Eraleign, operating under the apt73 label, has claimed 15 victims since first appearing on tracking systems in early June 2026, with activity clustering heavily in early July before tapering to a single claim in the following weeks. Sector and country data for these claims are not available, and no attributable geographic or industry pattern can be established from the current listings. No MITRE ATT&CK techniques are catalogued for this group at this time, so no verified tooling or intrusion methodology can be cited. The group's self-description is not on file, meaning any claims about its capabilities or motives remain unverified. Victim names published to date span a mix of cloud services, industrial, and hospitality-linked domains, though this briefing cannot confirm the accuracy or completeness of those claims.