ZeroFox Intelligence Flash Report - GhostSec Hacktivist Group Launches GhostLocker Ransom-as-a-Service
|by Alpha Team

ZeroFox Intelligence Flash Report - GhostSec Hacktivist Group Launches GhostLocker Ransom-as-a-Service
Product Serial: F-2023-11-14a
TLP:CLEAR
In this flash report, ZeroFox researchers delve into recent ransomware-as-a-service developments from the GhostSec hacktivist group, including how ransomware groups may leverage these developments and GhostSec's plans for selling access.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Hacktivist group GhostSec launched a new generation ransomware-as-a-service (RaaS) called GhostLocker, which it is auctioning through November 18, 2023, or until 20 copies are sold. After that, access to the ransomware will be invite-only.
- GhostLocker ransomware offers alleged military-grade encryption, undetectability, negotiation services, and low fees to affiliates, setting it apart from other similar RaaS offerings.
- Stormous ransomware group has announced it will be incorporating GhostLocker ransomware into its operations.
Tags: tlp:clear, DDW Ransomware, threat actor