GhostX
GhostX is a Windows remote access trojan (RAT) and offensive intrusion framework referenced in leaked materials from the Chinese cybersecurity firm KnownSec. The content describes it as a multi-vector exploitation and persistence framework used for active intrusion. Reported capabilities include file browsing, screen monitoring, keystroke logging, password and credential extraction, endpoint monitoring, browser exploitation, user profiling, network traffic manipulation, routing manipulation, and DNS hijacking. The leaked materials also describe browser fingerprinting intended to create a durable identity signature that can track users across VPNs, proxies, and devices. GhostX is associated in the content with KnownSec’s offensive product set and is described as likely developed for or used in support of Chinese state customers, including China’s Ministry of Public Security and elements of the People’s Liberation Army. The reporting places GhostX in the broader context of government digital surveillance and offensive cyber operations. High-confidence details directly mentioned in the content identify it as targeting Windows systems and enabling credential theft, persistence, and long-term access.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
1 technique
Execution
Credential Access
2 techniques
Credential Access
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows remote access trojan that enables screen monitoring, keystroke logging, and password extraction.
Windows remote access trojan enabling file browsing, screen monitoring, keystroke logging, and password extraction.
An offensive multi-vector exploitation and persistence framework used for intrusion. Capabilities described include browser fingerprinting for durable user identity tracking, credential theft, and network traffic manipulation; post-compromise modules include routing manipulation and DNS hijacking to redirect traffic and maintain long-term access.
Offensive platform described as enabling browser exploitation, routing manipulation, credential theft, and endpoint monitoring.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.