Alduin is a recently observed forum persona associated with unverified claims of data exposure affecting French organizations. The persona has advertised purported datasets attributed to a French local-government association, a newspaper and magazine retailer, and a restaurant-management platform. The claims describe alleged SQL injection, abuse of a purported authenticated application programming interface authorization weakness, and CRM data scraping. Claimed exposed material included customer and business records, account data, and—in the restaurant-platform allegation—credentials and payment-service secrets. None of the alleged compromises, datasets, or exploitation methods has been independently verified. The reported activity, if substantiated, would affect French local government, retail customers, and restaurant businesses.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed compromise and public release of Association des Maires de France data, including approximately 114,000 subscriber records, account-password hashes, and a smaller set of town-hall login addresses with plaintext passwords. The claim remains unverified.
Claimed publication of approximately 270,000 Journaux.fr delivery and billing records and disclosure of a purported authorization flaw in an API endpoint that could permit authenticated users to set their own store-credit balances. The claims are unverified.
Claimed scraping of a French restaurant management platform CRM, allegedly exposing restaurant client records containing plaintext remote access passwords, database credentials, email passwords, and live payment gateway secret keys.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.