Ghost Locker 2.0: The Evolving Threat of Ransomware-as-a-Service Unveiled by GhostSec
ID: 277a7c6f-2324-59c0-b4fb-ff38e6da5b5a
STIX ID: report--277a7c6f-2324-59c0-b4fb-ff38e6da5b5a
Feed Name: Seqrite Blog
Threat Score
Ghost Locker is a Ransomware-as-a-Service (RaaS) from GhostSec with two tracked variants (v1 Python, v2 Go) that register victims with C2 servers, exfiltrate specified file types, encrypt files (appending .ghost) using AES/Fernet, kill actor-defined services/processes to evade detection, and drop a ransom note; the report includes technical indicators (C2 IPs, a file hash), a YARA rule, and MITRE ATT&CK TTP mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
