Home/Threat Actor/GhostSec
Threat Actor

GhostSec

ghostsec · anonymous_offshoot_multi_ideology_drift · active since 2015-01

GhostSec (canonical naming, also Ghost Security + GhostSecMafia + GSM) is a hacktivist collective that emerged 2015 as an Anonymous offshoot for anti-ISIS counterterrorism operations (#OpISIS + #OpParis), and has undergone significant ideological + operational drift across multiple phases 2015-2026 including anti-ISIS origin (2015- 2020), multi-regime hacktivism (#OpLebanon + #OpNigeria + #OpMyanmar + #OpEcuador + #OpColombia 2015-2020), pro-Ukraine #OpRussia (early 2022), pivot to anti-Israel + pro-Palestinian + pro- Iranian-Hijab-protests with ICS/SCADA targeting capability (June-September 2022), financial pivot via GhostLocker RaaS + Stormous partnership + Five Families collective founding (2022-May 2024), May 2024 announced retirement-from-cybercrime back-to- hacktivism, and 2025-2026 anti-Zionist + anti-US + anti-Trump + Iranian-narrative-alignment + LockNet platform development.

non-state decentralized hacktivist collective attribution via Rapid7 canonical June 2025 longstanding analysis + SOCRadar Dark Web Profile + Cyberint July 2023 Raising the Bar + OTORIO David Krivobokov Industrial Cyber October 2022 Iranian Hijab protests support + MEMRI September 2022 + Outpost24 November 2025 + Daily Security Review September 2025 + SecurityAffairs March 2024 + Cisco Talos + Security Scientist April 2026 industry coverage with important honest characterization that GhostSec is NOT linked to legitimate "Ghost Security Group" counterterrorism organization per SecurityAffairs; standalone cluster paralleling predatory_sparrow + cyber_partisans + it_army_ukraine in v0.1.157 2020-2025 hacktivist collectives in geopolitical conflict zones cell.

operational target profile multi-phase evolution from 2015-2018 ISIS websites + social media accounts + multi-regime defacements + DDoS, to 2022+ Israeli organizations + Israeli ICS targeting (55 Berghof PLCs + water systems with pH/chlorine manipulation demonstration) + Indonesian National Railway Operator + Canadian Energy Supplier + 15+ country ransomware victims via STMX_GhostLocker, to 2025- 2026 Israeli emergency alert + radio broadcasting + government + media.

operational attack architecture: (1) cluster-defining Anonymous offshoot 2015 anti-ISIS origin with #OpISIS + #OpParis defacement + DDoS campaigns.

(2) cluster-defining ICS/SCADA hacking capability with September 4, 2022 55 Berghof PLC devices Israel breach with water system pH + chlorine level control demonstration + Moxa E2214 controller + Metasploit framework SCADA modules per OTORIO + Industrial Cyber + Cyberint analysis ("This demonstrates again the ease and potential impact of attacks on ICS systems that have insufficient security controls in place")

(3) cluster- defining GhostLocker RaaS Python initial variant + GhostLocker 2.0 Golang variant November 2023 + GhostLocker V3 planned next-generation ransomware financial pivot per Rapid7 + SecurityAffairs + Daily Security Review.

(4) cluster-defining Five Families collective founding signature with ThreatSec + Stormous + Blackforums + SiegedSec (until late 2023 removal) per SecurityAffairs + Daily Security Review establishing hacktivist- cybercrime alliance ecosystem.

(5) cluster- defining STMX_GhostLocker joint operation with Stormous with 15+ country ransomware victims including China + India + Brazil + Russia + Israel + Colombia + Iran + South Africa + Nigeria + Pakistan + Iraq + UAE + Lebanon + France + Sudan + Myanmar + Nicaragua + Philippines + Canada per Daily Security Review demonstrating global operational scale.

(6) cluster-defining unusual May 15, 2024 announced retirement-from-cybercrime back-to-hacktivism ("GhostSec announced its retirement from cybercriminal activities and its return to hacktivism. The group stated that it reached this decision after having obtained enough funding to support its hacktivist operations. GhostSec further mentioned that Stormous would remain in charge of the management and operation of GhostLocker") signature tradecraft; (7) signature 2025-2026 Iranian-narrative- alignment evolution + LockNet ransomware platform development per Outpost24 November 2025 with DDoS on Israeli emergency alert + radio broadcasting + data leaks + defacements + psychological operations via Telegram.

(8) signature January 2023 Belarusian Remote Terminal Unit (RTU) ransomware + Indonesian National Railway Operator (early 2024 GhostPresser tools) + Canadian Energy Supplier ICS-targeted operations; (9) signature subscription-based premium channel funding + affiliate commissions + ransomware income layered monetization model per Outpost24.

(10) signature GhostPresser + GhostSec Deep Scan proprietary website-attack + scanning toolsets; cluster fills the 2015-onward-Anonymous-offshoot- multi-ideology-hacktivism + anti-ISIS-origin + 2022-Israeli-ICS-Berghof-PLC-targeting + GhostLocker-Stormous-RaaS-financial-pivot + Five- Families-collective + May-2024-retirement-from- cybercrime + 2025-2026-Iranian-narrative-alignment position in 2020-2025 hacktivist collectives in geopolitical conflict zones cell.

canonical illustration of decade-long-lifecycle multi- ideology hacktivist collective + hacktivism-to- cybercrime convergence trajectory + ICS/SCADA hacking capability + Five Families collective + GhostLocker RaaS + Stormous partnership + announced-retirement-from-cybercrime tradecraft + 2025-2026 Iranian-narrative-alignment evolution cited in essentially all subsequent hacktivism- cybercrime-convergence industry analyses through 2015-2026 period.

anonymous_offshoot_multi_ideology_drift confidence: high 24 aliases
Sigma rules200 YARA rules2 Live IOCs0 CVEs exploited0

Profile

GhostSec (canonical naming, also Ghost Security + GhostSecMafia + GSM) is a hacktivist collective that emerged 2015 as an Anonymous offshoot for anti-ISIS counterterrorism operations (#OpISIS + #OpParis), and has undergone significant ideological + operational drift across multiple phases 2015-2026. Non-state decentralized hacktivist collective attribution, Anonymous offshoot origins 2015 + Eastern European/Moscow-hosted-server-suggesting infrastructure ties per Daily Security Review + multi-ideological-evolution trajectory making single-state attribution inapplicable. Important honest characterization: NOT linked to legitimate "Ghost Security Group" counterterrorism organization per SecurityAffairs. Standalone cluster paralleling predatory_sparrow + cyber_partisans + it_army_ukraine in v0.1.157 2020-2025 hacktivist collectives in geopolitical conflict zones cell.

Operational mission evolution phases
  • 2015-2020: anti-ISIS counterterrorism + multi-regime hacktivism.
  • 2020-2022: anti-Russia pro-Ukraine (#OpRussia)
  • June-September 2022: pivot to anti-Israel + pro-Palestinian + pro-Iranian-Hijab-protests with ICS-targeting (55 Berghof PLCs + water systems)
  • 2022-May 2024: GhostLocker RaaS + Stormous partnership + Five Families collective financial pivot.
  • May 2024-present: announced retirement from cybercrime + 2025-2026 anti-Zionist + anti-US + anti-Trump + Iranian-narrative alignment + LockNet platform development Operational attack architecture: (1) Anonymous offshoot 2015 anti-ISIS origin (cluster-defining): #OpISIS + #OpParis defacement + DDoS campaigns (2) ICS/SCADA targeting capability (cluster- defining): 55 Berghof PLCs Israel September 2022 + water system pH/chlorine control + Moxa E2214 + Metasploit SCADA modules (3) GhostLocker RaaS Python + Golang + V3 planned (cluster-defining): cluster-defining ransomware financial pivot (4) Five Families collective founding signature (cluster-defining): with ThreatSec + Stormous + Blackforums + SiegedSec (until late 2023) (5) STMX_GhostLocker joint operation with Stormous (cluster-defining): 15+ country ransomware victims including China + India + Brazil + Russia + Israel + Colombia + Iran + Lebanon + France + Sudan + Myanmar + Nicaragua + Philippines + Canada per Daily Security Review (6) May 15 2024 announced retirement-from- cybercrime (cluster-defining): unusual tradecraft announcement returning to hacktivism after cybercrime funding accumulation (7) 2025-2026 Iranian-narrative-alignment signature evolution + LockNet platform (8) Subscription-based premium channel funding model + affiliate commissions + ransomware income (signature): layered monetization The cluster fills the 2015-onward-Anonymous- offshoot-multi-ideology-hacktivism + anti-ISIS- origin + 2022-Israeli-ICS-Berghof-PLC-targeting + GhostLocker-Stormous-RaaS-financial-pivot + Five- Families-collective + May-2024-retirement-from- cybercrime + 2025-2026-Iranian-narrative-alignment position in 2020-2025 hacktivist collectives in geopolitical conflict zones cell.

Aliases

24
ghostsecghost_secghost secghost-secghost_securityghost securityghostsecmafiaghost security mafiagsmghostlocker_raasghostlocker raasstmx_ghostlockerstmx ghostlockerstmx_ghostsecghostsec anonymous offshoot 2015 emergenceghostsec opisis opparis anti-isis 2015 first operationsghostsec berghof plc israeli water system september 2022ghostsec metasploit scada moxa e2214 iranian hijab protests supportghostsec stormous five families collectiveghostsec stormous threatsec blackforums siegedsecghostsec ghostlocker python golang ransomwareghostsec may 2024 retirement from cybercrime back to hacktivismghostsec locknet ransomware platform 2025ghostsec lockbit black ransomware 2024 anti-israel ics

Notable Campaigns

13
2025-2026GhostSec 2025-2026 Anti-Zionist + Anti-US + Anti-Trump + Iranian Narrative Alignment + LockNet Platform
2024GhostSec May 15, 2024 Retirement-from-Cybercrime + Back-to-Hacktivism Announcement
2023-2024GhostSec Five Families Collective Membership Signature
2023-2024GhostSec 15+ Country Ransomware Attacks via STMX_GhostLocker
2023GhostSec January 2023 Belarusian Remote Terminal Unit (RTU) Ransomware
2022-2024GhostSec 2022-2024 Financial Pivot, GhostLocker RaaS + Stormous Partnership
2022GhostSec October 2022 Iranian Hijab Protests Support, ICS Support Pivot
2022GhostSec September 4 2022 55 Berghof PLC Devices Israel ICS Breach Signature
2022GhostSec June 2022 Anti-Israel Pivot Signature
2022GhostSec #OpRussia Pro-Ukraine Pivot (2022 initial)
2015-2026Continued Industry Reference Status (2015-2026)
2015-2020GhostSec 2015-2020 Multi-Regime Hacktivism Campaigns
2015GhostSec Origin, 2015 Anonymous Offshoot anti-ISIS #OpISIS + #OpParis

Attribution & Reporting

Attributed by
Rapid7 (canonical June 2025 Exploring Convergence from Hacktivism to Cybercrime longstanding tracking)Cisco Talos (canonical 2023-2024 GhostSec + Stormous activities observation)SecurityAffairs (canonical March 2024 GhostSec + Stourmous ransomware coverage)SOCRadar (canonical Dark Web Profile GhostSec multi-year analysis)Cyberint (canonical July 2023 GhostSec Raising the Bar 2022 Israeli campaign analysis)OTORIO + David Krivobokov (canonical October 2022 Iranian Hijab protests support + Berghof PLC ICS hacking analysis)Industrial Cyber (canonical OTORIO Iranian Hijab protests support coverage)MEMRI (canonical September 2022 Pro-Palestinian Hacktivist Group Targets Israeli Companies)Outpost24 (canonical November 2025 hacktivist cyber operations Iran-Israel + GhostSec 2025-2026 profile)Daily Security Review (canonical September 2025 GhostSec From Hacktivist to Ransomware Warlord + June 2025 RaaS Powerhouse profiles)Security Scientist (canonical April 2026 12 Questions and Answers About GhostSec)
Key reporting
reportRapid7: Exploring the Convergence from Hacktivism to Cybercrime (June 2025), canonical longstanding analysis
reportSOCRadar: Dark Web Profile, GhostSec (March 2024)
reportCyberint: GhostSec Raising the Bar (July 2023), canonical 2022 Israeli campaign
reportOTORIO + David Krivobokov: canonical October 2022 GhostSec Iranian Hijab protests ICS support
reportIndustrial Cyber: OTORIO reveals GhostSec hacktivist group now targets Iranian ICS
reportMEMRI: Pro-Palestinian Hacktivist Group Targets Israeli Companies In Cyber Attack (September 2022)
reportOutpost24: How hacktivist cyber operations surged amid Israeli-Iranian conflict (November 2025)
reportDaily Security Review: GhostSec, From Hacktivist to Ransomware Warlord (September 2025) + From Hacktivist Roots to RaaS Powerhouse (June 2025)
reportSecurityAffairs: Watch out, GhostSec and Stourmous groups jointly conducting ransomware attacks (March 2024)
reportCisco Talos: canonical 2023-2024 GhostSec + Stormous activities observation
reportSecurity Scientist: 12 Questions and Answers About GhostSec (April 2026)

Operational

State sponsor

Non-state decentralized hacktivist collective with decentralized operations + Anonymous offshoot origins 2015. Per Daily Security Review threat actor profile: "Decentralized operations; associated activity and C2 infrastructure (e.g., Moscow-hosted servers) suggest Eastern European ties, but with hacktivist roots in Middle East influence." Multi-ideological-evolution trajectory makes single-state attribution inapplicable; cluster operates primarily as ideological / financial hybrid actor. Important honest characterization: NOT linked to legitimate "Ghost Security Group" counterterrorism organization per SecurityAffairs ("The group is not linked to the hacktivist group Ghost Security Group, which primarily focuses on counterterrorism efforts and targets pro-ISIS websites"). Attribution chain: (1) Rapid7 canonical longstanding tracking + multi-phase analysis: per Rapid7 June 2025 Exploring Convergence from Hacktivism to Cybercrime: "The GhostSec hacktivist group (AKA Ghost Security, GhostSecMafia, and GSM) has been active since at least 2015. The Anonymous-affiliated group gained prominence with the #OpIsis and #OpParis campaigns, in which various hacktivist groups took down thousands of ISIS websites and social media accounts using defacement and DDoS attacks. Since then, GhostSec has participated in campaigns, such as #OpLebanon, #OpNigeria, #OpMyanmar, #OpEcuador, and #OpColombia. The group has also continuously launched cyberattacks on Israel in response to alleged war crimes, primarily defacing their websites to spread 'Free Palestine' messages." (2) Cyberint canonical 2022 Israeli-targeting campaign analysis: per Cyberint: "In June 2022, Cyberint observed a new hacktivist campaign targeting multiple Israeli organizations and enterprises coordinated via different social media platforms... GhostSec was first identified in 2015 and was initially founded to attack ISIS in the cyber realm as part of the fight against Islamic extremism. In past years, the group participated in several campaigns against several counties including Nigeria, Colombia, Lebanon and South Africa. From the start of the Russian- Ukrainian war, the group sided with Ukraine and published mainly Russian-related leaks, DDOS, and content under the campaign #OpRussia." (3) OTORIO canonical Iranian Hijab protests support tracking October 2022: per Industrial Cyber + OTORIO David Krivobokov: "The GhostSec hacktivist group has continued to demonstrate its ICS (industrial control system) hacking skills and has now turned its support to the recent waves of Hijab protests in Iran... successfully breached 55 Berghof PLC devices in Israel... taking control of a water system's pH and chlorine levels." (4) Cisco Talos + SecurityAffairs canonical GhostSec + Stormous joint ransomware operation March 2024: per SecurityAffairs: "Researchers warn that the cybercrime groups GhostSec and Stormous have joined forces in a new ransomware campaign... The GhostSec hacking activity surged in the past year and the cybercrime gang was spotted using a new GhostLocker 2.0 ransomware, a Golang variant of the GhostLocker ransomware... The two groups launched a new ransomware-as-a- service (RaaS) operation, called STMX_GhostLocker. GhostSec is a member of a modern-day Five Families group, which includes ThreatSec, Stormous, Blackforums, and SiegedSec." (5) SOCRadar canonical 2024 Dark Web Profile: per SOCRadar Dark Web Profile: "GhostSec has been collaborating with Stormous since at least the latter half of 2023. Cisco Talos also stated that they observed these activities over the year. However, according to our research, the traces of this kind of collaboration even extend to 2022." (6) GhostSec May 2024 retirement announcement + Stormous takeover: per Rapid7: "On May 15, 2024, GhostSec announced its retirement from cybercriminal activities and its return to hacktivism. The group stated that it reached this decision after having obtained enough funding to support its hacktivist operations. GhostSec further mentioned that Stormous would remain in charge of the management and operation of GhostLocker." (7) Outpost24 canonical 2025 Iranian-narrative- alignment analysis: per Outpost24 November 2025: "Focus: Anti-Zionist, anti-US, anti-Trump hacktivism.

increasingly aligned with Iranian geopolitical narratives. Activities: DDoS attacks on Israeli emergency alert and radio broadcasting infrastructure.

data leaks from government and media entities.

defacements of commercial websites; public psychological operations via Telegram; announced development of the 'LockNet' ransomware platform. Alliances: SiegedSec (longstanding partner), Stormous (joint ransomware), Five Families (until 2024). Possible relation with Arabian Ghosts.

public rivalry with Dark Storm Team.

" Operational mission objective evolution
  • 2015-2020: anti-ISIS counterterrorism + anti-multi-regime symbolic operations.
  • 2020-2022: anti-Russia pro-Ukraine support (#OpRussia post-invasion)
  • June-September 2022: pivot to anti-Israel + pro-Palestinian + pro-Iranian-Hijab-protests + ICS-targeting operations.
  • 2022-May 2024: financial pivot via GhostLocker RaaS + Stormous partnership + Five Families collective.
  • May 2024-present: return to hacktivism with funding from cybercrime period + 2025-2026 anti-Zionist + anti-US + anti-Trump + Iranian- narrative alignment Operational target profile evolution:.
  • 2015-2020: ISIS websites + social media accounts + multi-regime defacements.
  • 2022+: Israeli organizations + Israeli ICS (Berghof PLCs water systems + 55+ Israeli organizations) + Indonesian National Railway Operator + Canadian Energy Supplier + multi- country victims in 15+ countries (China + India + Brazil + Russia + Israel + Colombia + Iran + South Africa + Nigeria + Pakistan + Iraq + UAE + Lebanon + France + Sudan + Myanmar + Nicaragua + Philippines + Canada per Daily Security Review)
  • 2025-2026: Israeli emergency alert + radio broadcasting + government + media The cluster fills the 2015-onward-Anonymous- offshoot-multi-ideology-hacktivism + anti-ISIS- origin + 2022-Israeli-ICS-Berghof-PLC-targeting + GhostLocker-Stormous-RaaS-financial-pivot + Five- Families-collective + May-2024-retirement-from- cybercrime + 2025-2026-Iranian-narrative-alignment position in 2020-2025 hacktivist collectives in geopolitical conflict zones cell.
Motivations
anonymous_offshoot_2015_anti_isis_counterterrorism_origin, multi_regime_hacktivism_2015_2020_evolution, anti_israel_pro_palestinian_pro_iranian_hijab_protests_2022_pivot, financial_motivated_ghostlocker_raas_stormous_partnership_2022_2024, hacktivism_return_may_2024_iranian_narrative_alignment_2025_2026, ics_scada_targeting_capability_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)53/60 · 88%
Analytics (MITRE CAR)29/60 · 48%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)18/60 · 30%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MAY 2024 RETIREMENT-FROM-CYBERCRIME BACK-TO-HACKTIVISM ANNOUNCEMENT SIGNATUREMETASPLOIT FRAMEWORK SCADA MODULES BERGHOF PLC EXPLOITATIONMOXA E2214 CONTROLLER ADMIN WEB PORTAL EXPLOITATIONSIEGEDSEC REMOVED LATE 2023 LONGSTANDING-PARTNER-OTHERWISESTMX GHOSTLOCKER JOINT RAASSTORMOUS PARTNERSHIP 2022-PRESENTSUBSCRIPTION-BASED PREMIUM CHANNEL FUNDING MODEL
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin