Noct is a French-linked cybercriminal actor associated with the BreachForums underground forum ecosystem. The actor was publicly identified among a group of prominent BreachForums administrators arrested by French law enforcement in June 2025 alongside ShinyHunters, Hollow, and Depressed. Available reporting places Noct within a cluster of francophone actors tied to the forum’s administration and broader stolen-data marketplace activity. High-confidence public information about Noct’s individual operations, malware use, or distinct tradecraft remains limited. The strongest corroborated association is with BreachForums administration and the surrounding cybercrime environment centered on alleged data leaks, brokerage of stolen information, and underground forum activity. Noct has been referenced in the context of a broader surge in leak claims targeting French entities after disruptions affecting BreachForums, but that reporting does not establish Noct as the direct operator behind those campaigns. Based on currently available facts, Noct is best characterized as a French-linked cybercriminal forum administrator connected to the BreachForums ecosystem rather than a clearly documented standalone intrusion set. Detailed victimology, sector targeting, and technical capabilities attributable specifically to Noct are currently not available at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of four prominent French actors linked to BreachForums whose arrests are described as an initial trigger for the later surge in data-leak claims against French entities.
Referenced as one of the prominent French threat actors arrested in June 2025, part of the background trigger for subsequent France-focused underground activity.
Noct was an administrator of BreachForum, involved in the operation and facilitation of trading stolen data on the platform.
Named as one of the additional BreachForums administrators arrested in June 2025 as part of the broader disruption of the stolen data marketplace.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.