Last seven days
- First activity
- Jul 15, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 50 IP / 10 hostnames
Gh0st RAT is a long-running Windows remote access trojan whose source code became publicly available in 2008, leading to extensive reuse, modification, and actor-specific forks across criminal and espionage operations.
Profile source: Mallory opens in a new tabgh0st RAT
Gh0st RAT is a long-running Windows remote access trojan whose source code became publicly available in 2008, leading to extensive reuse, modification, and actor-specific forks across criminal and espionage operations. It is widely recognized as a foundational RAT family and as a codebase from which numerous derivatives have been built. The malware is associated with sustained activity by multiple China-linked clusters and cybercrime ecosystems, including operations overlapping with Silver Fox, GoldenEyeDog, and related ValleyRAT-linked activity, although not every observed campaign using Gh0st RAT infrastructure or derivatives is conclusively attributable.
Gh0st RAT provides full remote administration capabilities on compromised systems. Documented functionality includes remote shell access, file upload and download, process execution and control, desktop interaction, system information gathering, screen capture, clipboard access, and data exfiltration. Observed variants and derivatives also support keylogging, credential theft, proxying, plugin-based extension, and delivery of additional payloads. Some samples check installation state through Windows service or registry artifacts, alter installation timestamps, and establish persistence through autorun entries, services, watchdog scripts, or scheduled-task mechanisms. Certain derivatives use reflective loading, process injection into system processes, AMSI bypass in adjacent payload chains, and DLL sideloading to evade detection and reduce on-disk exposure.
Operationally, Gh0st RAT has appeared in diverse intrusion chains. Delivery methods documented for Gh0st RAT or its derivatives include phishing lures, fake software installers, SEO poisoning, counterfeit download sites, malicious archives, and DLL sideloading via legitimate signed executables. Campaigns have impersonated tax authorities, software vendors, and translation software providers to induce execution. In some ecosystems, Gh0st RAT is deployed as a final-stage implant after multi-stage loaders decrypt embedded payloads or retrieve encrypted components from remote infrastructure.
The malware has been used against a broad range of victims, including finance organizations in the Asia-Pacific region, technology and education entities, state-owned enterprises, and general users in countries such as India and across Asia. Some campaigns have targeted Chinese-speaking users specifically, while others used multilingual social engineering. Because the codebase is public and heavily modified, the name Gh0st RAT may refer either to the original family or to a broad set of derivatives that retain core remote-access behavior while differing in protocol, packaging, and auxiliary modules.
C2 tracking
Derp observations, rolling seven-day window
Samples
27dc2e511f4da03bc10b975156996133c8654defc24d40b829ff7d955be4e2ce 2e74827318235a497133219963a2205cd8d7779a195ec67d740d825599210932 5594d4a2153e25d5de0de21bc958e1d11a341679ea2fec2123567fa3547c7847 7ef34bf0c59089432586e8847b5a8d7439a28ed3aca3254fab49ef13723be65e c4617e465670873ca7de2d8898e8c349d8189b86561fc5b8996c4d8bab251801 0ef3ac2aa51586d974a0ee4028cde8902b845a100162542a564cb4e4c2af4616 c5459e3e34938add7d2bbe7e74a65ba567cef8d786cf5050fcf06b80d1f015c8 2394ab2e1f76565af0ba93ce839308e30a3cc9c052f58812877216599ae75415 2aca878672eb7220c094a4348ec25b13b90decf299e75926caa800c385245afd 7e27c52e1f198e9d2e307be1588b6ab5c0352aa916ee259ed670ffd2b4e8d561 Reported operators
These distributors operate across Asia, employing fake software installers and leveraging variants of Gh0st RAT and WinOS (ValleyRAT) trojans.
DCRAT → VenomRAT, EchoRAT, Gh0stRAT, BitRAT, CyberSpike, Dumpling RAT, DarkRAT (via ShaShenRAT)
While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.
While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.
While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.
"As part of the second stage, the group deploys customized Gh0st RAT and Poison Ivy malware payloads designed to evade detection on its victims' systems."
Elastic Security Labs identified a recent campaign distributing a modified variant of the gh0st RAT, attributed to the Dragon Breath APT (APT-Q-27)... The final payload has not undergone major changes since Sophos’s discovery of a DragonBreath campaign in 2023... It is still a modified version of the open-source gh0st RAT.
Elastic Security Labs identified a recent campaign distributing a modified variant of the gh0st RAT, attributed to the Dragon Breath APT (APT-Q-27)... The final payload has not undergone major changes since Sophos’s discovery of a DragonBreath campaign in 2023... It is still a modified version of the open-source gh0st RAT.
Starting in 2023, the hackers moved to stealthier tools like the abuse of msbuild.exe to load C# payloads from remote SMB shares, as well as variants of the Gh0stRAT malware.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
In this case, however, it contains the source code of the infamous gh0st RAT.
In this case, however, it contains the source code of the infamous gh0st RAT.
The fake FBI domain is one of the group’s favourites... five of which are observed to be used as the C2 server for malware such as KEYPLUG, SOGU, Cobalt Strike BEACON, GRAYRABBIT and Gh0st.
Attacks mounted by the group have leveraged remote access trojans (RATs) like Trochilus RAT, Gh0st RAT, and 9002 RAT.
the group had deployed publicly available malware including gh0st RAT, QUASARRAT, and AMADEY
Malware used include: Aryan, Gh0st RAT, Rifdoor, Phandoor, and Andarat.
The code and functions are similar to the malware Gh0stRAT, which is also used by BlackTech.
Appendix A lists "Gh0st RAT" under Malware.
APT40 has used a combination of tool frameworks and malware to establish persistence, escalate privileges, map, and move laterally on victim networks. ... Gh0stRAT
Tools: Sysupdate, China Chopper, OwaAuth, ZxShell, Gh0st RAT, PoisonIvy, Hunter, PlugX, Enfal, HttpBrowser, 9002, ASPXSpy, HyperBro
Exploited software
MITRE ATT&CK
Reporting
Golden Gh0st RAT’s main feature is remote access, and is a modified version of the Gh0st RAT. Gh0st RAT source code was originally published in 2008 and has been used in cyber attacks ever since.
These distributors operate across Asia, employing fake software installers and leveraging variants of Gh0st RAT and WinOS (ValleyRAT) trojans.
The two final implants are a Gh0st RAT derivative with screen capture abilities connecting over port 6666, and a Quasar or AsyncRAT family .NET implant that patches the Antimalware Scan Interface before loading, connecting over port 6351.
The two final implants are a Gh0st RAT derivative with screen capture abilities connecting over port 6666, and a Quasar or AsyncRAT family .NET implant that patches the Antimalware Scan Interface before loading, connecting over port 6351.
The first is a Gh0st RAT derivative connecting to kkxqbh[.]top on port 6666. It includes screen capture with a self-contained JPEG encoding pipeline, a reverse shell, file operations, and desktop interaction.
DCRAT → VenomRAT, EchoRAT, Gh0stRAT, BitRAT, CyberSpike, Dumpling RAT, DarkRAT (via ShaShenRAT)
Gh0stRAT is a long-lived remote access trojan (RAT) whose source code has been publicly available for years, which has made it a convenient base for modified RAT families and actor-specific forks.
202.61.160[.]201 had previously been observed as command-and-control infrastructure associated with ValleyRAT and Gh0st RAT activity.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.