GhostHackers is a ransomware-as-a-service broker observed operating a dedicated dark-web storefront advertising ransomware tooling and related offensive capabilities. The actor has been associated with offerings that promote AES-256 encryption, user account control bypass, and offline execution, indicating support for ransomware deployment and post-compromise operations. Available reporting places GhostHackers in a broader ransomware ecosystem alongside other criminal handles such as Nova, Nightspire, Everest, and TheGentlemen, but there is no high-confidence evidence here that these are aliases rather than separate actors. The observed tradecraft references ATT&CK techniques consistent with exploitation of public-facing applications, use of valid accounts, credential dumping, remote services, archive collection, file deletion for defense evasion, and financial theft objectives. Based on the available facts, GhostHackers is best characterized as a financially motivated cybercriminal actor involved in enabling ransomware operations rather than a state-linked espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.