// THREAT ACTOR
ZEROLOCKERSEC_
DormantZEROLOCKERSEC is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of ZEROLOCKERSEC — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2025 2
Leak site mirrors
1 mirror tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
ghfuviaplse6nbeowu7ghhid5hdowutbwbrv77aqgwco2b2ntgj3auad.onion403 Forbidden snapshot · 2026-07-07 21:26
Recent victims
The 50 most recent victims claimed by ZEROLOCKERSEC. Total in the index: 2.
| Date listed | Victim | Description |
|---|---|---|
| 2025-03-25 | massar.men.gov.ma | Data Size: 910.5 MB Last View: 02-13 12:53:10 Status: Active |
| 2025-03-25 | www.dgcx.ae | Data Size: 300mb Last View: 02-21 01:45:00 Status: Active |