Team GhostShell is a hacktivist threat actor known for large-scale data breaches and public leaks, particularly against universities and other prominent organizations. The group gained notoriety in 2012 after compromising dozens of universities and exposing large volumes of personal records belonging to students, faculty, staff, and alumni. It was also associated with subsequent intrusions affecting major organizations and the public release of large account datasets. Known aliases include GhostShell, TeamGhostShell, and Team_GhostShell. The actor’s historically documented operations align with hacktivist objectives centered on unauthorized access, data theft, and public disclosure of stolen information rather than ransomware. Reported activity indicates use of web application compromise, including SQL injection in some campaigns, to obtain access to backend data stores and exfiltrate records at scale. The group’s tradecraft is characterized by initial access through exploitation of internet-facing systems, theft of sensitive data, and leak-oriented post-compromise activity intended to maximize publicity and reputational impact on victims. The name GhostShell has also appeared in unrelated modern reporting for an Android spyware-as-a-service platform and for a separate cluster tracked as MB-0009 targeting Ukraine’s drone ecosystem. Those uses should not be conflated with Team GhostShell absent stronger attribution. High-confidence reporting supports Team GhostShell as a hacktivist actor distinct from those separate malware and intrusion designations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeting Ukraine’s drone sector, including military units, supply chains, and volunteer groups, using decoy documents and malware to steal information and disrupt Ukrainian defense-related networks.
TeamGhostShell posts "master list" of 548 leaks (so far)
Commercial Android spyware-as-a-service operation with a subscription model, reseller program, APK builder, credential theft, device surveillance, remote control, file management, and crypto clipper capabilities.
Published stolen personal records from 53 universities in a hacktivist-style campaign affecting higher education institutions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.