Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GhostR

Also known as: other aliases, several other aliases, Jumpy Pisces, ALPHV, Gleaming Pisces, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, APT28, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, BokBot, Gold Southfield, PlayCrypt, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla, Snake

Description

Ghostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the World-Check and leaking about 186GB of data from a stock trading platform. They have been active on Breachforums.is, revealing massive data breaches involving comprehensive details of Thai users, including full names, phone numbers, email addresses, and ID card numbers.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Critical infrastructure
Education
Manufacturing
Energy
Media
Non profit
Aerospace
Hospitality
Aviation
Transportation
Retail
Information technology
Think tank
Pharmaceutical
Maritime
Gaming
Legal services
Chemical
Mining
Nuclear
Construction
Utilities
Entertainment
Oil gas
Food agriculture

Targeted Countries / Regions

CN
US
RU
UA
IR
IN
GB
JP
VN
AU
KR
TW
IL
DE
PL
KP
PK
BY
SG
SA
AE
CA
TR
BR
MX
ES
FR
IT
KZ
RO
NG
LB
AZ

AI Analysis

· 1 week ago

Executive Summary

GhostR is a financially motivated threat actor known for targeting sensitive databases and leaking large volumes of stolen data. Their activities include sophisticated cyberattacks on financial platforms and entities, resulting in significant data breaches involving personal and financial information of millions of individuals.

Goals & Targeting

GhostR's strategic objectives appear to revolve around financial exploitation through data theft. They target sectors with high-value information, such as finance and trading platforms. Their geographic focus seems concentrated on regions or countries where their activities can yield the highest returns, though specific targeting of particular geographies beyond Thailand is not well-documented.

Enhanced Description

GhostR operates with a primary focus on financial gain, often carrying out cyberattacks to steal valuable datasets from organizations. They have been observed targeting stock trading platforms and other financial institutions, where they seek to compromise sensitive data for potential resale or extortion. Their activities are marked by a high degree of technical proficiency, often involving advanced tactics such as phishing, social engineering, and lateral movement within targeted networks. GhostR has also been associated with Breachforums.is, where they have shared and leaked stolen data, including personal details of Thai users.

Key Capabilities

  • Advanced phishing techniques
  • Data exfiltration
  • Spear-phishing campaigns
  • Compromise of sensitive financial systems

MITRE ATT&CK Tactics

Exfiltration
Credential Access
Phishing

ATT&CK Techniques

T1566.001
T1003.001
T1078.001
T1566.002

Software / Tooling

Custom phishing tools
Data exfiltration utilities
Lateral movement frameworks

Campaigns & Victims

GhostR's campaigns typically involve targeted attacks on financial institutions and data-rich organizations. They appear to operate with a moderate operational tempo, focusing on high-value targets rather than volume. Their use of forums like Breachforums.is suggests a pattern of sharing stolen data for notoriety or financial gain. Notable past operations include the theft of 5.3 million records from World-Check and 186GB of data from a stock trading platform.

IOC Patterns

  • Phishing emails with malicious links
  • Spear-phishing campaigns targeting financial sectors
  • Data exfiltration activities via encrypted channels

Recommended Actions

  • Implement robust phishing detection mechanisms
  • Enhance data exfiltration monitoring
  • Conduct regular security audits of financial systems
  • Secure and monitor forums and dark web activity for potential leaks

Suggested Tags

Financial APT
Data Theft
Phishing
Threat Sharing Forums

Confidence Assessment

Low confidence in specific details about GhostR due to the lack of comprehensive reporting. While their activities are documented in some forums and data breach reports, further information on their exact capabilities, tactics, and tools would enhance the accuracy of this assessment.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 10 Filename 9 MD5 Hash 1

References

  1. www.huntress.com — Cited by web research for: other aliases
  2. unit42.paloaltonetworks.com — Cited by web research for: T1486
  3. attack.mitre.org — Cited by web research for: Winnti
  4. attack.mitre.org — Cited by web research for: CVE-2023-48022

Intel Summary

10

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

7

Tactics

Tags

Financial Targeting
Data Exfiltration
Financial APT
Data Theft
Phishing
Threat Sharing Forums

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.