GoreTerminal is a forum persona associated with unverified claims of publishing purported customer data from FairMoney, a Nigerian digital financial-services provider, and HopCharge, an Indian electric-vehicle charging service. The actor offered the alleged datasets without identifying an intrusion or acquisition method. The claimed records contain personal, device, financial, transaction, location, and behavioral information that, if authentic, could support targeted social engineering, phishing, account impersonation, and financial fraud. The authenticity, provenance, and scope of the alleged data releases have not been independently verified.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed to have released a free downloadable, unverified FairMoney dataset containing approximately 335,505 customer and agent records. The post does not describe an intrusion or extraction method.
Claimed to have published for free an unverified 114 MB JSON Lines product-analytics export purportedly containing 19,323 HopCharge accounts, including identities, contact details, IP addresses, device data, charging-location coordinates, and service-usage and spending metrics.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.