GhostLocker is a name used in the provided content for two distinct malicious/security-related tools. First, it is described as a tool developed by security researcher zero2504 that neutralizes Endpoint Detection and Response (EDR) products by abusing the native Windows AppLocker feature. It deploys AppLocker deny rules against EDR user-mode executables in dynamic and static modes, preventing those components from running after policy application and reboot. Although it does not block EDR kernel drivers, the content states this effectively blinds commercial EDR products because telemetry can no longer be analyzed or surfaced, while management consoles may still show agents as online and protected. The technique is characterized as abuse of legitimate administrative functionality rather than an exploit, and defenders are advised to monitor AppLocker policy changes and validate security product execution status.
Second, GhostLocker is also referenced as ransomware operated by GhostSec as a ransomware-as-a-service (RaaS) offering developed in October 2023 to fund the group’s hacktivist activities. The content states GhostSec later announced it would exit ransomware and transfer GhostLocker operations to the Stormous ransomware group in May 2024. GhostSec is associated in the content with DDoS, ICS targeting, industrial sabotage, data exfiltration, extortion, and ransomware, and GhostLocker is listed alongside other GhostSec tooling such as GhostStealer and Ghostly Development malware.
Because the supplied content conflates an AppLocker-based EDR-disabling tool and a ransomware family under the same name, the exact canonical malware definition is ambiguous from the available information. High-confidence associations in the content tie GhostLocker to GhostSec and later Stormous in the ransomware context, and to Windows AppLocker abuse for disabling EDR in the separate tool context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
GhostLocker is a tool designed to neutralize EDR solutions by leveraging Windows AppLocker to block EDR userland processes, effectively blinding the EDR's behavioral analysis and alerting capabilities while leaving kernel drivers operational.
Ransomware attributed to/used by GhostSec as part of extortion and disruptive operations.
GhostLocker is a ransomware-as-a-service platform developed by GhostSec, used to fund hacktivist activities, with strict rules against targeting healthcare and education.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.