Also known as: GSG, tracked as, CVE-2026-60348
Global Secret Group surfaced in late 2024 as an opportunistic ransomware actor that blends technical proficiency with aggressive extortion tactics. Initial access is typically achieved via spear‑phishing attachments or compromise of remote desktop credentials, allowing the group to establish footholds quickly. From there, GSG employs rapid lateral movement over remote protocols and credential dumping (using tools such as a Go‑language backdoor dubbed GoGRPC) to gain administrative privileges across an enterprise. Before enacting encryption—data encrypted for impact (T1486)—the actor systematically exfiltrates substantial data sets, often ranging from 100 GB to 321 GB. The stolen files are uploaded to cloud storage and then permanently posted on a leak site operating over the Tor network, with onion addresses that include victim identities. By releasing the exfiltrated content publicly and incrementally, GSG creates escalating pressure for victims to pay. GSG’s operational arsenal includes classic ransomware modules such as AvosLocker and Qilin, alongside custom backdoors that function both as command‑and‑control channels and as data exfiltration gateways. The group also leverages remote‑access tools and a suite of credential‑dumping utilities. Their dual‑extortion model—encryption coupled with public disclosure—highlights a sophisticated understanding of reputation management. Operations span multiple industries, demonstrating opportunistic targeting rather than sector specialization. Victims include manufacturing plants, healthcare providers, financial services firms, as well as non‑profit and retail organizations. The attacker’s timeline is aggressive: within days of exfiltration the leak site is populated with massive files, often exceeding 300 GB, prompting fast ransom negotiations.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Global Secret Group (GSG) is a medium‑sophistication ransomware collective that emerged in late 2024, leveraging dual extortion by exfiltrating large volumes of data before encrypting victim systems and then publicly leaking the files on a Tor‑based site. Their campaigns target mid‑market organizations across diverse sectors in the US, India, Spain, Brazil, and Canada, forcing victims to choose between ransom payment and reputational damage.
Goals & Targeting
GSG seeks direct financial gain through ransomware payouts while simultaneously leveraging reputational harm to increase coercive pressure—a hallmark of double‑extortion campaigns. The actor’s geographic reach across the United States, India, Spain, Brazil, and Canada indicates an intent to exploit the large number of mid‑market firms that may lack robust data protection postures. By targeting a broad spectrum of sectors—healthcare, finance, manufacturing, telecommunications, energy, defense, aviation, gaming, retail, construction, and aerospace—the group maximizes its attack surface, favoring organizations with valuable corporate documents, personal employee data, or other assets that can be used in public doxxing. The focus on mid‑market enterprises (50–500 employees) aligns with their need for relatively low effort per victim while still delivering high ransom demands. Strategically, GSG appears to be building a pipeline of victims they can systematically threaten with public leaks, capitalising on the speed of modern cloud‑based exfiltration and the ease of orchestrating coordinated leak events via Tor. This modus operandi points to an actor that values both immediate revenue and long‑term reputational leverage.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its debut, Global Secret Group has executed dozens of campaigns across more than a dozen countries and sectors. Their operations are characterized by high speed: initial compromise through phishing or RDP credential theft, followed almost immediately by bulk data exfiltration to the cloud, culminating in ransomware encryption within 24–48 hours. The leak sites they use host tens of thousands of files (up to 322,742) and numerous folders, underscoring a commitment to rapid public disclosure. Victim profiles tend toward mid‑size enterprises (50–500 employees), yet the group has also targeted larger firms with a public presence, suggesting adaptability to target selection. GSG’s pattern includes incremental releases from the leak site—spreading files over days—to sustain pressure on victims and maintain negotiation leverage.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available information, drawn from recent threat reports and observed campaign behaviors, provides high confidence in identifying GSG’s tactical patterns—initial phishing/RDP theft, rapid lateral movement, dual‑extortion with public leak. However, gaps remain regarding definitive attribution and the full spectrum of malware variants used by the actor. Infrastructure details such as command‑and‑control IP addresses, hosting services, or persistent data exfiltration vectors are not fully disclosed in these sources.
No observed data linked yet.
7
Techniques
33
Tools
120
Campaigns
39
IOCs
0
Observed Data
6
Tactics