Xuanye group, also using the name Xuanyewen, is a threat actor associated with an extortion attempt against the UK-based online fashion retailer ASOS. Its publicly documented activity centers on unauthorized access to third-party customer-communication platforms and the use of compromised messaging infrastructure to pressure the retailer through its own mobile application. In the October 6 incident, an attacker impersonated a trusted contact to obtain an ASOS employee’s login credentials, then used those credentials to access third-party platforms containing personal and customer account information. The access enabled unauthorized push notifications to ASOS customers. These notifications addressed the retailer’s data protection and IT teams, threatened to leak data unless the company engaged with the attacker, and directed recipients to a Telegram channel identifying itself as Xuanye group. ASOS confirmed access to customer information and stated that payment information was not compromised and operations were unaffected. The incident demonstrates credential theft through impersonation, abuse of legitimate customer-messaging infrastructure, and data-leak threats as an extortion mechanism. No ransomware encryption was established. The group’s geographic origin, organizational structure, and broader operational history are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The actor claimed responsibility for the October 6 ASOS breach. ASOS confirmed that an attacker impersonated a trusted contact to obtain employee credentials and access third-party platforms, exposing personal and customer account data. The actor reportedly claimed that a Simon AI instance was compromised and used customer push notifications to publicize the breach and request engagement. Its initial claim of a compromised Snowflake instance remains unverified; Snowflake reported finding no platform compromise. JohnCZ and Moon Transfers were historical names of the associated Telegram account, not independently established threat groups. ASOS stated that payment information and operations were unaffected.
Claims to have compromised ASOS's Snowflake environment and stolen customer information, threatening to leak it unless the retailer engages. Unauthorized notifications sent through ASOS's official mobile app directed recipients to the group's Telegram channel. ASOS confirmed unauthorized access to third-party customer communication platforms and possible exposure of names and contact details, but did not confirm the claimed Snowflake compromise. The group provided no evidence substantiating that claim. No malware or ransomware use is identified in this report.
Claims responsibility for an alleged compromise involving ASOS and its Snowflake instance. Customers received an extortion message through ASOS app push notifications, suggesting unauthorized use of notification infrastructure. The claimed Snowflake compromise and customer-data theft remain unverified. The group's Telegram channel claimed payment information was unaffected, also without independent verification.
Claims responsibility for an ASOS breach and threatens to leak data unless the retailer engages. ASOS confirmed an unauthorized customer notification and is investigating activity involving third-party communication platforms. Names and contact details may have been accessed, but the claimed Snowflake compromise and data theft remain unverified. No malware or ransomware use is identified in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.