GordonFreeman is an alias used by a threat actor that publicly claimed responsibility for a cyberattack against Spain’s Ministry of Science, Innovation and Universities. The actor advertised allegedly stolen ministry data for sale to the highest bidder and published sample records on an underground forum as purported proof of compromise. Reported sample material included personal records, email data, enrollment-related information, and screenshots of official documents, indicating an intrusion affecting sensitive administrative systems used by researchers, universities, students, and other public-facing stakeholders. The actor claimed the intrusion was achieved through exploitation of a critical insecure direct object reference (IDOR) vulnerability, which allegedly exposed valid credentials and enabled full administrative access. Based on the available claims, the actor’s observed behavior is consistent with initial access through application-layer exploitation, followed by post-compromise access abuse and attempted data monetization. High-confidence reporting links the incident to operational disruption at the ministry, including partial shutdown of electronic services and suspension of administrative procedures. However, the authenticity of the actor’s full breach claims and the purported stolen data was not independently verified. No broader attribution, state nexus, sub-group structure, or sustained campaign history is established from the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.