GDLockerSec (also tracked as gd lockersec) is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 5 public victims claimed by this operator between January 24, 2025 and January 26, 2025. GDLockerSec is an emerging ransomware group first observed in January 2025, operating with apparent financial motivations based on their ransomware deployment patterns. The group's origin and affiliations remain unclear due to limited public documentation, though their targeting of victims across diverse geographic regions including the United States, Hong Kong, Egypt, Nigeria, and Morocco suggests either a broad operational scope or possible affiliate structure. With only five documented victims to date, GDLockerSec appears to focus on opportunistic targeting across multiple sectors including education, technology, and public sector entities, though their specific attack methodology, initial access vectors, and encryption techniques have not been publicly detailed by major security research organizations. No notable high-profile campaigns or significant ransoms have been publicly reported for this group, likely due to their recent emergence and limited observed activity. The group appears to remain active as of early 2025, though comprehensive threat intelligence on their operations, capabilities, and infrastructure remains limited in public security research reporting.
How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.