Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GhostSec

Also known as: Ghost Security

Description

GhostSec is a hacktivist group that emerged as an offshoot of Anonymous. They primarily focused on counterterrorism efforts and monitoring online activities associated with terrorism. They gained prominence following the 2015 Charlie Hebdo shooting in Paris and the rise of ISIS.

AI Analysis

· 2 weeks ago

Executive Summary

GhostSec is a hacktivist group emerging from Anonymous, focusing on counterterrorism and online surveillance post-2015 Paris attacks. They use cyber means to disrupt groups they oppose, with activities linked to specific domains and hashes indicating botnet C2 infrastructure.

Goals & Targeting

They aim to disrupt terrorist activities and promote transparency by targeting groups linked to terrorism or those aiding them. Typically targeting sectors related to security, media, and government entities that align with their counterterrorism goals.

Enhanced Description

GhostSec operates as a hacktivist collective primarily targeting entities associated with terrorism or opposing counterterrorism efforts. Known for DDoS attacks and data leaks, they leverage botnets to amplify their impact. Their tools include malware tracked through specific SHA-256 hashes and C2 servers hosted on particular IPs.

Key Capabilities

  • Advanced botnet infrastructure
  • DDoS attacks
  • Data exfiltration
  • Spear-phishing campaigns

MITRE ATT&CK Tactics

Network Operations
Disruption
Exfiltration

ATT&CK Techniques

T1045.004 - Botnet Communication C2/Dropzone Creation/Artifacts Generation: Web Request
T1486 - Use of Cloud Compute Infrastructure for Malicious Activities
T1071.001 - Email Spear Phishing Attachment: Static Payload

Software / Tooling

Botnet malware (based on sample hashes)
Custom C2 tools

Campaigns & Victims

Known for high-profile campaigns post-Paris attacks, with sustained activity targeting terrorism-associated groups. Campaigns often involve coordinated DDoS and data dumps to disrupt operations.

IOC Patterns

  • Hashes associated with botnet malware: a1b468e9550f9960c5e60f7c52ca3c058de19d42eafa760b9d5282eb24b7c55f, 8fa28795e4cd95e6c78c4a1308ea80674102669f9980b2006599d82eff6237b3
  • IP addresses linked to C2 servers: 94.103.91.246

Recommended Actions

  • Monitor network traffic for botnet-like activities on listed IPs
  • Implement email filtering to detect spear-phishing attempts
  • Secure web applications against C2 server impersonation

Suggested Tags

Hacktivism
Terrorism-related
DDoS
Botnets

Confidence Assessment

High confidence in identifying GhostSec as a hacktivist group with counterterrorism motives. Some aspects like exact TTPs are uncertain.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

10

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Hacktivism
Terrorism-related
DDoS
Botnets

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.