◇ SIGN IN
← all actors
ransomware

GhostSec / GhostLocker

activemedium confidence
Ransomware
GhostSecGhostLockerGhostLocker 2.0Ghost Security
Attribution
hacktivist (evolved to RaaS; joint operations with Stormous)
Origin
Unknown
First seen
2023
Last active
2025
Motivation
Hacktivism / ransomware
Confidence
medium
MENA targeting
Lebanon, Israel, Egypt, Qatar, Turkey, Morocco
Sectors
Telecom, oil & gas, infrastructure, healthcare, government/defense

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Lebanon, Israel, Egypt (Telecom, oil & gas, infrastructure sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

GhostSec is a hacktivist collective that developed the GhostLocker ransomware and ran joint RaaS operations with Stormous before publicly announcing a return to hacktivism in May 2024, handing GhostLocker's continuation to Stormous while continuing ideologically driven attacks.

History

GhostSec began as a hacktivist collective and, in October 2023, launched GhostLocker, a ransomware-as-a-service offering. It later fielded GhostLocker 2.0, a Golang rewrite, and conducted joint ransomware operations with Stormous, both part of the self-styled 'Five Families' cybercrime alliance (alongside ThreatSec, Blackforums and SiegedSec). Cisco Talos and others documented the group's expanding arsenal and cross-group tooling during this period.

On 15 May 2024, GhostSec announced it was stepping back from cybercrime and returning to hacktivism, stating it had secured sufficient funding, and said Stormous would take over management of GhostLocker, including transfer of existing clients and sharing of the GhostLocker V3 source code. As of 2025 the Stormous RaaS program continued as an apparent continuation of GhostLocker, while GhostSec resumed ideologically motivated operations.

GhostSec's hacktivist targeting has repeatedly focused on Israel and regional interests, with website defacements carrying pro-Palestinian messaging, and claimed activity across MENA including Lebanon, Israel, Egypt, Qatar, Turkey and Morocco. These claims are largely self-reported via Telegram and leak channels and should be treated as unverified unless confirmed by a reputable source.

Notable campaigns

2023
GhostLocker RaaS launch
Introduced GhostLocker ransomware-as-a-service in October 2023.
2024
Joint GhostSec/Stormous operations
Ran joint ransomware campaigns with Stormous documented by Cisco Talos.
2024
Return-to-hacktivism handover
Announced May 2024 exit from cybercrime, handing GhostLocker to Stormous while resuming hacktivism.