Quick Summary
AllegedExecutive Summary
GUSTO College GLMS, an educational institution located in Thailand, was identified on the DYSPHOR1A ransomware group’s dark web portal on August 20, 2026, as reported by SOCRadar’s Dark Web Monitoring service. The college operates a global learning management system (GLMS) that supports international education programs within Thailand’s higher education sector. This listing is part of a broader pattern of DYSPHOR1A activity in August 2026, which has seen a concentrated focus on educational and public sector institutions in Southeast Asia. The nature of its operations and its position within the educational landscape likely made it an attractive target for ransomware actors seeking to disrupt services or extort funds. During the 60 days preceding this listing, DYSPHOR1A claimed six other victims. The group has predominantly targeted the Education, Professional Services, and Government & Defense sectors, with a significant concentration of victims in Myanmar, Thailand, and Indonesia. GUSTO College GLMS’s profile aligns with DYSPHOR1A’s recent targeting of educational entities in Southeast Asia, with similar recent victims including Strategy First International College, The University of Delhi, AYUDHYA TH Insurance, and Job Net .COM.MM. This incident is consistent with the group’s established preference for regional educational targets.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed a credential exposure linked to the gusto-education.com domain. Specifically, 25 records were found associated with the Moodle learning management system subdomain, moodle.gusto-education.com. The usernames predominantly consisted of consumer Gmail addresses, suggesting that these credentials likely belong to students or external users accessing the institution’s LMS rather than internal staff. The most recent entries were dated August 19, 2026, indicating that credential harvesting was actively occurring just before the ransomware group’s listing. While this exposure is notable for its recency, the nature of the credentials primarily points to risks associated with student portal access rather than a direct intrusion into administrative systems. For threat actors like DYSPHOR1A, credentials harvested through infostealers offer a potential pathway for initial access. The observed LMS credential exposure, while potentially related to student accounts, warrants attention because the line between student and staff access can be blurred on educational platforms. The recency of these harvested credentials is a significant indicator. Consequently, threat intelligence teams advising educational institutions in Southeast Asia should consider a review of their LMS security protocols and the implementation of stricter segregation for staff accounts as part of their incident response and preparedness strategies. Continued monitoring of dark web and stealer-log data, alongside proactive checks on password hygiene and multi-factor authentication, are recommended actions.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.