GhostLocker is a ransomware family released by the hacktivist group GhostSec in October 2023. It was developed as part of a ransomware-as-a-service operation intended to finance the group's hacktivist activities. GhostSec subsequently collaborated with the Stormous ransomware group to conduct double-extortion attacks against organizations across multiple countries and business sectors, combining ransomware deployment with data theft and threats of disclosure.
GhostSec and Stormous established a joint ransomware-as-a-service program called StmX|GhostLocker. In May 2024, GhostSec announced its departure from ransomware operations and a return to hacktivism, transferring GhostLocker operations to Stormous. GhostLocker illustrates the convergence of hacktivist activity and financially motivated extortion. It is distinct from the identically named security-research tool that abuses Windows AppLocker to disable endpoint detection and response components.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In October 2023, this self-described "vigilante" group released a novel type of ransomware, called GhostLocker, before conducting double extortion attacks across multiple countries and business sectors, in collaboration with Stormous.
In October 2023, this self-described "vigilante" group released a novel type of ransomware, called GhostLocker, before conducting double extortion attacks across multiple countries and business sectors, in collaboration with Stormous.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
GhostLocker is a tool designed to neutralize EDR solutions by leveraging Windows AppLocker to block EDR userland processes, effectively blinding the EDR's behavioral analysis and alerting capabilities while leaving kernel drivers operational.
Ransomware attributed to/used by GhostSec as part of extortion and disruptive operations.
Ransomware released by GhostSec in October 2023 and used in double-extortion operations conducted in collaboration with Stormous. The article describes attacks across multiple countries and sectors without naming specific industries.
GhostLocker is a ransomware-as-a-service platform developed by GhostSec, used to fund hacktivist activities, with strict rules against targeting healthcare and education.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.