Gh0st RAT is a long-running Windows remote access trojan whose source code became publicly available in 2008, leading to extensive reuse, modification, and actor-specific forks across criminal and espionage operations. It is widely associated with Chinese-speaking threat activity and has appeared both as an original family and as the basis for derivatives such as Golden Gh0st RAT and other customized implants used in Asia-focused campaigns.
The malware’s core function is remote administration of compromised systems. Reported capabilities across Gh0st RAT and closely aligned derivatives include remote desktop interaction, screen capture, reverse shell access, file upload and download, process execution, clipboard access, system information gathering, keylogging, credential theft, proxying, plugin loading, and exfiltration over command-and-control channels. Some variants support persistence through Windows autorun mechanisms, service installation, watchdog relaunch logic, or scheduled-task creation, and some campaigns have used reflective loading, in-memory module execution, AMSI bypass in adjacent payload chains, and process injection to reduce forensic visibility.
Gh0st RAT is commonly delivered through social engineering and malware staging chains rather than as a standalone first-stage payload. Observed delivery methods include phishing and spearphishing lures, SEO poisoning, fake software and fake update sites, counterfeit application installers, malicious archives, and DLL sideloading chains that abuse legitimate signed executables. Recent campaigns have used tax-themed lures in India, fake DeepL download pages targeting Chinese-speaking users, and broader distributor-driven operations linked to Silver Fox that rely on fake installers across Asia.
The family remains significant because its public codebase has enabled a large ecosystem of derivatives and loosely related malware marketed or labeled with the Gh0st name. Security reporting also notes that some samples initially classified as Gh0st RAT variants may in fact be distinct malware, so attribution at the sample level requires protocol and code-level validation rather than name similarity alone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These attacks began with exploitation of CVE-2022-3236 which is detailed in Sophos Security Advisory sophos-sa-20220923-sfos-rce.
As in the CVE-2022-1040 attack, the attackers built a malware that inspects all ping packets, waiting for a specially crafted ping packet that would not, otherwise, occur “in nature.”
“RAT malware such as Gh0stRAT and PlugX often used by Chinese threat actors…”
21 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These distributors operate across Asia, employing fake software installers and leveraging variants of Gh0st RAT and WinOS (ValleyRAT) trojans.
DCRAT → VenomRAT, EchoRAT, Gh0stRAT, BitRAT, CyberSpike, Dumpling RAT, DarkRAT (via ShaShenRAT)
While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.
While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.
While the source code for Gh0st RAT was released online in 2008, the malware has continued to be used by advanced persistent threat (APT) groups. Gh0st RAT first made headlines back in 2009, when a cyber-espionage group called GhostNet used it to target diplomatic, political, economic, and military targets around the world.
"As part of the second stage, the group deploys customized Gh0st RAT and Poison Ivy malware payloads designed to evade detection on its victims' systems."
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The infection begins on fraudulent websites that copy the look of the Indian Income Tax Department, each using an “/incometax” path and a fabricated compliance notice.
MITRE ATT&CK Tactic Technique Technique ID Description / Relevance Persistence Scheduled Task/Job: Scheduled Task T1053.005 Potential use for persistence (variant-dependent).
MITRE ATT&CK Tactic Technique Technique ID Description / Relevance Execution Command and Scripting Interpreter: Windows Command Shell T1059.003 Batch files are used to monitor and reinitiate RAT processes.
The reflectively loaded DLL begins by resolving its API dependencies at runtime... CreateProcessA, VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread.
The attack chain employs social engineering and counterfeit domains to trick users into downloading malicious ZIP archives.
MITRE ATT&CK Tactic Technique Technique ID Description / Relevance Persistence Scheduled Task/Job: Scheduled Task T1053.005 Potential use for persistence (variant-dependent).
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
MITRE ATT&CK Tactic Technique Technique ID Description / Relevance Persistence Scheduled Task/Job: Scheduled Task T1053.005 Potential use for persistence (variant-dependent).
The chain finishes by injecting two payloads into svchost.exe processes across every active user session
then installs a persistence service disguised as “Windows Mixed Reality Service”.
The malware then fetches a file from its infrastructure that looks like an ordinary JPEG image but actually hides multiple encrypted payloads appended after the picture data.
The downloaded file is a polyglot... The malware, however, disregards the picture entirely and reads only the data appended after the image, where the real payload is stored.
RONINGLOADER to distribute a Gh0st RAT variant through NSIS installers masquerading as legitimate programs like Google Chrome and Microsoft Teams.
With elevation confirmed, the downloader prepares its staging directory under C:\Program Files\Windows Media Player, a legitimate-looking path... copies its own running binary into the working directory under the name Mixed Reality.exe.
The chain finishes by injecting two payloads into svchost.exe processes across every active user session
With elevation confirmed, the downloader prepares its staging directory under C:\Program Files\Windows Media Player, a legitimate-looking path, and removes any artifacts left by a previous run.
MITRE ATT&CK Tactic Technique Technique ID Description / Relevance Defense Evasion Deobfuscate/Decode Files or Information T1140 Malware may decode itself during runtime.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Each implant connects to its own command server, giving the attacker a built-in backup if one connection gets blocked or detected.
207 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
169 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An older remote access trojan whose source code was published in 2008; the article describes Golden Gh0st RAT as a modified version of it.
Упомянут только для сравнения отдельных функций с ValleyRAT.
A remote access trojan family referenced as one of the malware variants leveraged by distributors associated with Silver Fox operations.
A Gh0st RAT derivative used as one of the final in-memory implants in the campaign; it provides remote access and screen capture capability and communicates with its own C2 over port 6666.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.