Boldenis77
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known publicly as Boldenis77 emerged in mid‑2022 after contacting DataBreaches.net with a claim of having exfiltrated 13 GB of data from the Brazilian real‑estate firm Lopes. In their correspondence they asked to be referred to by the alias Boldenis77, noting that they also used the names Matron Group and Matrong in earlier communications. The actor supplied sample files to the journalist, which consisted of internal documents dated from December 2021 through May 2022, some of which pertained to customers or buyers. According to the spokesperson, the data was obtained after gaining access to one or more of Lopes’s servers. No further technical details about the stolen data set were disclosed in the exchange.
Boldenis77 stated that they selected Lopes because they were specifically searching for a real‑estate company to target, having attempted intrusions against four such firms before succeeding with Lopes. The initial compromise was described as occurring in February 2022 through a backdoor placed on the victim’s network. After establishing persistence, the actor reportedly issued a ransom demand to Lopes, naming the individuals Mr. Marcos Lopes and Mr. Cyro Naufel as the contacts. Lopes did not respond to the demand, and Boldenis77 indicated that they never encrypted any files during the interaction. By the time of the July 2022 correspondence with DataBreaches, the actor said they had lost access to the compromised systems.
Publicly available reporting does not link Boldenis77 to any state‑sponsored program or known criminal consortium; the actor remains unattributed beyond the self‑described aliases. No evidence of malware families, specific tooling, or infrastructure was provided in the discussions with the journalist. The actor’s communications were limited to email exchanges and did not include any code samples or indicators of compromise. Consequently, any assessment of affiliations or technical capabilities would be speculative and is omitted here.
The only publicly documented operation attributed to Boldenis77 is the intrusion into Lopes, which resulted in the alleged 13 GB of data being taken. The extent of any subsequent data leakage, sale, or misuse of that material has not been confirmed by either the victim or independent sources. No additional campaigns or victims have been reported in open‑source sources tied to the Boldenis77 moniker. As a result, the actor’s activity profile remains defined by this single, disclosed incident.
Incidents
Attributed incidents are available to members.
0 incidents