logo

Ghost Locker 2.0: The Evolving Threat of Ransomware-as-a-Service Unveiled by GhostSec

ID: 277a7c6f-2324-59c0-b4fb-ff38e6da5b5a

STIX ID: report--277a7c6f-2324-59c0-b4fb-ff38e6da5b5a

Feed Name: Seqrite Blog

Threat Score
75/100

Date Published: 2024-04-18

Date Updated: 2026-04-30

Author: Rumana Siddiqui

...
...

Ghost Locker is a Ransomware-as-a-Service (RaaS) from GhostSec with two tracked variants (v1 Python, v2 Go) that register victims with C2 servers, exfiltrate specified file types, encrypt files (appending .ghost) using AES/Fernet, kill actor-defined services/processes to evade detection, and drop a ransom note; the report includes technical indicators (C2 IPs, a file hash), a YARA rule, and MITRE ATT&CK TTP mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.