opportunistic discovery of exposed assets, extraction of data at scale, and resale of either the data or the access-derived capability. Victim organizations attributed to this persona span Kenya, South Korea, Cuba, and Colombia. Claimed exposed information has included personal identity data, employment records, travel and hospitality records, financial and payment-related information, private communications, geolocation data, and other operational backend content. The actor has also been associated with claims of an automated scanning operation and with advertising paid penetration-testing services, although the operational legitimacy of those claims is not independently established. High-confidence behavioral characteristics supported by the reporting include reconnaissance for exposed services, unauthorized collection and resale of sensitive data, and financially motivated exploitation of weak cloud security configurations. The breach and access claims tied to exfilar were repeatedly described as unverified, so attribution should be limited to the underground persona and its advertised activities rather than treated as independently confirmed compromise in every cited case.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Allegedly selling data exfiltrated from Snapstartalent, claiming to have extracted candidate profiles, resumes, and recorded video interviews from an exposed Firestore backend.
Allegedly selling a full extracted dataset from the Korean food-delivery platform FLY after claiming the backend had absent Firebase rules that allowed unauthenticated read/write access.
Selling allegedly live Branch API keys that could enable phishing via a trusted shared deep-link domain used by thousands of mobile apps; described as a capability sale rather than a confirmed breach.
Advertising an alleged sale of stolen Gran Caribe Hotel Group data, including guest passport records, employee files, and corporate systems access/data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.