GhostR is a financially motivated cybercriminal group known for massive data leaks primarily targeting Thailand.
Analyst brief
GhostR is a financially motivated cybercriminal group that stole 5.3 million confidential records from World-Check and leaked approximately 186 GB of data from a stock trading platform. They target users primarily in Thailand, exfiltrating comprehensive datasets including full names, phone numbers, email addresses, and ID card numbers. Their TTPs involve data exfiltration and active leaking via Breachforums.is, though initial access tools remain unknown. Defenders should strengthen access controls on sensitive databases, monitor for unusual data egress, and alert users about potential misuse of leaked personal information.
GhostR
unknown
Ghostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the World-Check and leaking about 186GB of data from a stock trading platform. They have been active on Breachforums.is, revealing massive data breaches involving comprehensive details of Thai users, including full names, phone numbers, email addresses, and ID card numbers.
What type of data has the GhostR group stolen and what is their primary target region?+
GhostR has exfiltrated comprehensive datasets including full names, phone numbers, email addresses, and ID card numbers, with their primary target region being Thailand.
Which platform is used by the GhostR group to leak the stolen data?+
The GhostR group leaks and shares the stolen data via Breachforums.is.