Xuanye Group, also using the name Xuanyewen, is a threat actor associated with an October 2026 intrusion and extortion attempt against UK-based online fashion retailer ASOS. Its operators used unauthorized access to third-party customer-communication platforms to broadcast an extortion message through the retailer’s official mobile-app push notifications. The message threatened to leak data unless ASOS engaged with the attackers and directed customers to a newly created Telegram channel. Notifications reached customers in the United Kingdom, France, Ireland, Sweden and Australia, bringing the extortion attempt directly to the retailer’s customer base. ASOS determined that the attacker impersonated a trusted contact to obtain an employee’s login credentials, then used those credentials to access third-party platforms and personal and customer-account information. The incident illustrates the use of trusted customer-messaging infrastructure to publicize an intrusion and amplify extortion pressure. ASOS confirmed that payment information was not compromised and that its operations were unaffected. The attackers’ claim of a fully compromised Snowflake instance was not substantiated. No encryption-based ransomware deployment has been established. The operators’ identities, country of origin and organizational structure remain unknown.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An extortion group associated with unauthorized Asos app notifications claiming compromise of the retailer's Snowflake instance and threatening to leak customer information. Access to a customer-messaging channel was demonstrated, but the claimed database compromise and possession of stolen customer data remained unverified. Its identity, origin and initial access method were unknown.
The actor claimed responsibility for the October 6 ASOS breach. ASOS confirmed that an attacker impersonated a trusted contact to obtain employee credentials and access third-party platforms, exposing personal and customer account data. The actor reportedly claimed that a Simon AI instance was compromised and used customer push notifications to publicize the breach and request engagement. Its initial claim of a compromised Snowflake instance remains unverified; Snowflake reported finding no platform compromise. JohnCZ and Moon Transfers were historical names of the associated Telegram account, not independently established threat groups. ASOS stated that payment information and operations were unaffected.
A newly reported group associated with an unauthorized notification sent to ASOS app users. The attackers claimed to have fully compromised ASOS's Snowflake instance and threatened to leak data unless the company engaged with them. ASOS confirmed unauthorized activity involving third-party customer communication platforms and possible exposure of names and contact details, but did not confirm the claimed Snowflake compromise. No specific ransom demand or malware use was reported.
Claims to have compromised ASOS's Snowflake environment and stolen customer information, threatening to leak it unless the retailer engages. Unauthorized notifications sent through ASOS's official mobile app directed recipients to the group's Telegram channel. ASOS confirmed unauthorized access to third-party customer communication platforms and possible exposure of names and contact details, but did not confirm the claimed Snowflake compromise. The group provided no evidence substantiating that claim. No malware or ransomware use is identified in this report.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.