Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors gdlockersec

Description

Our team members are from different countries and we are not interested in anything else, we are only interested in dollars. We do not allow CIS, Cuba, North Korea and China to be targeted. Re-attacks are not allowed for target companies that have already made payments. We do not allow non-profit hospitals and some non-profit organizations be targeted. Known victims: 5

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

gdlockersec is a newly emerged medium-sophistication threat actor with a primary motivation of organizational gain through ransomware activity and financial exploitation. The group exhibits strategic operational practices, including targeting restrictions for certain regions (e.g., CIS, Cuba, North Korea, and China) and avoiding re-targeting organizations that have already paid ransoms. While their activities are limited to date, they demonstrate a clear focus on financial gain through ransomware deployment.

Goals & Targeting

gdlockersec's strategic goals are centered on financial gain through ransomware deployment. While no specific sectors or countries have been explicitly targeted yet, the group has imposed restrictions on targeting certain regions (CIS, Cuba, North Korea, and China) and non-profit entities such as hospitals. This indicates a deliberate approach to minimize operational risks and avoid high-profile targets that could attract significant attention from law enforcement and international bodies. The group's focus on revictimization avoidance also reflects an attempt to maintain a sustained revenue stream without provoking retaliatory measures against their victims.

Enhanced Description

gdlockersec is a cybercriminal group that operates with a primary focus on generating revenue through ransomware activity. The group emphasizes strict operational rules, such as avoiding attacks on non-profit hospitals and certain geographic regions. This suggests a degree of self-regulation in their targeting strategy to mitigate potential backlash or legal consequences. While the group's activities are relatively new, their commitment to financial gain aligns with other established ransomware operators. The limited time frame since their first appearance (2025-01-24) indicates early-stage operational development, but their adherence to specific rules of engagement suggests a structured approach to victim selection and attack execution.

Key Capabilities

  • Ransomware deployment
  • Phishing and social engineering
  • Encryption of victim data
  • Command-and-control communication

MITRE ATT&CK Tactics

Ransomware
Persistence
Exfiltration

ATT&CK Techniques

T1486.001
T1567.001
T1055
T1218

Software / Tooling

Custom ransomware variant
Phishing emails with malicious attachments

Campaigns & Victims

gdlockersec has demonstrated early-stage campaign activity, with only five known victims identified so far. The group's adherence to operational rules suggests a structured approach to campaign management, including avoiding re-targeting organizations that have paid ransoms. While their geographic and sectoral targeting is not yet fully defined, the emphasis on financial gain indicates a focus on industries and regions where ransom payment compliance is higher.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Encrypted files with specific extension patterns (e.g., .gdlockersec)
  • Command-and-control communication over暗网 or encrypted channels

Recommended Actions

  • Implement robust email filtering and phishing detection mechanisms to mitigate spear-phishing attempts.
  • Conduct regular vulnerability assessments and apply patches to systems to reduce attack surface.
  • Monitor for unusual file encryption patterns and implement data backup solutions with air-gapped storage.
  • Establish incident response plans tailored to ransomware scenarios, including communication with law enforcement.

Suggested Tags

APT
ransomware
financial-motivation
emerging-group

Confidence Assessment

Confidence in the accuracy of this intelligence is moderate due to the limited timeline of observed activity (first seen: 2025-01-24). The group's operational rules and targeting restrictions align with known ransomware tactics, but specific technical details such as exact tools and techniques remain unclear. Further monitoring and analysis are required to confirm their full range of capabilities and campaign patterns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Healthcare Targeting
Critical Infrastructure
APT
ransomware
financial-motivation
emerging-group

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jan 24, 2025
Last Seen
Jan 26, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.