GhostLocker
GhostLocker is a name used in the provided content for two distinct malicious/security-related tools.
Profile source: Mallory opens in a new tabGhostLocker
Family profile
GhostLocker is a name used in the provided content for two distinct malicious/security-related tools. First, it is described as a tool developed by security researcher zero2504 that neutralizes Endpoint Detection and Response (EDR) products by abusing the native Windows AppLocker feature. It deploys AppLocker deny rules against EDR user-mode executables in dynamic and static modes, preventing those components from running after policy application and reboot. Although it does not block EDR kernel drivers, the content states this effectively blinds commercial EDR products because telemetry can no longer be analyzed or surfaced, while management consoles may still show agents as online and protected. The technique is characterized as abuse of legitimate administrative functionality rather than an exploit, and defenders are advised to monitor AppLocker policy changes and validate security product execution status.
Second, GhostLocker is also referenced as ransomware operated by GhostSec as a ransomware-as-a-service (RaaS) offering developed in October 2023 to fund the group’s hacktivist activities. The content states GhostSec later announced it would exit ransomware and transfer GhostLocker operations to the Stormous ransomware group in May 2024. GhostSec is associated in the content with DDoS, ICS targeting, industrial sabotage, data exfiltration, extortion, and ransomware, and GhostLocker is listed alongside other GhostSec tooling such as GhostStealer and Ghostly Development malware.
Because the supplied content conflates an AppLocker-based EDR-disabling tool and a ransomware family under the same name, the exact canonical malware definition is ambiguous from the available information. High-confidence associations in the content tie GhostLocker to GhostSec and later Stormous in the ransomware context, and to Windows AppLocker abuse for disabling EDR in the separate tool context.