GD LockerSec is a purported ransomware-related brand that has been identified primarily in the context of scam or impersonation activity rather than as a well-validated, independent ransomware operation. It has been mentioned among ransomware impersonators and in claimed associations with other criminal brands such as Bjorka and Babuk 2.0, but available high-confidence reporting does not substantiate GD LockerSec as a mature, distinct threat actor with a clearly documented intrusion set, victimology, tooling lineage, or operational history. The limited reporting available suggests GD LockerSec may have been presented as a possible affiliate in broader ransomware or extortion ecosystems. However, corroborated details about its command structure, malware development, targeting patterns, geographic origin, or confirmed campaigns remain insufficient. In the absence of stronger validation, GD LockerSec is best characterized as an ambiguously attributed ransomware-associated name that may overlap with deception, branding abuse, or low-confidence affiliate claims rather than a firmly established actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Likely impersonator or scam-oriented ransomware brand participating in recycled-data and reputational-arbitrage activity.
Named as a possible Babuk2 affiliate based on leak-site collaboration indicators; no further details provided.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.