Skip to content

gh0st RAT

Gh0st RAT is a long-running Chinese remote access trojan whose source code leaked around 2008, leading to extensive reuse, modification, and a large ecosystem of variants.

Profile source: Mallory opens in a new tab

gh0st RAT

Family profile

Gh0st RAT is a long-running Chinese remote access trojan whose source code leaked around 2008, leading to extensive reuse, modification, and a large ecosystem of variants. It is widely associated with Chinese-speaking threat activity and has appeared in espionage-oriented operations, including use by groups such as BRONZE EDISON, as well as in campaigns where trojanized software and VPN-themed lures were used to distribute Gh0st RAT variants.

Gh0st RAT is a Windows malware family that provides full remote administration of an infected host. Documented capabilities include remote shell access for command execution, process enumeration, screen capture, keylogging, and file deletion. Variants have also established persistence through Registry Run keys and have modified system configuration data in the Registry. Some samples have been observed decrypting and loading a Gh0st RAT DLL directly into memory after an initial dropper executes, and some variants have used DLL side-loading to launch malicious components through legitimate executables.

For command and control, Gh0st RAT has used encrypted and compressed network communications, including RC4 and XOR for traffic protection and zlib compression prior to encryption. This combination of remote control, surveillance, persistence, and defense-evasion tradecraft has made Gh0st RAT and its descendants a durable component of multiple intrusion sets for more than a decade.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
111 IP / 69 hostnames

Leading locations

  • US58
  • HK41
  • CN22
  • DE11
  • IE7
  • KR5
  • NL5
  • RU3
  • SG3
  • FR2
  • IR2
  • LU2

Leading providers

  • CTG Server Limited15
  • Amazon.com, Inc.14
  • FEDERAL ONLINE GROUP LLC11
  • Amazon.com, Inc.10
  • Krypt Technologies9
  • Cloudflare, Inc.8

Infrastructure traits

  • Hosting 142
  • Anycast 8

Samples

Recent associated samples

Reported operators

Threat actors

32 named in public reporting
BRONZE EDISON

BRONZE EDISON ... Tools ... Gh0st RAT, Wkysol, ZxPortMap

Iron Tiger APT

Among the hosted files in the HFS server we can also find a PE executable labeled as BX.exe, which is a Gh0st RAT variant.

Higaisa

It is primarily targeted at North Korean-related organizations and is believed to be aimed at stealing information using AttackBot, PIZ Stealer, and Gh0st RAT.

ChinaZ

Among the hosted files in the HFS server we can also find a PE executable labeled as BX.exe, which is a Gh0st RAT variant.

TA459

Gh0st is an open-source RAT that has been observed being used maliciously by cybercriminals and APT actors such as 'TA459' and 'APT18.'

Lazarus

A Gh0st remote access Trojan/tool (RAT) was delivered via PowerRatankba.B to several devices running common cryptocurrency-related applications.

APT18

Gh0st is an open-source RAT that has been observed being used maliciously by cybercriminals and APT actors such as 'TA459' and 'APT18.'

Kimsuky

A sample using the Gh0st RAT malware was detected by one of the crowdsourced rules: GhostDragon_Gh0stRAT. The malware is a backdoor written in C++ that communicates via a custom binary protocol over TCP or UDP, as reported by Mandiant.

GreenSpot

通过我们对于案例4中update.exe的分析,得到该样本所使用的互斥量为“chinaheikee__inderjns”,该互斥量与我们分析过的gh0st样本的互斥量一致,是默认配置,而且上线数据包与gh0st 3.75版本非常一致,因此我们可以判定该update.exe为gh0st后门。

APT-Q-27

木马后续将会解密 TXT 释放一个修改版 Gh0st 木马,C2 为 154.19.167.161:15628;经分析为银狐家族木马,最终释放了 Gh0st 实现远程控制。

金眼狗

木马后续将会解密 TXT 释放一个修改版 Gh0st 木马,C2 为 154.19.167.161:15628;经分析为银狐家族木马,最终释放了 Gh0st 实现远程控制。

Darkhotel

Both vulnerabilities were used as part of a campaign aimed at Chinese government agencies and attributed to the DarkHotel APT. This campaign delivered the Gh0st RAT malware onto compromised devices.

panda

The sample also installs Gh0st RAT, which communicates with the domain rat[.]kingminer[.]club.

Silver Fox

The trojanized loader resolves its APIs dynamically through PEB walking, decrypts an embedded Gh0st RAT configuration, and downloads a second-stage shellcode payload over raw TCP.

Threat Group-3390

gh0st RAT Remote access tool (RAT) used by China-nexus cyberespionage groups.

qwqdanchun

DCRAT → VenomRAT, EchoRAT, Gh0stRAT, BitRAT, CyberSpike, Dumpling RAT, DarkRAT (via ShaShenRAT)

GhostNet

While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.

Webworm

While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.

Space Pirates

While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.

GALLIUM

"As part of the second stage, the group deploys customized Gh0st RAT and Poison Ivy malware payloads designed to evade detection on its victims' systems."

DragonBreath

Elastic Security Labs identified a recent campaign distributing a modified variant of the gh0st RAT, attributed to the Dragon Breath APT (APT-Q-27)... The final payload has not undergone major changes since Sophos’s discovery of a DragonBreath campaign in 2023... It is still a modified version of the open-source gh0st RAT.

Unfading Sea Haze

Starting in 2023, the hackers moved to stealthier tools like the abuse of msbuild.exe to load C# payloads from remote SMB shares, as well as variants of the Gh0stRAT malware.

APT41

The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.

Axiom

The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.

GoldenEyeDog

In this case, however, it contains the source code of the infamous gh0st RAT.

UNC3569

The fake FBI domain is one of the group’s favourites... five of which are observed to be used as the C2 server for malware such as KEYPLUG, SOGU, Cobalt Strike BEACON, GRAYRABBIT and Gh0st.

SixLittleMonkeys

Attacks mounted by the group have leveraged remote access trojans (RATs) like Trochilus RAT, Gh0st RAT, and 9002 RAT.

Andariel

Malware used include: Aryan, Gh0st RAT, Rifdoor, Phandoor, and Andarat.

BlackTech

The code and functions are similar to the malware Gh0stRAT, which is also used by BlackTech.

Leviathan

APT40 has used a combination of tool frameworks and malware to establish persistence, escalate privileges, map, and move laterally on victim networks. ... Gh0stRAT

Exploited software

Vulnerabilities linked to gh0st RAT

9 CVEs

MITRE ATT&CK

gh0st RAT in ATT&CK

103 distinct techniques

Techniques

103 techniques
T1566.002 Spearphishing Link T1189 Drive-by Compromise T1566.001 Spearphishing Attachment T1112 Modify Registry T1113 Screen Capture T1105 Ingress Tool Transfer T1057 Process Discovery T1082 System Information Discovery T1059 Command and Scripting Interpreter T1547.001 Registry Run Keys / Startup Folder T1218.011 Rundll32 T1573 Encrypted Channel T1056.001 Keylogging T1106 Native API T1140 Deobfuscate/Decode Files or Information T1070.004 File Deletion T1071 Application Layer Protocol T1059.003 Windows Command Shell T1055 Process Injection T1071.001 Web Protocols T1125 Video Capture T1219 Remote Access Tools T1555 Credentials from Password Stores T1059.001 PowerShell T1083 File and Directory Discovery T1123 Audio Capture T1005 Data from Local System T1095 Non-Application Layer Protocol T1620 Reflective Code Loading T1090.003 Multi-hop Proxy T1041 Exfiltration Over C2 Channel T1566 Phishing T1622 Debugger Evasion T1070.001 Clear Windows Event Logs T1027 Obfuscated Files or Information T1529 System Shutdown/Reboot T1562.001 Disable or Modify Tools T1036 Masquerading T1195 Supply Chain Compromise T1203 Exploitation for Client Execution T1543.003 Windows Service T1210 Exploitation of Remote Services T1562 Impair Defenses T1204 User Execution T1583 Acquire Infrastructure T1068 Exploitation for Privilege Escalation T1548.002 Bypass User Account Control T1574.001 DLL T1027.003 Steganography T1012 Query Registry T1588.001 Malware T1587.001 Malware T1583.003 Virtual Private Server T1204.002 Malicious File T1036.005 Match Legitimate Resource Name or Location T1053.005 Scheduled Task T1027.009 Embedded Payloads T1033 System Owner/User Discovery T1001 Data Obfuscation T1593.002 Search Engines T1134.002 Create Process with Token T1027.007 Dynamic API Resolution T1564.001 Hidden Files and Directories T1055.002 Portable Executable Injection T1053 Scheduled Task/Job T1497 Virtualization/Sandbox Evasion T1205 Traffic Signaling T1573.001 Symmetric Cryptography T1115 Clipboard Data T1021 Remote Services T1568.002 Domain Generation Algorithms T1001.001 Junk Data T1132 Data Encoding T1018 Remote System Discovery T1071.004 DNS T1678 Delay Execution T1134 Access Token Manipulation T1102.001 Dead Drop Resolver T1016 System Network Configuration Discovery T1104 Multi-Stage Channels T1129 Shared Modules T1562.004 Disable or Modify System Firewall T1202 Indirect Command Execution T1564.003 Hidden Window T1539 Steal Web Session Cookie T1027.002 Software Packing T1497.001 System Checks T1070 Indicator Removal T1497.003 Time Based Checks T1014 Rootkit T1570 Lateral Tool Transfer T1490 Inhibit System Recovery T1027.013 Encrypted/Encoded File T1568 Dynamic Resolution T1218 System Binary Proxy Execution T1553.002 Code Signing T1021.001 Remote Desktop Protocol T1569.002 Service Execution T1090.002 External Proxy T1574 Hijack Execution Flow T1568.001 Fast Flux DNS T1132.001 Standard Encoding T1505.003 Web Shell

Reporting

Research mentioning gh0st RAT

Aug 25
Trendai Security

Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework | TrendAI (US)

TrendAI reported that a newly identified threat actor, Void Arachne, is targeting Chinese-speaking users with trojanized Windows Installer packages masquerading as AI tools, Telegram Simplified Chinese language packs, Google Chrome, and VPN software including LetsVPN and QuickVPN. The campaign uses attacker-controlled websites, SEO poisoning, and Chinese-language Telegram channels to distribute the fake installers, exploiting demand for censorship-evasion tools and popular AI-driven applications such as nudifier, face-swapping, and voice-changing software. The MSI-based infection chain ultimately deploys the Winos 4.0 backdoor, giving the operators persistent access for command execution, surveillance, keylogging, and plugin-enabled follow-on activity. TrendAI said the malware establishes persistence through scheduled tasks and services, adds firewall rules and port forwarding, and communicates with command-and-control infrastructure associated with webcamcn[.]xyz. The activity aligns with the broader MITRE ATT&CK T1566.002 Spearphishing Link pattern in which malicious links and deceptive delivery pages are used to lure victims into downloading malware-bearing installers and follow-on payloads.

Aug 19
Trendai Security

PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups | TrendAI (US)

Researchers detailed multiple China-aligned intrusion sets using modular tooling to compromise targets across Windows, web, and mobile environments. ESET said TheWizards used a tool called Spellbinder to abuse IPv6 SLAAC by sending rogue ICMPv6 Router Advertisements, positioning the attackers as the default gateway for adversary-in-the-middle operations. The group then intercepted DNS requests for Chinese software vendors and redirected update traffic so legitimate applications such as Tencent QQ and previously Sogou Pinyin fetched malicious payloads instead of real updates. The resulting infection chain used a downloader DLL, an encrypted blob, and in-memory loading of the WizardNet backdoor, which patched AMSI and ETW, supported modular execution, and injected shellcode into other processes while maintaining encrypted command-and-control. Separate reporting described broader China-linked operations using flexible malware delivery and post-compromise frameworks. Trend Micro tied Earth Minotaur to the MOONSHINE Exploit Kit and the DarkNimbus Android backdoor, while TrendAI documented PeckBirdy, a JScript-based framework used since 2023 across browsers, MSHTA, WScript, Classic ASP, Node.js, and .NET ScriptControl for watering-hole attacks, credential theft, lateral movement, reverse shells, and persistent backdoor access. PeckBirdy was observed in campaigns against Chinese gambling sites, Asian government entities, and private organizations, alongside modular backdoors HOLODONUT and MKDOOR. The reporting also noted infrastructure and tooling overlaps linking some of these activities to UNC3569, Earth Baxia, and supplier UPSEC, underscoring an ecosystem of China-aligned operators reusing shared malware, hijacking infrastructure, and fake software-update lures.

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Jul 13
Malware News

Dark Web Profile: Krybit Ransomware - Malware News - Malware Analysis, News and Indicators

Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybit’s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APT’s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.

Jul 13
Socradar

Dark Web Profile: Krybit Ransomware

Jul 12
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Jul 12
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Apr 9
Cynet

Threats Looming Over the Horizon

Chinese espionage group Deep Panda was linked to an opportunistic campaign that exploited the Log4Shell vulnerability on VMware Horizon servers to compromise organizations in finance, academia, cosmetics, and travel across multiple countries. Investigators said the attackers used PowerShell after initial access to fetch a script chain that installed Milestone, a DLL backdoor derived from leaked Gh0st RAT/Netbot Attacker code, for command-and-control and data theft. Fortinet’s forensic analysis also identified a previously unknown Windows kernel rootkit named Fire Chili, deployed to hide malicious files, processes, registry keys, and network connections and signed with stolen code-signing certificates from game developers. The intrusion chain included DLL side-loading through a legitimate Synaptics-signed executable and installation of the crtsys.sys driver as a service, while attribution was supported by overlaps with Deep Panda’s historical Infoadmin RAT activity and infrastructure tied to Winnti, including the domain gnisoft[.]com.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.