ExtaseHunters is a threat actor associated with an alleged large-scale breach of ANTS, the French government agency now branded France Titres, which manages secure identity documents and legal titles. In the reported operation, ExtaseHunters was identified alongside EvilDump and Breach3d, with ExtaseHunters and Breach3d presented as collaborators and the stolen data advertised for sale. The claimed dataset consisted of approximately 18 million records containing highly sensitive citizen identity information, indicating a data-theft and monetization operation targeting the French public sector. Reported victim data included identity, contact, birth, address, and government-verification attributes, creating substantial risk of identity fraud and administrative impersonation if authentic. The operation is consistent with intrusion against a public-facing application, collection of data from information repositories, exfiltration for resale, and post-compromise monetization. Based on the available facts, ExtaseHunters is best characterized as a financially motivated data-breach actor engaged in exfiltration and sale of stolen government-held personal data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.