GnosticPlayers is a cybercriminal data-breach and credential-trafficking group that emerged in 2019 and became known for compromising consumer-facing online services, stealing large volumes of account data, and selling or otherwise monetizing the stolen records on dark web marketplaces. The actor has been publicly associated with intrusions affecting companies such as Zynga and Canva, and has also claimed responsibility for breaches involving numerous other online platforms. Reporting has linked the group to the theft and sale of hundreds of millions of credentials across multiple campaigns. The actor’s operations are characterized primarily by unauthorized access to web-exposed services and databases, bulk theft of user records, and subsequent exfiltration and criminal resale of the data. Publicly attributed activity includes compromise of large user databases tied to gaming, social, and online consumer services, as well as theft of cryptocurrency in at least one separately reported case involving individuals alleged to be associated with the group. GnosticPlayers has also been linked in later reporting to personas and individuals associated with the broader BreachForums and ShinyHunters cybercrime ecosystem. Known aliases directly supported here are limited to GnosticPlayers and the lowercase form gnosticplayers. Individuals alleged in public reporting to have been core members or associates include Maxime Thalet-Fischer, Nassim Benhaddou, and Gabriel Kimiaie Asadi Bildstein; Nassim Benhaddou has also been described as later forming ShinyHunters. Because member-level attribution is distinct from group attribution, these associations should be treated as reporting on alleged membership rather than alternate names for the group itself. GnosticPlayers is best understood as a financially motivated cybercrime actor focused on large-scale credential theft, data exfiltration, and monetization of breached databases rather than espionage or destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a well-known cybercrime group whose associated actors may be exposed in the leaked BreachForums user database; no specific operations, tooling, or TTPs are described in this content.
Referenced as a cybercrime group that some BreachForums users were previously associated with; no specific operation or campaign details provided in the content.
Referenced as a cybercriminal group that some individuals named in the ‘James’ message were allegedly connected to; no additional operational detail provided in the content.
Mentioned only as a named group in a related-post title about arrests/charges; no additional activity details are present in the provided content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.