Actor Profile

🏹 GDLockerSec — Ransomware

Our team members are from different countries and we are not interested in anything else, we are only interested in dollars. We do not allow CIS, Cuba, North Korea and China to be targeted. Re-attacks are not allowed for target companies that have already made payments. We do not allow non-profit hospitals and some non-profit organizations be targeted.

Classification

Ransomware

Leak-site victims

5
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (5)

VictimCountryPublishedDomain
www.fgse.cu.edu.eg EG 2025-01-26T19:29:25.544312+00:00 fgse.cu.edu.eg
aws.amazon.com US 2025-01-24T16:48:09.243902+00:00 aws.amazon.com
www.usmba.ac.ma MA 2025-01-24T16:46:00.622901+00:00 usmba.ac.ma
www.lnrbda.gov.ng NG 2025-01-24T16:43:45.129184+00:00 lnrbda.gov.ng
www.shihka.com.hk HK 2025-01-24T16:41:36.046395+00:00 shihka.com.hk

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php