Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 111 IP / 69 hostnames
Gh0st RAT is a long-running Chinese remote access trojan whose source code leaked around 2008, leading to extensive reuse, modification, and a large ecosystem of variants.
Profile source: Mallory opens in a new tabgh0st RAT
Gh0st RAT is a long-running Chinese remote access trojan whose source code leaked around 2008, leading to extensive reuse, modification, and a large ecosystem of variants. It is widely associated with Chinese-speaking threat activity and has appeared in espionage-oriented operations, including use by groups such as BRONZE EDISON, as well as in campaigns where trojanized software and VPN-themed lures were used to distribute Gh0st RAT variants.
Gh0st RAT is a Windows malware family that provides full remote administration of an infected host. Documented capabilities include remote shell access for command execution, process enumeration, screen capture, keylogging, and file deletion. Variants have also established persistence through Registry Run keys and have modified system configuration data in the Registry. Some samples have been observed decrypting and loading a Gh0st RAT DLL directly into memory after an initial dropper executes, and some variants have used DLL side-loading to launch malicious components through legitimate executables.
For command and control, Gh0st RAT has used encrypted and compressed network communications, including RC4 and XOR for traffic protection and zlib compression prior to encryption. This combination of remote control, surveillance, persistence, and defense-evasion tradecraft has made Gh0st RAT and its descendants a durable component of multiple intrusion sets for more than a decade.
C2 tracking
Derp observations, rolling seven-day window
Samples
1ab38c4f49f7fbfefe9665466e276c5b6181f201ca54f74666030e38b9954a18 1cd56e19b8a4e21a6ea73949631ef80e8ba460d5ad527589e2c58964d2710054 5e4cb29836187e495329e0374acba583cefb50a9342b82ea86012d87b3ac9881 a87312122ffb2232249ac5cecf2418068c6d3bd7f33abd0b8dfce2d456e8e1af f9f09fbf412e4b4465dc900e7b28c14fc052c46aed1abcf6b0889ccc9ec765b7 329aa4b71b39b71b38c2b5140af2f7436242f1c1eddd80a419325e2bf7ee5665 3925905e8613a48f328a8f32854bc876498102690eff0d47cea9b50f97e43d2d 427727be19870488d1c57821e05448c09f72354cc271f4a91479301d7bfad865 8a7bf4eb7ab96502825949707b5dfcd761b4036e9539b655a5daeb6e24e61805 957158c4fb4ee442da50e7aa5899b6f663f85b793bdbd5fcfef5cedd079bfec1 Reported operators
BRONZE EDISON ... Tools ... Gh0st RAT, Wkysol, ZxPortMap
Among the hosted files in the HFS server we can also find a PE executable labeled as BX.exe, which is a Gh0st RAT variant.
It is primarily targeted at North Korean-related organizations and is believed to be aimed at stealing information using AttackBot, PIZ Stealer, and Gh0st RAT.
Among the hosted files in the HFS server we can also find a PE executable labeled as BX.exe, which is a Gh0st RAT variant.
Gh0st is an open-source RAT that has been observed being used maliciously by cybercriminals and APT actors such as 'TA459' and 'APT18.'
A Gh0st remote access Trojan/tool (RAT) was delivered via PowerRatankba.B to several devices running common cryptocurrency-related applications.
Gh0st is an open-source RAT that has been observed being used maliciously by cybercriminals and APT actors such as 'TA459' and 'APT18.'
A sample using the Gh0st RAT malware was detected by one of the crowdsourced rules: GhostDragon_Gh0stRAT. The malware is a backdoor written in C++ that communicates via a custom binary protocol over TCP or UDP, as reported by Mandiant.
通过我们对于案例4中update.exe的分析,得到该样本所使用的互斥量为“chinaheikee__inderjns”,该互斥量与我们分析过的gh0st样本的互斥量一致,是默认配置,而且上线数据包与gh0st 3.75版本非常一致,因此我们可以判定该update.exe为gh0st后门。
木马后续将会解密 TXT 释放一个修改版 Gh0st 木马,C2 为 154.19.167.161:15628;经分析为银狐家族木马,最终释放了 Gh0st 实现远程控制。
木马后续将会解密 TXT 释放一个修改版 Gh0st 木马,C2 为 154.19.167.161:15628;经分析为银狐家族木马,最终释放了 Gh0st 实现远程控制。
Both vulnerabilities were used as part of a campaign aimed at Chinese government agencies and attributed to the DarkHotel APT. This campaign delivered the Gh0st RAT malware onto compromised devices.
The sample also installs Gh0st RAT, which communicates with the domain rat[.]kingminer[.]club.
The trojanized loader resolves its APIs dynamically through PEB walking, decrypts an embedded Gh0st RAT configuration, and downloads a second-stage shellcode payload over raw TCP.
gh0st RAT Remote access tool (RAT) used by China-nexus cyberespionage groups.
DCRAT → VenomRAT, EchoRAT, Gh0stRAT, BitRAT, CyberSpike, Dumpling RAT, DarkRAT (via ShaShenRAT)
While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.
While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.
While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.
"As part of the second stage, the group deploys customized Gh0st RAT and Poison Ivy malware payloads designed to evade detection on its victims' systems."
Elastic Security Labs identified a recent campaign distributing a modified variant of the gh0st RAT, attributed to the Dragon Breath APT (APT-Q-27)... The final payload has not undergone major changes since Sophos’s discovery of a DragonBreath campaign in 2023... It is still a modified version of the open-source gh0st RAT.
Starting in 2023, the hackers moved to stealthier tools like the abuse of msbuild.exe to load C# payloads from remote SMB shares, as well as variants of the Gh0stRAT malware.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
In this case, however, it contains the source code of the infamous gh0st RAT.
In this case, however, it contains the source code of the infamous gh0st RAT.
The fake FBI domain is one of the group’s favourites... five of which are observed to be used as the C2 server for malware such as KEYPLUG, SOGU, Cobalt Strike BEACON, GRAYRABBIT and Gh0st.
Attacks mounted by the group have leveraged remote access trojans (RATs) like Trochilus RAT, Gh0st RAT, and 9002 RAT.
Malware used include: Aryan, Gh0st RAT, Rifdoor, Phandoor, and Andarat.
The code and functions are similar to the malware Gh0stRAT, which is also used by BlackTech.
Appendix A lists "Gh0st RAT" under Malware.
APT40 has used a combination of tool frameworks and malware to establish persistence, escalate privileges, map, and move laterally on victim networks. ... Gh0stRAT
Exploited software
MITRE ATT&CK
Reporting
TrendAI reported that a newly identified threat actor, Void Arachne, is targeting Chinese-speaking users with trojanized Windows Installer packages masquerading as AI tools, Telegram Simplified Chinese language packs, Google Chrome, and VPN software including LetsVPN and QuickVPN. The campaign uses attacker-controlled websites, SEO poisoning, and Chinese-language Telegram channels to distribute the fake installers, exploiting demand for censorship-evasion tools and popular AI-driven applications such as nudifier, face-swapping, and voice-changing software. The MSI-based infection chain ultimately deploys the Winos 4.0 backdoor, giving the operators persistent access for command execution, surveillance, keylogging, and plugin-enabled follow-on activity. TrendAI said the malware establishes persistence through scheduled tasks and services, adds firewall rules and port forwarding, and communicates with command-and-control infrastructure associated with webcamcn[.]xyz. The activity aligns with the broader MITRE ATT&CK T1566.002 Spearphishing Link pattern in which malicious links and deceptive delivery pages are used to lure victims into downloading malware-bearing installers and follow-on payloads.
Researchers detailed multiple China-aligned intrusion sets using modular tooling to compromise targets across Windows, web, and mobile environments. ESET said TheWizards used a tool called Spellbinder to abuse IPv6 SLAAC by sending rogue ICMPv6 Router Advertisements, positioning the attackers as the default gateway for adversary-in-the-middle operations. The group then intercepted DNS requests for Chinese software vendors and redirected update traffic so legitimate applications such as Tencent QQ and previously Sogou Pinyin fetched malicious payloads instead of real updates. The resulting infection chain used a downloader DLL, an encrypted blob, and in-memory loading of the WizardNet backdoor, which patched AMSI and ETW, supported modular execution, and injected shellcode into other processes while maintaining encrypted command-and-control. Separate reporting described broader China-linked operations using flexible malware delivery and post-compromise frameworks. Trend Micro tied Earth Minotaur to the MOONSHINE Exploit Kit and the DarkNimbus Android backdoor, while TrendAI documented PeckBirdy, a JScript-based framework used since 2023 across browsers, MSHTA, WScript, Classic ASP, Node.js, and .NET ScriptControl for watering-hole attacks, credential theft, lateral movement, reverse shells, and persistent backdoor access. PeckBirdy was observed in campaigns against Chinese gambling sites, Asian government entities, and private organizations, alongside modular backdoors HOLODONUT and MKDOOR. The reporting also noted infrastructure and tooling overlaps linking some of these activities to UNC3569, Earth Baxia, and supplier UPSEC, underscoring an ecosystem of China-aligned operators reusing shared malware, hijacking infrastructure, and fake software-update lures.
Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.
Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybit’s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APT’s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.
Chinese espionage group Deep Panda was linked to an opportunistic campaign that exploited the Log4Shell vulnerability on VMware Horizon servers to compromise organizations in finance, academia, cosmetics, and travel across multiple countries. Investigators said the attackers used PowerShell after initial access to fetch a script chain that installed Milestone, a DLL backdoor derived from leaked Gh0st RAT/Netbot Attacker code, for command-and-control and data theft. Fortinet’s forensic analysis also identified a previously unknown Windows kernel rootkit named Fire Chili, deployed to hide malicious files, processes, registry keys, and network connections and signed with stolen code-signing certificates from game developers. The intrusion chain included DLL side-loading through a legitimate Synaptics-signed executable and installation of the crtsys.sys driver as a service, while attribution was supported by overlaps with Deep Panda’s historical Infoadmin RAT activity and infrastructure tied to Winnti, including the domain gnisoft[.]com.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.