Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Exploits CVEs in the wild

ByteToBreach

Also known asbytetobreach

ByteToBreach is a financially motivated cybercriminal described as a data leak trader and access broker, active since at least June 2025. The actor operates across DarkForums, Dread, Telegram, Pastebin, and a public WordPress site branded "Pentesting Ltd.," which was used for self-promotion, victim shaming, and monetization. Reported communication channels include Telegram, ProtonMail, Tuta, Gmail, Signal, and Session, and the actor has also shared or sold data via Google Drive and OwnCloud. The content describes ByteToBreach as targeting high-impact organizations globally across banking, insurance, telecom, airlines, transportation, healthcare, universities, government, and IT services. Reported victim geography spans multiple countries, including the United States, India, Italy, Spain, Russia, the Netherlands, France, Finland, Poland, Portugal, Cyprus, Seychelles, Singapore, Chile, Panama, Uzbekistan, Kazakhstan, Thailand, Ukraine, Ethiopia, and Sweden. The victimology is described as financially driven rather than politically constrained, including targeting of CIS countries as well as Ukraine. Reported initial access methods include exploitation of known vulnerabilities in internet-facing cloud and enterprise software, reuse of stolen credentials from infostealers and phishing, and occasional brute force or abuse of misconfigurations. Post-compromise behavior described in the content includes lateral movement, credential harvesting, tunneling, compromise of backups and security tooling, data exfiltration, extortion, and in at least one claimed case ransomware deployment. Specific claimed techniques in the content include exploitation of public-facing applications, SQL injection, Oracle WebLogic exploitation, Microsoft Exchange ProxyLogon exploitation, Apache Solr local file inclusion, JSP reverse shell upload, Jenkins compromise, Docker escape, SSH key pivots, SQL copy-to-program pivots, credential dumping, tunneling with Ligolo, and exfiltration over web services. The actor is associated in the content with claimed breaches involving VUMI Group, National Oil Ethiopia PLC, Viking Line, CGI Sverige AB and Sweden's e-government platform, Eurofiber France's GLPI and ATE environments, and other alleged victims including banks, telecom providers, airlines, universities, and government-related entities. In the Eurofiber case, ByteToBreach claimed theft of data from roughly 10,000 business and government clients. KELA describes the actor as credible and adaptable, noting that some leaked datasets were later corroborated by affected organizations or contained verifiable technical artifacts. Known aliases and related identifiers directly mentioned in the content include bytetobreach, ByteToBreach, Telegram handle @ByteToBreach, prior Telegram names "CvHNWwEG" and "inesslopez," and the public-facing brand "Pentesting Ltd." The content assesses the actor as likely a single technically skilled individual or a small group.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Insurance

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
MITRE ATT&CK

Tradecraft

23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

13 of 15 tactics30 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1589
Gather Victim Identity Information
T1589.001
Credentials
TA0001
Initial Access
2 techniques
T1078
Valid Accounts
T1190×2
Exploit Public-Facing Application
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1203
Exploitation for Client Execution
TA0003
Persistence
3 techniques
T1078
Valid Accounts
T1098
Account Manipulation
T1098.004
SSH Authorized Keys
T1505
Server Software Component
T1505.003
Web Shell
TA0004
Privilege Escalation
3 techniques
T1068
Exploitation for Privilege Escalation
T1078
Valid Accounts
T1098
Account Manipulation
T1098.004
SSH Authorized Keys
TA0005
Stealth
1 technique
T1078
Valid Accounts
TA0006
Credential Access
2 techniques
T1003
OS Credential Dumping
T1212
Exploitation for Credential Access
TA0007
Discovery
1 technique
T1082
System Information Discovery
TA0008
Lateral Movement
2 techniques
T1021×2
Remote Services
T1210×2
Exploitation of Remote Services
TA0009
Collection
3 techniques
T1005×3
Data from Local System
T1074
Data Staged
T1213×2
Data from Information Repositories
TA0011
Command and Control
1 technique
T1572
Protocol Tunneling
TA0010
Exfiltration
3 techniques
T1030
Data Transfer Size Limits
T1537
Transfer Data to Cloud Account
T1567
Exfiltration Over Web Service
TA0040
Impact
2 techniques
T1486
Data Encrypted for Impact
T1490
Inhibit System Recovery
WEAPONIZED

Associated vulnerabilities

1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.

ACTIVITY FEED

Recent activity

10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

darkwebinformerNews
Apr 13, 2026
International Insurer VUMI Group Allegedly Breached, 300K Policyholders and 25K Staff Exposed With SSNs, Passports, and W-9 Forms

Claims a data breach against VUMI Group involving systematic database enumeration and six days of throttled exfiltration of insurance records, SSNs, passport scans, W-9 forms, and other PII, then distributes the stolen data via OwnCloud.

Read more
darkwebinformerNews
Mar 24, 2026
Alleged Full Infrastructure Compromise of National Oil Ethiopia With 800GB ERP Database Exfiltration, Veeam and Kaspersky Compromise, and Ransomware Deployment

Conducted a ransomware and data theft intrusion against National Oil Ethiopia, claiming full infrastructure compromise, exfiltration of 800+ GB of data, compromise of Active Directory, Veeam backups, and Kaspersky security tooling, followed by ransomware deployment.

Read more
darkwebinformerNews
Mar 12, 2026
Full Source Code of Sweden's E-Government Platform Leaked From Compromised CGI Sverige Infrastructure

Leaked the full source code of Sweden's e-government platform after allegedly compromising CGI Sverige AB infrastructure, and claimed to have also collected citizen PII databases, electronic signing documents, staff database data, API signing systems, and pivot credentials.

Read more
darkwebinformerNews
Mar 11, 2026
Viking Line Ferries Allegedly Breached With Full Passenger Database and Payment Data Leaked

Claimed a data breach against Viking Line in Finland, alleging theft and public release of traveler personal information, vehicle registration plates, and payment-related transaction data, including abuse of the NetAxept payment integration.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping23

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.