Noct is an alleged French cybercriminal figure identified as one of several administrators associated with BreachForums, a major underground marketplace focused on stolen data and cybercrime-related brokerage. In June 2025, French authorities arrested Noct alongside other prominent BreachForums-linked actors including ShinyHunters, Hollow, and Depressed, in a law-enforcement action that significantly disrupted the forum’s leadership structure. Available high-confidence reporting ties Noct to the BreachForums administrative ecosystem rather than to a distinct malware family, ransomware program, or state-backed intrusion set. The actor is associated with the cybercriminal underground centered on data leaks, stolen-data trading, and forum administration. The broader environment around Noct’s arrest was marked by heightened attention to French and francophone actors involved in opportunistic, reputation-driven cybercrime activity, particularly activity involving alleged data leaks rather than ransomware operations. Noct is best understood as part of the BreachForums administrator cohort disrupted by French law enforcement in 2025. Publicly supported facts in this context do not establish specific victim sectors, bespoke tooling, or a detailed independent intrusion tradecraft profile for Noct beyond this administrative role in the stolen-data ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as one of the prominent French threat actors arrested in June 2025, part of the background trigger for subsequent France-focused underground activity.
Noct was an administrator of BreachForum, involved in the operation and facilitation of trading stolen data on the platform.
Named as one of the additional BreachForums administrators arrested in June 2025 as part of the broader disruption of the stolen data marketplace.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.