{"id":443,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2015<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Unknown (International)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Hacktivism, Anti-ISIS, Later Pro-Palestinian, Financial (Ransomware pivot)<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Counter-terrorism operations, website takedowns, data leaks, ransomware deployment (post-2022)<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Ghost Security Group, GhostSec Team<\/div>\n  <\/div>\n<\/div>\n<p>GhostSec (Ghost Security Group) was originally founded in 2015 as an anti-ISIS hacktivist collective operating under the broader Anonymous umbrella, dedicated to identifying and taking down online infrastructure used by the Islamic State for recruitment, propaganda, and operational coordination. The group gained international media attention and cautious acknowledgment from Western intelligence agencies for their counter-terrorism cyber operations, including reporting thousands of ISIS-affiliated social media accounts and websites to law enforcement.<\/p>\n<p>However, GhostSec's operational profile underwent a significant and controversial transformation from approximately 2022 onwards. The group pivoted toward pro-Palestinian hacktivism and began conducting more aggressive offensive operations, including attacks against Israeli and Western targets. Most significantly, GhostSec entered a partnership with the Stormous ransomware operation, deploying GhostLocker ransomware against corporate targets ,  a dramatic departure from their original counter-terrorism mandate that attracted considerable criticism from the cybersecurity community.<\/p>\n<p>GhostSec has claimed attacks against Israeli industrial control systems, critical infrastructure, and government databases, as well as Cuban government portals. Their ransomware operations have targeted organisations across multiple countries, with GhostLocker 2.0 representing a technically improved second-generation payload demonstrating continued malware development investment.<\/p>\n<p>The group's evolution from anti-terrorism vigilantes to ransomware operators exemplifies the fluid and often contradictory nature of hacktivist group identities and the challenge of maintaining ideological consistency as geopolitical contexts shift and financial incentives emerge within underground criminal ecosystems.<\/p>\n\n<p><strong>Tactical Telemetry and Extortion Framework:<\/strong> In confirmed intrusions, <strong>GhostSec<\/strong> employs double-extortion tactics, combining high-speed asymmetric encryption with automated data exfiltration pipelines. Initial access is routinely obtained via compromised Remote Desktop Protocol (RDP) credentials, initial access broker (IAB) marketplaces, and spear-phishing campaigns delivering infostealer payloads. Organizations operating critical IT infrastructure are advised to enforce strict network segmentation, deploy hardware-backed multi-factor authentication across all external access points, and maintain immutable offline backups to mitigate operational disruption.<\/p>","link":"https:\/\/cyberasia.io\/actor\/ghostsec\/","name":"GhostSec","slug":"ghostsec","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/443","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=443"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}