GhostSec, also known as Ghost Security and Ghost Security Group, is a hacktivist collective widely associated with Anonymous and best known for counterterrorism operations targeting the Islamic State’s online ecosystem. The group emerged as an anti-ISIS actor within the broader #OpISIS movement and was described as comprising current and former Anonymous participants, while later attempting to professionalize its image and distinguish itself from the broader Anonymous brand. GhostSec focused primarily on disrupting extremist propaganda, recruitment, communications, and support infrastructure online. Reported activity included identifying and mass-reporting social media accounts, notifying service providers about extremist content, pursuing website takedowns, and conducting disruptive operations against online assets associated with ISIS. The group was also reported to have used DDoS attacks, SQL injection, and infiltration of jihadi forums as part of its operations. In addition to disruption, GhostSec engaged in intelligence collection and vetting, including review of suspected extremist infrastructure by multiple members and use of Arabic-language expertise to reduce false positives. The group has been linked to volunteer-driven workflows in which large numbers of supporters submitted leads on suspected extremist sites and accounts for validation and action. GhostSec representatives stated that they prioritized targets tied to recruitment and communications and that a substantial portion of hosting providers would remove content when notified. Reporting has also associated GhostSec with collection of open-source and forum-derived intelligence that was shared onward to external intermediaries and, in some cases, law-enforcement or intelligence channels for counterterrorism purposes. GhostSec is best characterized as a politically motivated hacktivist and counter-extremist actor rather than a state-sponsored threat group. Available information does not support classifying it as a nation-state actor. Mentioned aliases include Ghost Security and Ghost Security Group, with GhostSec being the most commonly used name in security discourse. GhostSec was also cited as part of a 2023 alliance alongside SiegedSec, BlackForums, ThreatSec, and Stormous Ransomware, though the durability and operational significance of that alignment are not well established from high-confidence public reporting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Member of the 'Five Families' alliance with SiegedSec and other groups, which collectively claimed multiple breaches before becoming inactive.
Anti-Islamic State hacktivist group conducting website takedowns, DDoS and SQL injection attacks, deep-web monitoring, forum infiltration, and intelligence sharing with U.S. authorities.
Anti-Islamic State hacktivist group conducting website takedowns, DDoS and SQL injection attacks, deep-web monitoring, forum infiltration, and intelligence gathering on suspected Islamic State infrastructure and supporters.
Groups Ghost Security
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.