Threat actor

GlorySec

GlorySec is a hacktivist group associated in open-source sources with campaigns such as #OpVenezuela and #OPTerrorismo. Its claims regarding victims are treated as statements by the actor unless independently corroborated.

Incidents
10
High impact
1
First seen
Apr 6, 2024
Latest seen
Aug 5, 2024

Linked incidents

10 incidents
Unauthorised modification of information

GlorySec Claims Responsibility for Attack on the Communist Party of Venezuela (PCV)

On August 5, 2024, GlorySec took over or defaced the Dailymotion channel Tribuna_Popular, which is associated with the Communist Party of Venezuela (PCV). Direct evidence on Dailymotion supports the unauthorized modification of the channel, not the exfiltration of internal data.

Partido Comunista de Venezuela (PCV)
Infected system

GlorySec claims to have distributed worm-type malware via USB and infected more than 100 companies in Ciudad Guayana

GlorySec claimed to have distributed a worm via USB and infected more than 100 companies in Ciudad Guayana. Trend Micro and Daily Dark Web have reported the claim, but there is no verified list of victims or independent confirmation of the scope of the attack.

Más de 100 empresas en Ciudad Guayana, Venezuela
unconfirmed actor claim

GlorySec Claims Responsibility for Attack on King Bike

King Bike appears as a lead/discovery within GlorySec’s USB malware campaign, but there is insufficient independent evidence to confirm a separate incident.

King Bike
Unauthorised modification of information

GlorySec Claims Responsibility for Attack on Tu Ticket Venezuela

GlorySec claimed responsibility for the defacement of Tu Ticket Venezuela as part of its campaign against Venezuelan websites. Sources have preserved the claim or list; there has been no confirmation from the victim, nor has any data been leaked.

Tu Ticket Venezuela
Unauthorised modification of information

GlorySec claims to have defaced more than 50 Venezuelan websites (#OpVenezuela)

GlorySec claimed to have taken down more than 50 Venezuelan websites, mainly private ones. This is considered a general campaign claim; it does not confirm that every listed site was compromised or that data was leaked.

Más de 50 sitios web venezolanos, principalmente empresas privadas
Leak of confidential information

GlorySec Claims Responsibility for Attack Against the United Socialist Party of Venezuela (PSUV)

GlorySec claimed to have gained access to the PSUV in April 2024. Research sources cite this as a case study or campaign, but there is no independent validation of the leaked data.

Partido Socialista Unido de Venezuela (PSUV)
unconfirmed actor claim

GlorySec Claims Responsibility for Attack on the Central Bank of Venezuela (BCV)

GlorySec/Residual claimed access to BCV systems in April 2024. The publicly available evidence consists primarily of social media claims and does not validate access, credentials, or data.

Banco Central de Venezuela (BCV)
Unauthorised modification of information

GlorySec Reports an Attack on Touch Celular

In April 2024, the threat actor GlorySec defaced the website of Touch Celular, a Venezuelan mobile phone retailer. The defacement was part of the #OPTerrorism campaign, as evidenced by a snapshot of the victim’s website archived on April 7, 2024, which displayed the threat actor’s name and the campaign’s hashtag. It is unclear whether any data was leaked or whether there were any financial losses resulting from the incident.

Touch Celular
Unauthorised modification of information

GlorySec Claims Responsibility for Attack on Abras CA

On April 6, 2024, the hacktivist group GlorySec defaced the website of Abras CA (abras.com.ve), a convenience store operating in Venezuela. The defacement was part of a politically motivated campaign tracked under the hashtags #OPTerrorism and #OPVenezuela. It is currently unknown whether any confidential data was compromised or whether the incident resulted in financial losses.

Abras CA
Unauthorised modification of information

GlorySec claims to have defaced the Urbavia Tu Mercado website

On April 6, 2024, an archived snapshot of the domain www.urbavia.com.ve showed tags associated with GlorySec and #OPTerrorism. The publicly available evidence allows us to treat the case as a defacement or a claim of responsibility regarding the Urbavia Tu Mercado website, but it does not confirm data exfiltration, persistence, financial impact, or prolonged downtime.

Urbavia Tu Mercado