GhostSec
GhostSec (canonical naming, also Ghost Security + GhostSecMafia + GSM) is a hacktivist collective that emerged 2015 as an Anonymous offshoot for anti-ISIS counterterrorism operations (#OpISIS + #OpParis), and has undergone significant ideological + operational drift across multiple phases 2015-2026 including anti-ISIS origin (2015- 2020), multi-regime hacktivism (#OpLebanon + #OpNigeria + #OpMyanmar + #OpEcuador + #OpColombia 2015-2020), pro-Ukraine #OpRussia (early 2022), pivot to anti-Israel + pro-Palestinian + pro- Iranian-Hijab-protests with ICS/SCADA targeting capability (June-September 2022), financial pivot via GhostLocker RaaS + Stormous partnership + Five Families collective founding (2022-May 2024), May 2024 announced retirement-from-cybercrime back-to- hacktivism, and 2025-2026 anti-Zionist + anti-US + anti-Trump + Iranian-narrative-alignment + LockNet platform development.
non-state decentralized hacktivist collective attribution via Rapid7 canonical June 2025 longstanding analysis + SOCRadar Dark Web Profile + Cyberint July 2023 Raising the Bar + OTORIO David Krivobokov Industrial Cyber October 2022 Iranian Hijab protests support + MEMRI September 2022 + Outpost24 November 2025 + Daily Security Review September 2025 + SecurityAffairs March 2024 + Cisco Talos + Security Scientist April 2026 industry coverage with important honest characterization that GhostSec is NOT linked to legitimate "Ghost Security Group" counterterrorism organization per SecurityAffairs; standalone cluster paralleling predatory_sparrow + cyber_partisans + it_army_ukraine in v0.1.157 2020-2025 hacktivist collectives in geopolitical conflict zones cell.
operational target profile multi-phase evolution from 2015-2018 ISIS websites + social media accounts + multi-regime defacements + DDoS, to 2022+ Israeli organizations + Israeli ICS targeting (55 Berghof PLCs + water systems with pH/chlorine manipulation demonstration) + Indonesian National Railway Operator + Canadian Energy Supplier + 15+ country ransomware victims via STMX_GhostLocker, to 2025- 2026 Israeli emergency alert + radio broadcasting + government + media.
operational attack architecture: (1) cluster-defining Anonymous offshoot 2015 anti-ISIS origin with #OpISIS + #OpParis defacement + DDoS campaigns.
(2) cluster-defining ICS/SCADA hacking capability with September 4, 2022 55 Berghof PLC devices Israel breach with water system pH + chlorine level control demonstration + Moxa E2214 controller + Metasploit framework SCADA modules per OTORIO + Industrial Cyber + Cyberint analysis ("This demonstrates again the ease and potential impact of attacks on ICS systems that have insufficient security controls in place")
(3) cluster- defining GhostLocker RaaS Python initial variant + GhostLocker 2.0 Golang variant November 2023 + GhostLocker V3 planned next-generation ransomware financial pivot per Rapid7 + SecurityAffairs + Daily Security Review.
(4) cluster-defining Five Families collective founding signature with ThreatSec + Stormous + Blackforums + SiegedSec (until late 2023 removal) per SecurityAffairs + Daily Security Review establishing hacktivist- cybercrime alliance ecosystem.
(5) cluster- defining STMX_GhostLocker joint operation with Stormous with 15+ country ransomware victims including China + India + Brazil + Russia + Israel + Colombia + Iran + South Africa + Nigeria + Pakistan + Iraq + UAE + Lebanon + France + Sudan + Myanmar + Nicaragua + Philippines + Canada per Daily Security Review demonstrating global operational scale.
(6) cluster-defining unusual May 15, 2024 announced retirement-from-cybercrime back-to-hacktivism ("GhostSec announced its retirement from cybercriminal activities and its return to hacktivism. The group stated that it reached this decision after having obtained enough funding to support its hacktivist operations. GhostSec further mentioned that Stormous would remain in charge of the management and operation of GhostLocker") signature tradecraft; (7) signature 2025-2026 Iranian-narrative- alignment evolution + LockNet ransomware platform development per Outpost24 November 2025 with DDoS on Israeli emergency alert + radio broadcasting + data leaks + defacements + psychological operations via Telegram.
(8) signature January 2023 Belarusian Remote Terminal Unit (RTU) ransomware + Indonesian National Railway Operator (early 2024 GhostPresser tools) + Canadian Energy Supplier ICS-targeted operations; (9) signature subscription-based premium channel funding + affiliate commissions + ransomware income layered monetization model per Outpost24.
(10) signature GhostPresser + GhostSec Deep Scan proprietary website-attack + scanning toolsets; cluster fills the 2015-onward-Anonymous-offshoot- multi-ideology-hacktivism + anti-ISIS-origin + 2022-Israeli-ICS-Berghof-PLC-targeting + GhostLocker-Stormous-RaaS-financial-pivot + Five- Families-collective + May-2024-retirement-from- cybercrime + 2025-2026-Iranian-narrative-alignment position in 2020-2025 hacktivist collectives in geopolitical conflict zones cell.
canonical illustration of decade-long-lifecycle multi- ideology hacktivist collective + hacktivism-to- cybercrime convergence trajectory + ICS/SCADA hacking capability + Five Families collective + GhostLocker RaaS + Stormous partnership + announced-retirement-from-cybercrime tradecraft + 2025-2026 Iranian-narrative-alignment evolution cited in essentially all subsequent hacktivism- cybercrime-convergence industry analyses through 2015-2026 period.