News Room
16
Share
Global Secret Group Ransomware Syndicate Leverages LockBit Black Derivatives to Target Energy Sector
criticalThreat Intelligence

Global Secret Group Ransomware Syndicate Leverages LockBit Black Derivatives to Target Energy Sector

A new ransomware syndicate, Global Secret Group (GSG), has emerged using modified LockBit Black code to target critical infrastructure. The group has recently claimed over 100,000 victims, focusing on energy and utility sectors.

18 August 2026Last updated 20 August 20264 min readBitdefender Labs
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2026-58231, CVE-2026-13739
Source:
Bitdefender Labs
Read Time:
4 min

Executive Summary

The cybersecurity landscape in mid-August 2026 has been marked by the aggressive expansion of the Global Secret Group (GSG), a ransomware syndicate utilizing sophisticated derivatives of the LockBit Black (LockBit 3.0) source code. Unlike typical copycat actors, GSG has demonstrated advanced operational capabilities, recently updating its data leak site to include over 100,000 victim records. Concurrently, the discovery of critical vulnerabilities in SAP Commerce Cloud (CVE-2026-58231) and Commvault Command Center (CVE-2026-13739) has provided new vectors for initial access that these groups are actively scanning for as of August 16, 2026.

Threat Analysis

GSG distinguishes itself through its strategic focus on the energy and utilities sectors, a shift from the broader targeting seen by other LockBit-based groups. By repurposing the leaked LockBit Black builder, the group maintains a high level of encryption efficiency while avoiding the infrastructure overhead of developing a proprietary locker from scratch. Their recent activity suggests a shift toward 'encryptionless extortion' in some cases, where data exfiltration is the primary leverage, though the LockBit-based payload remains their signature tool for operational disruption. The group's ability to manage massive datasets—surpassing 100,000 records—indicates a highly organized backend infrastructure capable of sustained extortion campaigns.

Technical Details

The group's technical workflow involves the exploitation of edge-facing vulnerabilities for initial access. Intelligence suggests GSG is currently prioritizing the exploitation of CVE-2026-58231, an improper authorization flaw in the SAP Commerce Cloud Data Hub Adapter that allows for remote code execution (RCE). Once inside, they utilize Living-off-the-Cloud (LOTC) tactics, specifically leveraging RClone for data exfiltration to cloud storage providers. The ransomware payload itself is a modified version of the LockBit 3.0 locker, often delivered via PowerShell scripts that disable local security agents before execution. Furthermore, recent reports indicate these actors are experimenting with 'Safe Mode' reboot tactics to bypass Endpoint Detection and Response (EDR) solutions, a technique also observed in recent Akira ransomware campaigns.

Attribution Assessment

While GSG utilizes leaked code, their organizational structure and victim volume suggest they are a professionalized syndicate rather than a transient threat actor. There are moderate-confidence indicators linking some of their infrastructure to former affiliates of the original LockBit and Qilin operations, suggesting a migration of talent following recent law enforcement disruptions of those groups. The group's operational tempo and focus on high-value critical infrastructure targets align with the profiles of established cybercriminal syndicates operating out of Eastern Europe.

Implications

The targeting of the energy sector poses a significant risk to national security and public safety. The combination of RCE-capable vulnerabilities in enterprise software like SAP and the high-speed encryption of LockBit-derived malware creates a narrow window for detection and response. If GSG continues to successfully compromise utility providers, the potential for cascading operational failures in regional power grids becomes a realistic threat.

Recommendations

Organizations should immediately prioritize patching SAP Commerce Cloud (CVE-2026-58231) and Commvault Command Center (CVE-2026-13739) instances. Implementing strict egress filtering to block unauthorized RClone traffic and enforcing phishing-resistant Multi-Factor Authentication (MFA) across all administrative interfaces is critical. Furthermore, defenders should monitor for unauthorized attempts to modify boot configurations or force 'Safe Mode' reboots, which are key indicators of an impending ransomware deployment.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo