logo

Ransomware Tracker (Entry #214): GhosHacker

ID: 3a478b79-f74e-504d-b8f2-677d123d248c

STIX ID: report--3a478b79-f74e-504d-b8f2-677d123d248c

Feed Name: WatchGuard Secplicity Blog

Threat Score
50/100

Date Published: 2025-02-24

Date Updated: 2026-05-01

Author: Ryan Estes

...
...

GhosHacker is a NoCry-derived crypto-ransomware that changes the victim's wallpaper, displays a ransom modal, and encrypts files with AES appending the .red extension; actors demand $75 in Bitcoin and threaten deletion or increased extortion if unpaid. The variant is closely related to BlackSkull, Anonymous, and AzzaSec and appears to be part of a series of similar/test builds with limited public technical detail.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.