Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors global secret group

global secret group

TLP:CLEAR
Active

Also known as: GSG, tracked as, CVE-2026-60348

Description

Global Secret Group surfaced in late 2024 as an opportunistic ransomware actor that blends technical proficiency with aggressive extortion tactics. Initial access is typically achieved via spear‑phishing attachments or compromise of remote desktop credentials, allowing the group to establish footholds quickly. From there, GSG employs rapid lateral movement over remote protocols and credential dumping (using tools such as a Go‑language backdoor dubbed GoGRPC) to gain administrative privileges across an enterprise. Before enacting encryption—data encrypted for impact (T1486)—the actor systematically exfiltrates substantial data sets, often ranging from 100 GB to 321 GB. The stolen files are uploaded to cloud storage and then permanently posted on a leak site operating over the Tor network, with onion addresses that include victim identities. By releasing the exfiltrated content publicly and incrementally, GSG creates escalating pressure for victims to pay. GSG’s operational arsenal includes classic ransomware modules such as AvosLocker and Qilin, alongside custom backdoors that function both as command‑and‑control channels and as data exfiltration gateways. The group also leverages remote‑access tools and a suite of credential‑dumping utilities. Their dual‑extortion model—encryption coupled with public disclosure—highlights a sophisticated understanding of reputation management. Operations span multiple industries, demonstrating opportunistic targeting rather than sector specialization. Victims include manufacturing plants, healthcare providers, financial services firms, as well as non‑profit and retail organizations. The attacker’s timeline is aggressive: within days of exfiltration the leak site is populated with massive files, often exceeding 300 GB, prompting fast ransom negotiations.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Healthcare
Financial services
Manufacturing
Non profit
Transportation
Defense
Gaming
Telecommunications
Retail
Energy
Construction
Aviation
Aerospace
Information technology

Targeted Countries / Regions

US
IN
ES
BR
CA

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 21 hours ago

Executive Summary

Global Secret Group (GSG) is a medium‑sophistication ransomware collective that emerged in late 2024, leveraging dual extortion by exfiltrating large volumes of data before encrypting victim systems and then publicly leaking the files on a Tor‑based site. Their campaigns target mid‑market organizations across diverse sectors in the US, India, Spain, Brazil, and Canada, forcing victims to choose between ransom payment and reputational damage.

Goals & Targeting

GSG seeks direct financial gain through ransomware payouts while simultaneously leveraging reputational harm to increase coercive pressure—a hallmark of double‑extortion campaigns. The actor’s geographic reach across the United States, India, Spain, Brazil, and Canada indicates an intent to exploit the large number of mid‑market firms that may lack robust data protection postures. By targeting a broad spectrum of sectors—healthcare, finance, manufacturing, telecommunications, energy, defense, aviation, gaming, retail, construction, and aerospace—the group maximizes its attack surface, favoring organizations with valuable corporate documents, personal employee data, or other assets that can be used in public doxxing. The focus on mid‑market enterprises (50–500 employees) aligns with their need for relatively low effort per victim while still delivering high ransom demands. Strategically, GSG appears to be building a pipeline of victims they can systematically threaten with public leaks, capitalising on the speed of modern cloud‑based exfiltration and the ease of orchestrating coordinated leak events via Tor. This modus operandi points to an actor that values both immediate revenue and long‑term reputational leverage.

Enhanced Description

Key Capabilities

  • Compromising remote desktop credentials
  • Phishing-based initial access
  • Rapid lateral movement over remote services
  • Credential dumping via GoGRPC backdoor
  • Data exfiltration via cloud storage services
  • Dual extortion with encryption and public leak
  • Fast data publication on Tor leak site
  • Large‑volume data theft (up to 321 GB)
  • Ransomware deployment
  • Public victim disclosure

MITRE ATT&CK Tactics

Initial Access
Credential Access
Lateral Movement
Exfiltration
Impact

ATT&CK Techniques

T1566
T1078
T1105
T1567.001
T1486
T1041
T1550.006

Software / Tooling

GoGRPC backdoor
AvosLocker ransomware
Qilin ransomware
DoxxScan infostealer

Campaigns & Victims

Since its debut, Global Secret Group has executed dozens of campaigns across more than a dozen countries and sectors. Their operations are characterized by high speed: initial compromise through phishing or RDP credential theft, followed almost immediately by bulk data exfiltration to the cloud, culminating in ransomware encryption within 24–48 hours. The leak sites they use host tens of thousands of files (up to 322,742) and numerous folders, underscoring a commitment to rapid public disclosure. Victim profiles tend toward mid‑size enterprises (50–500 employees), yet the group has also targeted larger firms with a public presence, suggesting adaptability to target selection. GSG’s pattern includes incremental releases from the leak site—spreading files over days—to sustain pressure on victims and maintain negotiation leverage.

IOC Patterns

  • Leak site on Tor onion address
  • Large corporate document volumes up to 321 GB leaked
  • Public victim disclosure and incremental file releases

Recommended Actions

  • Enforce least‑privileged remote desktop (RDP) usage and monitor for anomalous RDP logins
  • Implement comprehensive phishing detection controls and conduct user training campaigns
  • Maintain current, off‑site backups and test restoration procedures regularly to mitigate ransomware impact
  • Deploy data loss prevention (DLP) solutions and monitor unusual cloud storage activity indicative of exfiltration
  • Use threat intelligence feeds to track publicly disclosed leak sites and preemptively identify potential victim reports
  • Apply security controls around key assets—such as strong multi‑factor authentication, endpoint detection and response (EDR), and network segmentation—to hinder lateral movement
  • Keep all software up to date and patch known vulnerabilities promptly

Suggested Tags

ransomware
double-extortion
mid-market targeting
phishing
remote desktop exploitation
cloud exfiltration
leak site
Global Secret Group
Data Theft
Non-governmental actor

Confidence Assessment

The available information, drawn from recent threat reports and observed campaign behaviors, provides high confidence in identifying GSG’s tactical patterns—initial phishing/RDP theft, rapid lateral movement, dual‑extortion with public leak. However, gaps remain regarding definitive attribution and the full spectrum of malware variants used by the actor. Infrastructure details such as command‑and‑control IP addresses, hosting services, or persistent data exfiltration vectors are not fully disclosed in these sources.

ATT&CK Techniques

Campaigns / Victims

Observed Data

No observed data linked yet.

References

Intel Summary

7

Techniques

33

Tools

120

Campaigns

39

IOCs

0

Observed Data

6

Tactics

Tags

ransomware
dual-extortion
data-exfiltration
cloud exfiltration
tor leak site
public disclosure
phishing
remote-desktop compromise
credential dumping
Lateral Movement
Go backdoor
GSG
mid-market enterprises
mid-2026
identity-theft
doxxing
double-extortion
mid-market targeting
remote desktop exploitation
leak site
Global Secret Group
Data Theft
Non-governmental actor

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
Brazil (BR)
Confidence
80%
Last Seen
Aug 10, 2026
Added
Jul 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.