Marak is a cybercriminal group linked by French authorities to intrusions against healthcare institutions, medical-sector companies, and a messaging service used by French customs. The group was investigated following the 2025 compromise of Hôpital privé de la Loire in Saint-Étienne. The intrusion involved impersonation or compromise of a physician account by exploiting weaknesses in authentication for dematerialized professional credentials, enabling access to electronic patient data. Authorities attribute the exfiltration of nearly four million patient records in total to the group’s activity. Five suspected members, aged 16 to 22, were arrested; three were subsequently indicted for offenses involving automated data-processing systems and placed under judicial supervision. An individual using the Marak alias also claimed responsibility for the hospital breach and reportedly attempted to sell stolen data. Marak’s confirmed operational behavior includes credential compromise or account abuse for initial access, access to sensitive medical information repositories, and large-scale data exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for the 2025 breach of Hôpital privé de la Loire, which exposed health and personal data for more than 727,000 patients and trusted third parties. The actor reportedly attempted to sell the stolen data, but it was neither sold nor published.
Claimed responsibility for compromising a doctor's account at a French hospital, using that access to reach the hospital's internal systems and exfiltrate sensitive records for more than 727,000 people. The actor reportedly attempted to sell the stolen data for €2,000–€5,000, though it was reportedly neither sold nor published.
Listed among the threat actors detected in the CTI research covering the spike in data-leak claims against French targets.
Cybercriminal group accused of targeting healthcare institutions, medical-sector companies, and a messaging service used by customs, including theft and exfiltration of large volumes of patient data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.