Ransomware family
Global Secret Group Ransomware Decryption & Data Recovery
- Active
- High
- No public decryptor
Global Secret Group (GSG) is an emerging data-extortion crew that surfaced in late July 2026. It steals corporate documents, contracts and HR records and pressures victims through staged publication on a Tor leak site. No decryptor exists and sample-level intelligence is scarce.
- First seen
- 2026-07
- File extensions
- No public information
- Ransom notes
- No public information
- Affected platforms
- Windows
Public information on this family is limited. What follows is compiled from the small amount of verified material available, so please contact us for a sample assessment before you act on it.
Family profile
- File extensions
- No public information
- Ransom notes
- No public information
- Contact patterns
- Tor (.onion) leak site with per-victim pages; trackers record six mirror domains with persistently poor uptime
- Tox messaging ID, listed by threat-intel platforms as one contact route
- An email address published on the leak site for so-called negotiation and data-purchase enquiries
- Entries annotated with revenue, headcount and data volume, using timed free-release threats as pressure
- No phone, WeChat or QQ channels observed for direct contact with victim organisations
- Aliases / versions
- GSG、globalsecretgroup
- First seen
- 2026-07
- Status
- Active
- Operational status
- Newly emerged
- Threat level
- High
- Affected platforms
- Windows
- Tags
- Emerging
- Active
- Double extortion
No free public decryptor exists for Global Secret Group. The family does not appear in the No More Ransom catalogue, and no law enforcement agency or mainstream vendor has released a tool.
More fundamentally, no public source has produced an encryptor sample, a file extension or a ransom note filename for this group. WatchGuard classifies it as a Data Broker - an operation built on stealing, selling and exposing data. A few aggregators assert that it encrypts, but supply no sample, hash or analysis. The verifiable behaviour is data theft and public pressure; any encryption capability remains unconfirmed.
That yields a conclusion which matters operationally: if your files really do carry a rewritten extension and will not open, do not apply this playbook. The cause is most likely a separate encrypting family, or a second intrusion set in the same window, and identification has to be redone from real samples and the actual note.
Latest activity
Trackers recorded a new entry for an Indian bank (41.3 GB claimed); about ten posts landed in the previous 30 days, with activity undiminished. Its six .onion mirrors average roughly 50% uptime.
SourcesThree US victims - construction, manufacturing and auto retail - were posted to the leak site on a single day, with claimed data volumes ranging from 32.9 GB to 1.3 TB.
SourcesGSG's Tor leak site was first indexed by ransomware.live and RansomLook, launching with about 30 victim entries plus a claim of 4.2 TB stolen from Korea's Nexon - unproven, with Nexon saying it was investigating.
Sources
Overview
The Tor leak site of Global Secret Group (self-styled GSG) was first indexed by ransomware.live and RansomLook on 26 July 2026, when close to thirty entries appeared at once, many of them back-dated across January to July. By 11 September 2026 RansomLook lists 40 posts and ransomware.live 46, the most recent dated 10 September. Dating differs by source: WatchGuard marks January 2026, while intelligence aggregators date the group from the leak site going live in July 2026; ransomware.live's earliest entry is dated 17 January 2026, with isolated entries claiming attack dates as far back as mid-2025 - more likely recycled datasets than evidence of long dwell time.
Around 60% of victims are US organisations, then India, Canada and Brazil, across the 15 countries ransomware.live records - including one March 2026 entry for a Chinese electronics manufacturer (China also appears in WatchGuard's country breakdown). Sectors cluster in manufacturing, financial services and insurance, retail and wholesale, construction and real estate, with most victims small or mid-sized.
Public information is limited. No mainstream vendor has published sample-level analysis and no Chinese-language vendor report could be found; the claim against Korean game publisher Nexon made when the site launched (self-reported as 4.2 TB and nearly 25,000 files) came with no samples or directory listings, and Korean media flagged its authenticity as unverified at the time. Treat every advertised volume with the same scepticism.
How to identify it
There is no extension or note to look up. No public source has recorded a GSG file extension or ransom note filename, so the family cannot be attributed by searching a suffix.
A case typically surfaces when the company appears on the Tor leak site with revenue, headcount and a claimed volume (published entries range from tens of gigabytes to several terabytes, quoted alongside file and folder counts), after which the actors apply pressure via the email address or Tox ID published there. Operations are often undisrupted, with anomalies confined to outbound traffic and transfer-utility traces, so media or customers frequently spot the entry first.
Bottom line. Where files are intact, run the incident as a data breach; where files carry a rewritten extension and will not open, re-identify the family from real samples.
Infection vectors
No public source documents this group's intrusion methods or tooling, and no vendor has released indicators or a TTP list. What follows is not confirmed tradecraft - only where to look first, to be confirmed from logs and host forensics:
- Perimeter and credentials. VPN without MFA, internet-reachable RDP and management interfaces, unpatched edge appliances, plus credentials and Microsoft 365 sessions harvested by infostealers.
- File servers and OA/ERP systems. Over-permissive or legacy everyone-readable shares, usually the real source when hundreds of gigabytes of documents leave at once.
Encryption behavior
No encryptor sample is publicly available: there is no algorithm, encryption ratio or shadow-copy deletion command to describe, because no public source has analysed a GSG payload. WatchGuard classifies it as a Data Broker - extortion types recorded as direct extortion, double extortion and free data leaks, with its encryption-practices field left blank; a few aggregators tag the group with MITRE ATT&CK's "Data Encrypted for Impact" (T1486) yet publish no sample, hash or analysis to support it.
The verifiable behaviour is exfiltration-first: theft of office documents, contracts, financial and HR records, then staged publication as leverage. The core loss is therefore not "files will not open" but data having already left the organisational boundary.
Assess before you act
Recoverability assessment
A GSG case usually has no decryption step; what needs restoring is control over data and regulatory standing. We do not pay ransoms and do not negotiate on a client's behalf:
1) Breach impact assessment. From outbound traffic, firewall logs and transfer-utility traces, establish which directories, what volume and what window were taken; the advertised volume is leverage, not fact.
2) Data classification and legal obligations. Grade personal information, trade secrets, financial data and source code, then fix notification deadlines and recipients under China's PIPL, Data Security Law and Cybersecurity Law.
3) Credential rotation and notification. Exfiltrated documents frequently contain password lists and keys, so rotate privileged accounts and certificates once persistence is removed, and notify employees, customers and partners in tiers.
4) If encryption is also present. More than one family is on site, and only then does the conventional ladder apply - public decryptor, then database and virtual-disk repair, then backups and snapshots, then log replay, then carving.
Once data has left, no technique can ensure it is destroyed.
Our response plan
Hit by Global Secret Group ransomware? What to do
Containment and evidence preservation
Preserve evidence first. Do not rush to rebuild, clean up or power off - in an exfiltration-led incident the evidence lives in logs and memory, and reimaging one staging host can destroy the entire transfer trail.
Preserve: outbound traffic records from perimeter firewalls and proxies (including session duration and byte counts), VPN and remote access logs, file server and NAS access auditing, domain controller and identity logs, Microsoft 365 sign-in and consent auditing, plus memory and disk images of involved hosts. Most logs retain only 7-30 days, so the first action after discovery is to extend retention and export an offline copy. Retain the leak-site screenshots, original emails with full headers, and any file tree or samples supplied.
Attribution and claim verification
Confirm the counterparty really is Global Secret Group rather than an impersonator or a different family - once a crew gains visibility, extortion emails trading on its name are common. Verify by comparing the leak-site entry, the contact channels (Tox ID, email domain) and the formatting of its previous entries, and by requiring verifiable samples.
The decisive branch is whether file encryption is present. If it is, this is not a single-actor GSG case: take three to five encrypted files plus the original note, identify that family independently, and build the recovery plan around it. If there is no encryption, commit to a data-breach response and do not import an encryption-recovery workflow. In parallel, reconcile the claimed volume and file counts against your own logs.
Exfiltration scope and breach impact assessment
Define the time window, path, directory scope and volume from log evidence. Focus on high-volume outbound sessions and their destinations, archiving and splitting activity, artefacts and execution records for Rclone-style sync tools and cloud clients, bulk reads and directory enumeration on file servers, and bulk exports from mail and OA systems.
Then classify what was taken and assess business impact, regulatory exposure and the follow-on attack surface. Deliver a written conclusion that can be defended externally - what is confirmed exfiltrated, what cannot be ruled out, what can be ruled out, each with its evidence. This underpins notification, customer communication and any regulatory enquiry.
Eradication, credential rotation and notification
Remove the foothold first: new or newly privileged accounts, unexpected mailbox delegations and OAuth grants, remote management tools, scheduled tasks and services, tunnels and reverse proxies. Only once eradication is confirmed and no new outbound activity is seen should rotation begin - otherwise the new passwords go straight to an attacker still inside.
Rotation scope: domain and local privileged accounts, service accounts, VPN and remote access credentials, database and middleware passwords, API keys and certificates, third-party integration keys - with MFA enforced on every remote entry point. Run notification off the previous step's classification: fix regulatory deadlines and recipients, prepare tiered messaging for employees, customers and partners, and warn them about phishing and payment fraud using the leaked material as bait.
Root cause remediation and exfiltration-control acceptance
Identify and close the real entry point: remote access missing MFA, unpatched edge appliances and internet-facing applications, sessions and credentials exposed through infostealer logs, over-broad permissions and sharing links on cloud and collaboration platforms, hardcoded keys left in repositories or front-end code.
Harden specifically against bulk document exfiltration: tighten file server and share permissions, eliminating legacy everyone-readable directories; enable access auditing and anomalous-read alerting on core data stores; restrict and monitor cloud storage and sync utilities; establish an egress traffic baseline with alerting on large transfers; set thresholds on bulk exports from mail and OA systems.
Acceptance is measured against two questions: could the attacker re-enter by the same route, and would an exfiltration of the same size now be detected and stopped as it happens. Delivered with an incident report, a hardening checklist and a repeatable verification record.
Risk warning
What not to do
- Do not run this as an encryption incident. GSG's verifiable behaviour is data theft and exposure, and no encryptor, extension or note is publicly documented. Time spent hunting a decryptor is time lost from exfiltration forensics and notification.
- Do not rush to rebuild or clean affected hosts, and do not let logs expire. Exfiltration evidence lives in traffic records, file-server auditing and host artefacts, and most logs retain only 7-30 days - extend retention and export an offline copy immediately.
- Do not treat the attackers' stated data volumes and file lists as fact. The group's Nexon claim was questioned precisely because no proof samples were provided; scope must be reconciled from your own logs.
- Do not rotate credentials before eradication. If the attackers are still inside they simply collect the new ones; confirm removal first, then rotate comprehensively.
- Do not pay for a promise to delete data. Destruction cannot be verified once data has left, payment does not prevent later publication or resale, and it marks the organisation as one that pays.
- Do not let individuals trade emails or Tox messages with the actors on their own. Unscripted replies reveal internal assessment progress and tolerance, and can be excerpted later for further pressure or impersonation fraud.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
OA Collaboration System Encrypted by Ransomware
An encrypted OA system halts document circulation, approvals, contract archives, HR and knowledge bases at once — and because OA is so often published to the internet, it is frequently the attacker's first foothold. This page covers its vulnerability profile, the twin-track recovery of attachments and database, and how to check for lateral spread.
ERP System Encrypted by Ransomware
An encrypted ERP is not a single broken database: the application tier, database, attachments and interfaces fail together, halting finance, procurement, production and inventory. This page covers the vulnerability entry points seen in Chinese ERP deployments, the order in which the four tiers are recovered, and how account sets are reconciled at sign-off.
Related industries
Manufacturing Ransomware Response and Recovery
Ransomware in manufacturing hits information systems and production cadence at the same time: with ERP down there are no orders, with MES down there is no schedule, and an encrypted drawing library takes the process documentation for an entire product line with it. This page covers the asset profile, recovery priorities and targeted defences.
Financial Services Ransomware Response and Recovery
Financial and quasi-financial institutions face far stricter requirements on data integrity, transaction continuity and regulatory reporting than most sectors, so one ransomware event hits availability, customer trust and compliance simultaneously. This page covers the threat profile, a recovery approach centred on transactional consistency, and hardening priorities.
Construction and Real Estate Ransomware Response
In construction and real estate the core assets are drawings, models and project documentation — typically scattered across project-site NAS units, shared drives and personal computers with no unified backup. This page covers the sector's threat profile, recovery of drawings and BIM models, and defences for dispersed, multi-project environments.
Similar families
- No public decryptor
FulcrumSec
FulcrumSec is a data-theft extortion crew that surfaced in September 2025. It deploys no encryptor, changes no extensions and causes no outage - it harvests leaked API keys and cloud misconfigurations, then squeezes victims through staged publication on its leak site.
- No public decryptor
World Leaks
World Leaks is the extortion-only brand Hunters International adopted in January 2025: no encryptor, no renamed files, just data theft backed by a Tor leak site. No new victims have been posted since late July 2026 and the leak site has been unreachable, so the operation currently looks dormant.
- No public decryptor
Silent Ransom Group
Silent Ransom Group (Luna Moth, Chatty Spider, UNC3753) is a Conti-lineage crew that extorts without encrypting anything. Operators impersonate an internal IT helpdesk by phone, walk staff into a remote-access session, take documents out, then press with a clearnet leak site and calls to employees. The FBI flagged in-person intrusions with USB storage in both May 2025 and May 2026.
FAQ
Global Secret Group Frequently asked questions
Global Secret Group listed us on its leak site, but all our files still open. Is this even ransomware?
It is an extortion incident, just not an encryption one. GSG's verifiable model is stealing data and staging its publication on a Tor leak site for leverage; WatchGuard classifies it as a Data Broker, and no public source documents an encryptor, extension or note.
Files opening normally does not mean the loss is small. The data has left your boundary, and the exposure is personal information and trade secrets being published, statutory notification duties, damaged customer trust, and follow-on phishing or payment fraud using the leaked material. Effort belongs on scoping the exfiltration, determining legal obligations and rotating credentials - not on finding a decryptor. If files are also encrypted, more than one intrusion set is present and that has to be identified separately.
Is there a Global Secret Group decryptor? Do the ones advertised online work?
No. The family is absent from the No More Ransom catalogue, and neither law enforcement nor mainstream vendors have released anything. More fundamentally, no public source has analysed a GSG payload, and it is not established that the group deploys an encryptor at all - WatchGuard classifies it as a data-theft-focused Data Broker.
Any service advertising "Global Secret Group decryption" is therefore either built on a misunderstanding of the group or is misattributing files encrypted by a different family. If your files really do carry a rewritten extension and will not open, take three to five encrypted files plus the original note, re-identify the family, and only then assess recovery routes. Never trial an unverified tool against original disks - a build mismatch causes further damage.
GSG claims it took hundreds of gigabytes from us. Should we believe that?
Verify independently rather than taking it at face value. Emerging crews routinely overstate results and name-drop well-known companies - when GSG's site launched, its claim against the Korean game publisher Nexon came with no proof samples and was questioned by media and researchers. Trackers record its entries framing leverage as gigabytes or terabytes plus file and folder counts, and those numbers are themselves a negotiating instrument.
Reconcile against your own evidence: outbound traffic records including session duration and byte counts, proxy and firewall logs, file server and NAS access auditing, and execution traces for cloud and transfer utilities. Compare any file tree and samples they provide against your real directory structure. Aim for a three-part conclusion - confirmed exfiltrated, cannot be ruled out, ruled out - each with supporting evidence, for internal decisions and any regulatory enquiry.
What matters most in the first 48 hours after GSG names us?
Four things, in this order:
1. Preserve evidence. Immediately extend log retention on firewalls, proxies, VPN, file-server auditing and identity systems, and export offline copies. Most environments keep only 7-30 days, and once logs roll over the scope can never be established. Save the leak-site screenshots and every original email in full.
2. Determine whether the attackers are still inside. Check for anomalous accounts, mailbox delegations and OAuth grants, remote management tools, scheduled tasks and tunnels. If they are still present, eradicate before rotating credentials.
3. Start reconciling the exfiltration scope. Establish the time window, path, directories and volume from logs, not from the attackers' claims.
4. Fix a single external line. Appoint one point of contact, with legal and compliance engaged on notification duties.
Everything else - rebuilding systems, cleaning "the virus", broadcasting internally - comes after these four.
Will paying make Global Secret Group delete our data?
It cannot be verified, so it cannot be the basis for a decision. Once data leaves your boundary, no one can prove the copies were destroyed - the actors can retain them, resell them, or return months later with "newly discovered" old data. International law enforcement and security agencies are consistent: payment does not remove breach risk, and it marks the organisation as one that pays.
Our position is explicit: we do not pay ransoms and do not negotiate on a client's behalf. What we can do is reduce the uncertainty to something manageable - establish the true exfiltration scope from your own logs, determine notification duties from data classification, complete credential and key rotation, deliver tiered notification, and keep monitoring leak sites and lookalike domains. That produces verifiable conclusions and a defensible record of response; payment produces an unverifiable verbal promise.
Sources
- WatchGuard Ransomware Tracker – Global Secret Group
- RansomLook – Global Secret Group group profile
- Ransomware.live – Global Secret Group
- Mallory.ai – Global Secret Group threat actor profile (T1486 tag, no sample published)
- TheElec – Nexon investigating Global Secret Group's unverified breach claim
- No More Ransom – Decryption Tools (no entry for this family)
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated