GnosticPlayers is a financially motivated cybercriminal hacking group that emerged in 2019 and is also known by the Gnosticplayers alias. It became known for compromising online services and monetizing stolen user data and credentials through dark-web marketplaces. The group claimed responsibility for breaches affecting numerous large online companies, including Canva and Zynga, and was associated with the sale of hundreds of millions of records from web-service databases. Zynga confirmed that unauthorized parties accessed certain account-login information associated with its Draw Something and Words With Friends games. GnosticPlayers’ operations involved unauthorized access to web-hosted databases, collection and exfiltration of user-account data, and the sale of stolen credentials in staged releases. Reporting has suggested possible historical links or operational overlap with ShinyHunters, but that relationship has not been conclusively established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a well-known cybercrime group whose associated actors may be exposed in the leaked BreachForums user database; no specific operations, tooling, or TTPs are described in this content.
Referenced as a cybercrime group that some BreachForums users were previously associated with; no specific operation or campaign details provided in the content.
Referenced as a cybercriminal group that some individuals named in the ‘James’ message were allegedly connected to; no additional operational detail provided in the content.
Mentioned only as a named group in a related-post title about arrests/charges; no additional activity details are present in the provided content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.