Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
1 malware family

GhostSec

Also known asGhostSec

GhostSec is a hacktivist collective, described in the content as Anonymous-affiliated and, in some reporting, Iran-affiliated. It has targeted Islamic extremist content online, Israeli organizations, industrial control and water-related systems, satellite/GNSS infrastructure, and social media accounts. Known aliases in the provided content include only GhostSec; related groups mentioned include CtrlSec, which was founded by GhostSec-linked operator “Mikro” and shared personnel and resources. The content states GhostSec’s self-declared mission was to target Islamic extremist content on websites, blogs, videos, and social media accounts using both “official channels” and “digital weapons.” It reportedly conducted DDoS attacks against ISIS-linked websites and claimed to have disrupted or taken down more than 130 such sites. Mikro is identified as GhostSec’s “operations officer,” and GhostSec and CtrlSec are described as originating from Anonymous. In later reporting, GhostSec is associated with disruptive and opportunistic hacktivist activity tied to the Israel-Hamas and Israel-Iran conflicts. The group is cited as targeting Unitronics PLCs and Aegis devices used to control water pumps, and as compromising Israeli water, industrial control, and satellite systems. One report says GhostSec claimed on October 13, 2023 to have hacked multiple Unitronics devices and 27 Aegis devices. Other content states GhostSec targeted PLCs linked to Israeli media and water systems, and claimed access to water/ICS and satellite systems during 2025 conflict-related operations. GhostSec also targeted satellite-related infrastructure. In 2023 it reportedly attacked numerous GNSS receivers in countries including Russia and Israel, and in some cases claimed to have wiped data from compromised receivers. Additional reporting in the content describes GhostSec as part of hacktivist activity involving DDoS, web defacement, and claimed intrusions into VSAT terminals and satellite operators. The content also links GhostSec to ransomware operations. It references GhostLocker ransomware and GhostStealer, and describes GhostSec as collecting local and system information, encrypting victim data for impact, inhibiting recovery, and using bootkit elements, obfuscation, process injection, masquerading, and timestamp modification for defense evasion. In May 2024, GhostSec reportedly announced it was ending its ransomware operations and returning to hacktivism, with GhostLocker RaaS operations to be handed off to Stormous. Across the provided sources, GhostSec is characterized as a hacktivist actor whose observed tactics include DDoS, web defacement, claimed intrusions into ICS/OT and satellite systems, data wiping claims, ransomware-based encryption for impact, system and local information collection, recovery inhibition, bootkit use, obfuscation, process injection, masquerading, and timestamp modification.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇷🇺 Russia
  • 🇮🇱 Israel
MITRE ATT&CK

Tradecraft

8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

7 of 15 tactics14 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1590×3
Gather Victim Network Information
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1583.005
Botnet
T1584
Compromise Infrastructure
T1584.005
Botnet
TA0001
Initial Access
1 technique
T1190×3
Exploit Public-Facing Application
TA0003
Persistence
1 technique
T1037
Boot or Logon Initialization Scripts
T1037.005
Startup Items
TA0004
Privilege Escalation
1 technique
T1037
Boot or Logon Initialization Scripts
T1037.005
Startup Items
TA0005
Stealth
1 technique
T1070
Indicator Removal
T1070.006
Timestomp
TA0040
Impact
2 techniques
T1485
Data Destruction
T1498×3
Network Denial of Service
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping8

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

GhostSec | Mallory