Global Secret Group is a ransomware threat actor associated with extortion-driven intrusions and public claims of data theft against organizations in multiple countries. Reported victims span the United States, Argentina, Cyprus, Finland, India, and the United Arab Emirates, indicating opportunistic or broad targeting rather than a narrowly defined vertical focus. Observed victim sectors include technology, telecommunications, financial services, healthcare, manufacturing, retail, logistics, construction, and energy. The group is linked to ransomware incidents that also involve alleged data exfiltration and breach disclosure, consistent with double-extortion tradecraft in which encryption and theft are used to pressure victims. Publicly attributed activity shows repeated claims against small and mid-sized enterprises as well as larger commercial organizations, with emphasis on operational disruption and exposure of stolen corporate data. Available reporting ties the actor to ransomware operations, victim shaming or leak-style disclosures, and compromises affecting diverse business environments. Some incident narratives reference telecom and network-oriented assessment activity, including deep-packet inspection, backbone traffic analysis, satellite communications, cryptographic key management review, zero-trust architecture review, and SS7-related assessment themes; however, these details are limited and do not by themselves establish a distinctive or fully corroborated intrusion methodology for the actor. No high-confidence public attribution to a specific nation state is currently available. The actor is best characterized as a financially motivated ransomware group. Known alias usage in the available data is limited to Global Secret Group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack resulting in a data breach against Stratos Network.
Conducting a ransomware attack against Cipher Dynamics, a technology-sector organization in India.
Conducting a ransomware attack resulting in a data breach against Prism Telecom.
Conducting a ransomware attack resulting in a data breach against One Plus Capital, a financial services organization in Cyprus.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.