Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory

888

Also known as888

888 is a financially motivated cybercriminal and data broker active on cybercrime forums including BreachForums and DarkForums. Based on the provided reporting, the actor is associated with advertising, selling, leaking, or claiming responsibility for multiple large-scale data breaches affecting organizations in several sectors, including space/scientific collaboration, real estate, events, recruitment, betting, and other commercial targets. Known victims mentioned in the content include the European Space Agency (ESA), Ledil Immobilier, DinerEnBlanc.com, CIEE (Centro de Integração Empresa-Escola), ThankQCamping, Samsung Medison, MinasBet, and incidents involving Microsoft and Nokia employee data. The actor has been described as having a credible reputation on the dark web for large-scale data breaches and operating for financial gain. 888 has offered stolen data for sale or publication on forums, including exclusive sales and free-download leaks, and has requested payment in Monero in some cases. Reported exposed data types across incidents include personally identifiable information, employee and customer records, source code from private Bitbucket repositories, CI/CD configurations, API and access tokens, SQL database files, Terraform code, credentials, internal documentation, event-management data, and sensitive cloud-hosted records. Tradecraft explicitly mentioned in the content includes use of cybercrime forums for monetization and disclosure, alleged exploitation of public-facing applications, theft of data from information repositories, exfiltration over web services, and in at least one case access via a compromised third-party service. In the CIEE incident, reporting tied the exposure to a publicly accessible misconfigured Google Cloud Storage bucket. In the ESA case, 888 claimed access to external servers supporting unclassified collaborative engineering activities and posted screenshots as purported proof, though some reporting noted the authenticity of samples had not yet been independently verified at the time. No nation-state attribution is supported by the provided content. No additional aliases or sub-groups for 888 are directly established in the content beyond the actor name itself.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Real Estate Management & Development

Where they target

Geographies tied to known operations.

  • 🇫🇷 France
MITRE ATT&CK

Tradecraft

10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics11 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1589
Gather Victim Identity Information
T1589.002
Email Addresses
TA0001
Initial Access
2 techniques
T1190
Exploit Public-Facing Application
T1195
Supply Chain Compromise
TA0006
Credential Access
2 techniques
T1552
Unsecured Credentials
T1555
Credentials from Password Stores
TA0007
Discovery
1 technique
T1619
Cloud Storage Object Discovery
TA0009
Collection
2 techniques
T1074
Data Staged
T1213×3
Data from Information Repositories
TA0010
Exfiltration
1 technique
T1567×2
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
IOCS

Observables

2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

darkwebinformerNews
Apr 21, 2026
Ledil Immobilier (ledil.immo) Database Breached: Threat Actor 888 Leaks 6,700 French Real Estate User Records

Posted and freely distributed a full database allegedly stolen from Ledil Immobilier on darkforums.su, exposing 6,700 user records containing real estate customer, agent, notaire, property, and transaction data.

Read more
darkwebinformerNews
Apr 17, 2026
Global Dining Event Diner en Blanc Breached, 411K Guest Records With Event Details and Invite Codes Listed for Sale

Selling a stolen DinerEnBlanc.com database containing 411,000 user records, including personal details, event logistics, VIP/VIF status, partner links, and newsletter data, as a one-time exclusive sale for Monero.

Read more
cyfirma newsNews
Jan 30, 2026
Weekly Intelligence Report - 30 January 2026 - CYFIRMA

Financially motivated data-leak actor advertising/selling stolen datasets on underground forums; claimed breaches include a Thailand-based health supplement company (Hopeful Co., Ltd; ~158k customer records) and a UAE-based consulting/software firm (MHz Group). Authenticity not independently verified in the report.

Read more
techrepublic com securityNews
Jan 2, 2026
Hacker Claims 200GB Data Theft From European Space Agency — Here’s What We Know

888 is known for breaching organizations and exfiltrating sensitive data, which is then offered for sale on cybercrime forums. In this incident, 888 claims to have accessed European Space Agency servers for a week, stealing hundreds of gigabytes of internal data.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping10

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables2

Domains, IPs, and hashes tied to this actor, refreshed continuously.