Also known as: tracked as, APT43, Midnight Blizzard, Nobelium, NGOs, tech providers, Masked Spider, Abyss Locker
GlobalSecretGroup—also tracked under aliases such as APT43, Midnight Blizzard, Abyss Locker and Masked Spider—is an emerging ransomware‑as‑a‑service threat first observed in 2025. The actor has claimed responsibility for over seventeen victims across the United States, India, Brazil, and several other countries, affecting sectors ranging from healthcare and defense to finance, government and critical infrastructure. Their approach combines initial spearphishing attachments or exploitation of public applications with remote service-based lateral movement, culminating in data encryption (T1486) and exfiltration (T1041). Following a successful compromise, GlobalSecretGroup uploads exfiltrated data to a dedicated leak site hosted on a Tor .onion service. Victims are instructed to contact the actor via Tor or Telegram to obtain decryption tools; refusal results in key deletion and public disclosure of the encrypted data after seven days—a tactic designed to create urgency and pressure. The operator employs a suite of malware families—including SynAck, BlackCat, LockBit 3.0, Clop, Qilin and others—indicating a modular toolbox approach that supports rapid deployment across diverse target environments. Publicly available indicators show use of phishing frameworks, Evilginx backdoors, and legitimate-looking ransomware bundles such as RansomHub. Despite the lack of concrete attribution details, security researchers consistently note GlobalSecretGroup’s sophisticated delivery methods and aggressive ransom demands, positioning it among the most threatening ransomware‑as‑a‑service groups observed in recent years.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GlobalSecretGroup, an emerging ransomware‑as‑a‑service actor active since 2025, has struck more than 17 victims across the United States, India and Brazil, targeting a wide array of industries including healthcare, finance, defense, and critical infrastructure. The group encrypts victim data, exfiltrates it to remote servers and publishes leaked files on a dedicated .onion site if the ransom is not paid within seven days. Their operations combine phishing, exploitation of public‑facing applications and lateral movement through remote services.
Goals & Targeting
GlobalSecretGroup pursues a purely financial objective by monetizing data encryption attacks. Their strategy focuses on high‑value or highly regulated sectors where data is critical to operational continuity, including healthcare, defense, finance and critical infrastructure. The actor leverages phishing, exploitation of software supply chains (T1195.001) and remote services to gain initial access and expand within victim networks, then exfiltrates data for potential black‑mail before demanding payment. Persistence in hosting the leak site on a hidden service further ensures anonymity while applying pressure on victims.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The group’s activity has been concentrated between 2025 and the present, with a notable escalation in 2025 when they claimed responsibility for a dozen high‑profile victims. Campaigns typically involve spearphishing attachments or exploitation of public applications followed by lateral movement via scheduled tasks and remote services. Victims are subjected to data encryption and exfiltration; if ransom demands are unmet within seven days, leaked datasets are publicly released on an .onion domain. This pattern suggests a focus on maximizing financial gain while maintaining operational secrecy through Tor-based leak sites.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence provides a clear picture of GlobalSecretGroup’s tactics, techniques, and procedures (TTPs) in terms of ransomware delivery, exfiltration, and leak‑site usage. However, certain contextual elements—such as the group’s exact origins, attribution details, long‑term operational tempo, and comprehensive victim list—remain uncertain due to limited publicly disclosed data. Confidence is moderate to high for technical indicators but lower regarding strategic narratives and threat actor lineage.
No campaigns linked yet.
No observed data linked yet.
35
Techniques
43
Tools
0
Campaigns
39
IOCs
0
Observed Data
14
Tactics