Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GlobalSecretGroup

Also known as: tracked as, APT43, Midnight Blizzard, Nobelium, NGOs, tech providers, Masked Spider, Abyss Locker

Description

GlobalSecretGroup—also tracked under aliases such as APT43, Midnight Blizzard, Abyss Locker and Masked Spider—is an emerging ransomware‑as‑a‑service threat first observed in 2025. The actor has claimed responsibility for over seventeen victims across the United States, India, Brazil, and several other countries, affecting sectors ranging from healthcare and defense to finance, government and critical infrastructure. Their approach combines initial spearphishing attachments or exploitation of public applications with remote service-based lateral movement, culminating in data encryption (T1486) and exfiltration (T1041). Following a successful compromise, GlobalSecretGroup uploads exfiltrated data to a dedicated leak site hosted on a Tor .onion service. Victims are instructed to contact the actor via Tor or Telegram to obtain decryption tools; refusal results in key deletion and public disclosure of the encrypted data after seven days—a tactic designed to create urgency and pressure. The operator employs a suite of malware families—including SynAck, BlackCat, LockBit 3.0, Clop, Qilin and others—indicating a modular toolbox approach that supports rapid deployment across diverse target environments. Publicly available indicators show use of phishing frameworks, Evilginx backdoors, and legitimate-looking ransomware bundles such as RansomHub. Despite the lack of concrete attribution details, security researchers consistently note GlobalSecretGroup’s sophisticated delivery methods and aggressive ransom demands, positioning it among the most threatening ransomware‑as‑a‑service groups observed in recent years.

Goals & Targeting

Targeted Sectors

Healthcare
Manufacturing
Defense
Financial services
Government
Transportation
Retail
Telecommunications
Non profit
Oil gas
Hospitality
Utilities
Construction
Legal services
Mining
Chemical
Critical infrastructure
Information technology
Aviation

Targeted Countries / Regions

US
RU
BR
CN
GB
AU
MX
ES
CA
UA
IN
IQ

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

GlobalSecretGroup, an emerging ransomware‑as‑a‑service actor active since 2025, has struck more than 17 victims across the United States, India and Brazil, targeting a wide array of industries including healthcare, finance, defense, and critical infrastructure. The group encrypts victim data, exfiltrates it to remote servers and publishes leaked files on a dedicated .onion site if the ransom is not paid within seven days. Their operations combine phishing, exploitation of public‑facing applications and lateral movement through remote services.

Goals & Targeting

GlobalSecretGroup pursues a purely financial objective by monetizing data encryption attacks. Their strategy focuses on high‑value or highly regulated sectors where data is critical to operational continuity, including healthcare, defense, finance and critical infrastructure. The actor leverages phishing, exploitation of software supply chains (T1195.001) and remote services to gain initial access and expand within victim networks, then exfiltrates data for potential black‑mail before demanding payment. Persistence in hosting the leak site on a hidden service further ensures anonymity while applying pressure on victims.

Enhanced Description

Key Capabilities

  • Ransomware-as-a-Service delivery
  • Targeting multiple sectors
  • Encrypt victim data
  • Upload exfiltrated data to remote server
  • Maintain dedicated leak site

MITRE ATT&CK Tactics

Impact
Exfiltration
Privilege Escalation
Execution
Persistence
Initial Access
Defense Evasion
Disruption

ATT&CK Techniques

T1041
T1053
T1078
T1083
T1110
T1127
T1195.001
T1190
T1203
T1219
T1222.001
T1236
T1294
T1505.002
T1518.001
T1526
T1531
T1553.003
T1562.006
T1572.001
T1589.001
T1640.004
T1486

Software / Tooling

SynAck
RansomHub
BlackCat
Akira
LockBit 3.0
Black Basta
Clop
Qilin
INC Ransomware
Dark
Anubis
BianLian
Evilginx
Pink
Crisis
Leverage
Phishing tools
8Base
Global Secret Group ransomware
Brain Cipher
Infostealer

Campaigns & Victims

The group’s activity has been concentrated between 2025 and the present, with a notable escalation in 2025 when they claimed responsibility for a dozen high‑profile victims. Campaigns typically involve spearphishing attachments or exploitation of public applications followed by lateral movement via scheduled tasks and remote services. Victims are subjected to data encryption and exfiltration; if ransom demands are unmet within seven days, leaked datasets are publicly released on an .onion domain. This pattern suggests a focus on maximizing financial gain while maintaining operational secrecy through Tor-based leak sites.

IOC Patterns

  • Domain
  • URL
  • Email address
  • Tor Hidden Service URL
  • Telegram channel

Recommended Actions

  • Block outbound traffic to identified malicious domains and .onion addresses; update firewall and DNS filtering accordingly.
  • Implement multi‑factor authentication and least‑privilege access controls, especially for remote services such as RDP/SSH.
  • Enable network segmentation and restrict lateral movement via mandatory use of privileged account management.
  • Deploy email security solutions that include attachment sandboxing and link scanning to thwart spearphishing campaigns.
  • Establish automated exfiltration detection using outbound traffic analytics and anomaly detection tools.
  • Maintain regular, off‑site, immutable backups for critical data sets and test restoration procedures weekly.
  • Conduct targeted security awareness training emphasizing phishing recognition and safe URL practices.

Suggested Tags

ransomware
ransomware-as-a-service
2025 emerging threat
Abyss
Extortion
Dedicated Leak Site
Tor Hidden Service

Confidence Assessment

The available intelligence provides a clear picture of GlobalSecretGroup’s tactics, techniques, and procedures (TTPs) in terms of ransomware delivery, exfiltration, and leak‑site usage. However, certain contextual elements—such as the group’s exact origins, attribution details, long‑term operational tempo, and comprehensive victim list—remain uncertain due to limited publicly disclosed data. Confidence is moderate to high for technical indicators but lower regarding strategic narratives and threat actor lineage.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 Email Address 1 URL 1

References

  1. deepstrike.io — Cited by web research for: Midnight Blizzard
  2. www.vectra.ai — Cited by web research for: T1053
  3. cyber.netsecops.io — Cited by web research for: T1195.001
  4. www.group-ib.com — Cited by web research for: Lynx
  5. areteir.com — Cited by web research for: Leverage
  6. areteir.com — Cited by web research for: CVE-2025-59718
  7. www.galaxywarden.com — Cited by web research for: Construction
  8. https://areteir.com/resources/ransomhub-leverages-new-betruger-backdoor — Cited by AI analysis.
  9. http://xb6q2aggycmlcrjtbjendcnnwpmmwbosqaugxsqb4nx6cmod3emy7sad.onion/contact — Cited by AI analysis.
  10. https://t.me/eightbase — Cited by AI analysis.
  11. https://torproject.org — Cited by AI analysis.

Intel Summary

35

Techniques

43

Tools

0

Campaigns

39

IOCs

0

Observed Data

14

Tactics

Tags

ransomware
ransomware-as-a-service
2025 emerging threat
Abyss
Extortion
Dedicated Leak Site
Tor Hidden Service

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
North Korea (KP)
Confidence
60%
Added
Aug 7, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.