C. Rufus Security Team is a Chinese threat actor associated with development of Ghost RAT, a long-running remote access Trojan that played a key role in the GhostNet cyberespionage campaign. The group is historically tied to Chinese intrusion activity and is notable in later reporting because source code from Ghost RAT was assessed to have been borrowed or reused by other Chinese espionage operations. Ghost RAT has been linked to surveillance-oriented intrusions against politically sensitive targets, including Tibetan exile organizations associated with the Dalai Lama. The actor is best known for malware development rather than for a broad, independently documented intrusion set in the supplied facts. Its principal known capability is creation of remote-access tooling used for covert access and post-compromise control in espionage operations. The association with GhostNet and subsequent code reuse by later Chinese clusters places C. Rufus Security Team within the broader Chinese state-linked cyberespionage ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese threat actor referenced as the developer of Ghost RAT (circa 2008), which is noted as source code likely borrowed by Phantom Taurus for backdoor deployment.
Chinese threat actor referenced as the developer of Ghost RAT (circa 2008), which is noted as source code likely borrowed by Phantom Taurus for backdoor deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.