Also known as: other aliases, several other aliases, Jumpy Pisces, ALPHV, Gleaming Pisces, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, APT28, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, BokBot, Gold Southfield, PlayCrypt, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla, Snake
Ghostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the World-Check and leaking about 186GB of data from a stock trading platform. They have been active on Breachforums.is, revealing massive data breaches involving comprehensive details of Thai users, including full names, phone numbers, email addresses, and ID card numbers.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GhostR is a financially motivated threat actor known for targeting sensitive databases and leaking large volumes of stolen data. Their activities include sophisticated cyberattacks on financial platforms and entities, resulting in significant data breaches involving personal and financial information of millions of individuals.
Goals & Targeting
GhostR's strategic objectives appear to revolve around financial exploitation through data theft. They target sectors with high-value information, such as finance and trading platforms. Their geographic focus seems concentrated on regions or countries where their activities can yield the highest returns, though specific targeting of particular geographies beyond Thailand is not well-documented.
Enhanced Description
GhostR operates with a primary focus on financial gain, often carrying out cyberattacks to steal valuable datasets from organizations. They have been observed targeting stock trading platforms and other financial institutions, where they seek to compromise sensitive data for potential resale or extortion. Their activities are marked by a high degree of technical proficiency, often involving advanced tactics such as phishing, social engineering, and lateral movement within targeted networks. GhostR has also been associated with Breachforums.is, where they have shared and leaked stolen data, including personal details of Thai users.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GhostR's campaigns typically involve targeted attacks on financial institutions and data-rich organizations. They appear to operate with a moderate operational tempo, focusing on high-value targets rather than volume. Their use of forums like Breachforums.is suggests a pattern of sharing stolen data for notoriety or financial gain. Notable past operations include the theft of 5.3 million records from World-Check and 186GB of data from a stock trading platform.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in specific details about GhostR due to the lack of comprehensive reporting. While their activities are documented in some forums and data breach reports, further information on their exact capabilities, tactics, and tools would enhance the accuracy of this assessment.
No campaigns linked yet.
No observed data linked yet.
10
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
7
Tactics