Our team members are from different countries and we are not interested in anything else, we are only interested in dollars. We do not allow CIS, Cuba, North Korea and China to be targeted. Re-attacks are not allowed for target companies that have already made payments. We do not allow non-profit hospitals and some non-profit organizations be targeted. Known victims: 5
Objectives
Executive Summary
gdlockersec is a newly emerged medium-sophistication threat actor with a primary motivation of organizational gain through ransomware activity and financial exploitation. The group exhibits strategic operational practices, including targeting restrictions for certain regions (e.g., CIS, Cuba, North Korea, and China) and avoiding re-targeting organizations that have already paid ransoms. While their activities are limited to date, they demonstrate a clear focus on financial gain through ransomware deployment.
Goals & Targeting
gdlockersec's strategic goals are centered on financial gain through ransomware deployment. While no specific sectors or countries have been explicitly targeted yet, the group has imposed restrictions on targeting certain regions (CIS, Cuba, North Korea, and China) and non-profit entities such as hospitals. This indicates a deliberate approach to minimize operational risks and avoid high-profile targets that could attract significant attention from law enforcement and international bodies. The group's focus on revictimization avoidance also reflects an attempt to maintain a sustained revenue stream without provoking retaliatory measures against their victims.
Enhanced Description
gdlockersec is a cybercriminal group that operates with a primary focus on generating revenue through ransomware activity. The group emphasizes strict operational rules, such as avoiding attacks on non-profit hospitals and certain geographic regions. This suggests a degree of self-regulation in their targeting strategy to mitigate potential backlash or legal consequences. While the group's activities are relatively new, their commitment to financial gain aligns with other established ransomware operators. The limited time frame since their first appearance (2025-01-24) indicates early-stage operational development, but their adherence to specific rules of engagement suggests a structured approach to victim selection and attack execution.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
gdlockersec has demonstrated early-stage campaign activity, with only five known victims identified so far. The group's adherence to operational rules suggests a structured approach to campaign management, including avoiding re-targeting organizations that have paid ransoms. While their geographic and sectoral targeting is not yet fully defined, the emphasis on financial gain indicates a focus on industries and regions where ransom payment compliance is higher.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the accuracy of this intelligence is moderate due to the limited timeline of observed activity (first seen: 2025-01-24). The group's operational rules and targeting restrictions align with known ransomware tactics, but specific technical details such as exact tools and techniques remain unclear. Further monitoring and analysis are required to confirm their full range of capabilities and campaign patterns.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics