🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Global
GHOSTSEC

/actor/ghostsec/  ·  0 intel reports

Year Established
2015
Attribution
Unknown (International)
Motivation
Hacktivism, Anti-ISIS, Later Pro-Palestinian, Financial (Ransomware pivot)
Modus Operandi (MO)
Counter-terrorism operations, website takedowns, data leaks, ransomware deployment (post-2022)
Primary Aliases
Ghost Security Group, GhostSec Team

GhostSec (Ghost Security Group) was originally founded in 2015 as an anti-ISIS hacktivist collective operating under the broader Anonymous umbrella, dedicated to identifying and taking down online infrastructure used by the Islamic State for recruitment, propaganda, and operational coordination. The group gained international media attention and cautious acknowledgment from Western intelligence agencies for their counter-terrorism cyber operations, including reporting thousands of ISIS-affiliated social media accounts and websites to law enforcement.

However, GhostSec's operational profile underwent a significant and controversial transformation from approximately 2022 onwards. The group pivoted toward pro-Palestinian hacktivism and began conducting more aggressive offensive operations, including attacks against Israeli and Western targets. Most significantly, GhostSec entered a partnership with the Stormous ransomware operation, deploying GhostLocker ransomware against corporate targets , a dramatic departure from their original counter-terrorism mandate that attracted considerable criticism from the cybersecurity community.

GhostSec has claimed attacks against Israeli industrial control systems, critical infrastructure, and government databases, as well as Cuban government portals. Their ransomware operations have targeted organisations across multiple countries, with GhostLocker 2.0 representing a technically improved second-generation payload demonstrating continued malware development investment.

The group's evolution from anti-terrorism vigilantes to ransomware operators exemplifies the fluid and often contradictory nature of hacktivist group identities and the challenge of maintaining ideological consistency as geopolitical contexts shift and financial incentives emerge within underground criminal ecosystems.

Tactical Telemetry and Extortion Framework: In confirmed intrusions, GhostSec employs double-extortion tactics, combining high-speed asymmetric encryption with automated data exfiltration pipelines. Initial access is routinely obtained via compromised Remote Desktop Protocol (RDP) credentials, initial access broker (IAB) marketplaces, and spear-phishing campaigns delivering infostealer payloads. Organizations operating critical IT infrastructure are advised to enforce strict network segmentation, deploy hardware-backed multi-factor authentication across all external access points, and maintain immutable offline backups to mitigate operational disruption.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles