GhostSec is a hacktivist collective that emerged from the Anonymous ecosystem and became known for operations framed around anti-ISIS activity before later expanding into disruptive campaigns tied to Middle East geopolitical conflicts, especially against Israeli targets. The group has also operated alongside or through closely related branding such as CtrlSec, and reporting has linked personnel overlap between those efforts. GhostSec has publicly positioned itself as targeting extremist online content, while later activity shows a broader pattern of politically motivated cyber operations against government, media, satellite, industrial, and water-related systems. GhostSec has been associated with distributed denial-of-service attacks, website disruption, social-media takedown efforts, claimed intrusions, destructive or disruptive actions against operational technology, and a period of ransomware activity under the GhostLocker name. Reported targeting has included GNSS receivers, satellite-related systems, Unitronics PLCs, Aegis water-control devices, and other OT-adjacent infrastructure. In 2023 and 2025, GhostSec was repeatedly cited among pro-Palestinian or anti-Israeli hacktivist actors claiming compromises of Israeli water, industrial control, and satellite systems. The group has also been linked to attacks or claimed attacks affecting receivers in Russia and Israel, and to an attempted filesystem-encryption incident involving a Belarusian industrial router or RTU platform. Operationally, GhostSec has been described as using disruptive and impact-oriented techniques including data wiping claims, encryption for impact, inhibition of recovery, obfuscation, masquerading, timestamp modification, process injection, and bootkit-related elements. Other reporting attributes to GhostSec collection of local and system information and financially motivated ransomware behavior during its GhostLocker phase. In May 2024, GhostSec reportedly announced the end of its ransomware operations and a return to hacktivism, with GhostLocker operations handed off to Stormous. GhostSec is best characterized as a politically motivated hacktivist actor with a demonstrated history of disruptive operations and opportunistic targeting of exposed internet-facing systems, including OT and satellite-adjacent assets. Although some reporting has described the group as Iran-affiliated, the available facts here support treating GhostSec primarily as a hacktivist collective rather than confidently attributing it to direct state control.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist operations targeting Israeli satellite operators/VSAT terminals with disruption and credential theft claims during regional conflict dynamics.
GhostSec is an Iran-affiliated group targeting programmable logic controllers (PLCs) in Israeli media and water systems, as part of coordinated campaigns against critical infrastructure.
Highly organized hacktivist/cybercrime-adjacent actor conducting DDoS, ICS/OT targeting and sabotage, data theft/extortion, doxxing, and ransomware activity; claims compromises of Modbus/PLC and VSAT environments.
GhostSec is a hacktivist group participating in cyber operations against Israel, employing tactics such as DDoS and data leaks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.