ZeroFox Intelligence Flash Report - GhostSec Announces Return to Hacktivism
|by Alpha Team

ZeroFox Intelligence Flash Report - GhostSec Announces Return to Hacktivism
Product Serial: F-2024-05-22a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on a recent statement from the threat collective GhostSec, announcing their plans to abandon financially-motivated activity and return to hacktivism.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On May 15, 2024, the threat group “GhostSec” announced on its official Telegram channel its intention to abandon financially motivated cybercrime and resume hacktivism activities.
- GhostSec is a member of the Five Families, a collective of hacking groups that has conducted financially, ideologically, and politically-motivated attacks against industries across the globe.
- GhostSec's renewed focus on hacktivism is very likely enabled by its financial success in leveraging GhostLocker ransomware-as-a-service (RaaS) in ransomware and digital extortion (R&DE) activity. In the short to medium term, GhostSec is likely to attempt disruptive and undermining attacks against the Israeli government, as well as other state institutions that are politically and ideologically misaligned with the group.
Tags: tlp:clear, threat actor, DDW Ransomware