Skip to content
Malware family Windows

gh0st RAT

Gh0st RAT is a long-running Windows remote access trojan whose source code became publicly available in 2008, leading to extensive reuse, modification, and actor-specific forks across criminal and espionage operations.

Profile source: Mallory opens in a new tab

gh0st RAT

Family profile

Gh0st RAT is a long-running Windows remote access trojan whose source code became publicly available in 2008, leading to extensive reuse, modification, and actor-specific forks across criminal and espionage operations. It is widely recognized as a foundational RAT family and as a codebase from which numerous derivatives have been built. The malware is associated with sustained activity by multiple China-linked clusters and cybercrime ecosystems, including operations overlapping with Silver Fox, GoldenEyeDog, and related ValleyRAT-linked activity, although not every observed campaign using Gh0st RAT infrastructure or derivatives is conclusively attributable.

Gh0st RAT provides full remote administration capabilities on compromised systems. Documented functionality includes remote shell access, file upload and download, process execution and control, desktop interaction, system information gathering, screen capture, clipboard access, and data exfiltration. Observed variants and derivatives also support keylogging, credential theft, proxying, plugin-based extension, and delivery of additional payloads. Some samples check installation state through Windows service or registry artifacts, alter installation timestamps, and establish persistence through autorun entries, services, watchdog scripts, or scheduled-task mechanisms. Certain derivatives use reflective loading, process injection into system processes, AMSI bypass in adjacent payload chains, and DLL sideloading to evade detection and reduce on-disk exposure.

Operationally, Gh0st RAT has appeared in diverse intrusion chains. Delivery methods documented for Gh0st RAT or its derivatives include phishing lures, fake software installers, SEO poisoning, counterfeit download sites, malicious archives, and DLL sideloading via legitimate signed executables. Campaigns have impersonated tax authorities, software vendors, and translation software providers to induce execution. In some ecosystems, Gh0st RAT is deployed as a final-stage implant after multi-stage loaders decrypt embedded payloads or retrieve encrypted components from remote infrastructure.

The malware has been used against a broad range of victims, including finance organizations in the Asia-Pacific region, technology and education entities, state-owned enterprises, and general users in countries such as India and across Asia. Some campaigns have targeted Chinese-speaking users specifically, while others used multilingual social engineering. Because the codebase is public and heavily modified, the name Gh0st RAT may refer either to the original family or to a broad set of derivatives that retain core remote-access behavior while differing in protocol, packaging, and auxiliary modules.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 15, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
50 IP / 10 hostnames

Leading locations

  • US18
  • HK13
  • DE10
  • LU5
  • NL3
  • GB2
  • CH1
  • CN1
  • ES1
  • IE1
  • SG1
  • TR1

Leading providers

  • Krypt Technologies6
  • CTG Server Limited5
  • Ghosty Networks LLC5
  • FEMO IT SOLUTIONS LIMITED4
  • Cloudflare, Inc.3
  • DigitalOcean, LLC3

Infrastructure traits

  • Hosting 55
  • Anycast 3
  • Vpn 2
  • Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

21 named in public reporting
Silver Fox

These distributors operate across Asia, employing fake software installers and leveraging variants of Gh0st RAT and WinOS (ValleyRAT) trojans.

qwqdanchun

DCRAT → VenomRAT, EchoRAT, Gh0stRAT, BitRAT, CyberSpike, Dumpling RAT, DarkRAT (via ShaShenRAT)

GhostNet

While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.

Webworm

While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.

Space Pirates

While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.

GALLIUM

"As part of the second stage, the group deploys customized Gh0st RAT and Poison Ivy malware payloads designed to evade detection on its victims' systems."

DragonBreath

Elastic Security Labs identified a recent campaign distributing a modified variant of the gh0st RAT, attributed to the Dragon Breath APT (APT-Q-27)... The final payload has not undergone major changes since Sophos’s discovery of a DragonBreath campaign in 2023... It is still a modified version of the open-source gh0st RAT.

APT-Q-27

Elastic Security Labs identified a recent campaign distributing a modified variant of the gh0st RAT, attributed to the Dragon Breath APT (APT-Q-27)... The final payload has not undergone major changes since Sophos’s discovery of a DragonBreath campaign in 2023... It is still a modified version of the open-source gh0st RAT.

Unfading Sea Haze

Starting in 2023, the hackers moved to stealthier tools like the abuse of msbuild.exe to load C# payloads from remote SMB shares, as well as variants of the Gh0stRAT malware.

APT41

The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.

Axiom

The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.

UNC3569

The fake FBI domain is one of the group’s favourites... five of which are observed to be used as the C2 server for malware such as KEYPLUG, SOGU, Cobalt Strike BEACON, GRAYRABBIT and Gh0st.

SixLittleMonkeys

Attacks mounted by the group have leveraged remote access trojans (RATs) like Trochilus RAT, Gh0st RAT, and 9002 RAT.

Kimsuky

the group had deployed publicly available malware including gh0st RAT, QUASARRAT, and AMADEY

Andariel

Malware used include: Aryan, Gh0st RAT, Rifdoor, Phandoor, and Andarat.

BlackTech

The code and functions are similar to the malware Gh0stRAT, which is also used by BlackTech.

Leviathan

APT40 has used a combination of tool frameworks and malware to establish persistence, escalate privileges, map, and move laterally on victim networks. ... Gh0stRAT

Threat Group-3390

Tools: Sysupdate, China Chopper, OwaAuth, ZxShell, Gh0st RAT, PoisonIvy, Hunter, PlugX, Enfal, HttpBrowser, 9002, ASPXSpy, HyperBro

Exploited software

Vulnerabilities linked to gh0st RAT

3 CVEs

MITRE ATT&CK

gh0st RAT in ATT&CK

98 distinct techniques

Techniques

98 techniques
T1566 Phishing T1036 Masquerading T1204 User Execution T1548.002 Bypass User Account Control T1071 Application Layer Protocol T1113 Screen Capture T1574.001 DLL T1620 Reflective Code Loading T1055 Process Injection T1219 Remote Access Tools T1566.002 Spearphishing Link T1189 Drive-by Compromise T1027.003 Steganography T1543.003 Windows Service T1082 System Information Discovery T1112 Modify Registry T1547.001 Registry Run Keys / Startup Folder T1012 Query Registry T1588.001 Malware T1587.001 Malware T1583.003 Virtual Private Server T1140 Deobfuscate/Decode Files or Information T1204.002 Malicious File T1106 Native API T1059.003 Windows Command Shell T1095 Non-Application Layer Protocol T1036.005 Match Legitimate Resource Name or Location T1070.004 File Deletion T1041 Exfiltration Over C2 Channel T1053.005 Scheduled Task T1027.009 Embedded Payloads T1033 System Owner/User Discovery T1001 Data Obfuscation T1027 Obfuscated Files or Information T1083 File and Directory Discovery T1593.002 Search Engines T1134.002 Create Process with Token T1057 Process Discovery T1027.007 Dynamic API Resolution T1564.001 Hidden Files and Directories T1071.001 Web Protocols T1055.002 Portable Executable Injection T1053 Scheduled Task/Job T1218.011 Rundll32 T1497 Virtualization/Sandbox Evasion T1105 Ingress Tool Transfer T1566.001 Spearphishing Attachment T1059 Command and Scripting Interpreter T1205 Traffic Signaling T1573.001 Symmetric Cryptography T1070.001 Clear Windows Event Logs T1115 Clipboard Data T1056.001 Keylogging T1021 Remote Services T1568.002 Domain Generation Algorithms T1001.001 Junk Data T1132 Data Encoding T1018 Remote System Discovery T1071.004 DNS T1678 Delay Execution T1134 Access Token Manipulation T1102.001 Dead Drop Resolver T1016 System Network Configuration Discovery T1562.001 Disable or Modify Tools T1059.001 PowerShell T1104 Multi-Stage Channels T1129 Shared Modules T1562.004 Disable or Modify System Firewall T1202 Indirect Command Execution T1564.003 Hidden Window T1539 Steal Web Session Cookie T1027.002 Software Packing T1497.001 System Checks T1070 Indicator Removal T1622 Debugger Evasion T1497.003 Time Based Checks T1195 Supply Chain Compromise T1562 Impair Defenses T1014 Rootkit T1570 Lateral Tool Transfer T1125 Video Capture T1490 Inhibit System Recovery T1027.013 Encrypted/Encoded File T1123 Audio Capture T1529 System Shutdown/Reboot T1568 Dynamic Resolution T1218 System Binary Proxy Execution T1553.002 Code Signing T1021.001 Remote Desktop Protocol T1555 Credentials from Password Stores T1569.002 Service Execution T1203 Exploitation for Client Execution T1573 Encrypted Channel T1090.002 External Proxy T1574 Hijack Execution Flow T1568.001 Fast Flux DNS T1132.001 Standard Encoding T1505.003 Web Shell

Reporting

Research mentioning gh0st RAT

Jul 15
Expel

Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident | Expel

Golden Gh0st RAT’s main feature is remote access, and is a modified version of the Gh0st RAT. Gh0st RAT source code was originally published in 2008 and has been used in cyber attacks ever since.

Jul 10
Scworld

Silver Fox group uses new Rust-based MODBEACON RAT | brief | SC Media

These distributors operate across Asia, employing fake software installers and leveraging variants of Gh0st RAT and WinOS (ValleyRAT) trojans.

Jul 8
Cyber Security News

Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain

The two final implants are a Gh0st RAT derivative with screen capture abilities connecting over port 6666, and a Quasar or AsyncRAT family .NET implant that patches the Antimalware Scan Interface before loading, connecting over port 6351.

Jul 8
Cryptika

Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain | Cryptika Cybersecurity

The two final implants are a Gh0st RAT derivative with screen capture abilities connecting over port 6666, and a Quasar or AsyncRAT family .NET implant that patches the Antimalware Scan Interface before loading, connecting over port 6351.

Jul 7
Cyderes

Tax Trap: Fake Indian ITR Notice to Dual RAT Deployment in Six Stages

The first is a Gh0st RAT derivative connecting to kkxqbh[.]top on port 6666. It includes screen capture with a self-contained JPEG encoding pipeline, a reverse shell, file operations, and desktop interaction.

Jun 30
Cyberveille

AsyncRAT Family : cartographie de 40 variants RAT et leur infrastructure C2 active | CyberVeille

DCRAT → VenomRAT, EchoRAT, Gh0stRAT, BitRAT, CyberSpike, Dumpling RAT, DarkRAT (via ShaShenRAT)

Jun 25
Talosintelligence Other

Introduction to COM usage by Windows threats

Gh0stRAT is a long-lived remote access trojan (RAT) whose source code has been publicly available for years, which has made it a convenient base for modified RAT families and actor-specific forks.

Jun 25
Netresec

Ping32 RMM and ValleyRAT

202.61.160[.]201 had previously been observed as command-and-control infrastructure associated with ValleyRAT and Gh0st RAT activity.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.