Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 3, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 2 hostnames
Ghost is an overloaded malware name used in multiple distinct contexts, including a ransomware variant, a ransomware group branding, and a separate npm-based malware campaign.
Profile source: Mallory opens in a new tabGhost
Ghost is an overloaded malware name used in multiple distinct contexts, including a ransomware variant, a ransomware group branding, and a separate npm-based malware campaign. High-confidence reporting ties the name to ransomware activity affecting a California water and wastewater facility in 2021, where a Ghost ransomware variant encrypted systems including SCADA-related servers. More recent reporting also uses Ghost or GhostLocker for a ransomware operation associated with GhostSec that evolved from hacktivist roots into ransomware and double-extortion activity, including rapid exploitation of newly disclosed vulnerabilities in unpatched internet-facing systems and exfiltration prior to extortion. Separately, the name Ghost has been applied to a 2026 malicious npm supply-chain campaign targeting developers with trojanized packages masquerading as useful tools. In that campaign, deceptive installation output and social engineering were used to obtain sudo credentials and deploy a remote access trojan that searched for cryptocurrency wallets and sensitive personal data, with some variants supporting broader data theft. Because these references describe materially different malware or operations sharing the same name, Ghost should be treated as an ambiguous designation rather than a single well-defined malware family.
Samples
187ded3f9fbdbdfbb2bbb0d9f34d2407568a7d2f464417906456ad72f3666d09 a4836c6b904aacccbc39ca333620b53eb91659efda314ca20adc3c87041c1e7f 3058b74c25d7abd4af3e1670265b8605582821138263675f049514055c59c9b3 45b07b365357fe490d7f8bd6793c79fa5ecb77f1fb991ac39ce5d629ba34fce5 aeb7bfee4fe86e10c4888f2de2ed627eb9dc0c854693fda5d7d08339b1028bb5 Reported operators
APT27 (aka Lucky Mouse, Emissary Panda, Iron Tiger, ZipToken, Group 35, TEMP.Hippo, TG 3390, Bronze Union) ... Examples of associated tools: Ghost, ASPXSpy, ZxShell RAT, HyperBro, PlugX RAT, Windows Credential Editor, FoundCore, China Chopper...
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.