Gh0st RAT is a long-running Windows remote access trojan associated with Chinese-language threat activity and historically linked to the GhostNet espionage campaign. Public reporting places its origins around 2008 and ties its development lineage to the C. Rufus Security Team. Over time, both original builds and source-derived variants have appeared across multiple China-nexus intrusion sets, including activity overlapping with APT27-related reporting and later campaigns targeting Tibetan communities and organizations in Asia.
Gh0st RAT provides full remote-control functionality typical of a mature RAT and is used as a backdoor for sustained post-compromise access. Reported variants support arbitrary command execution, persistence, and command-and-control over custom network protocols; some newer samples also use multi-stage loading, dynamic API resolution, and domain-generation-based command-and-control to complicate detection and tracking. In observed intrusions, operators have deployed Gh0st RAT after establishing an initial foothold through exposed web applications and web shells, then used it to maintain access and continue follow-on operations.
Recent reporting describes Gh0st RAT variants being installed after compromise of internet-exposed phpMyAdmin instances, where attackers abused database log poisoning to write a web shell, managed the host with AntSword, deployed the Nezha monitoring agent for staging and control, disabled Microsoft Defender protections, and then installed the RAT with service-based persistence. Victimology in that campaign was concentrated in Taiwan, Japan, South Korea, and Hong Kong, with broader spread elsewhere. Gh0st RAT and closely related source-derived backdoors have also been observed in broader Chinese cyber-espionage operations against diplomatic, political, and regional targets.
Gh0st RAT remains notable less as a single static family than as an enduring codebase and operational pattern reused, modified, and repurposed by multiple actors for espionage-oriented remote access on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Decoding network data from a Gh0st RAT variant Ghost RAT APT27
Decoding network data from a Gh0st RAT variant Ghost RAT APT27
Decoding network data from a Gh0st RAT variant Ghost RAT APT27
“...deploying backdoors that very likely borrowed source code from Ghost RAT, a Trojan developed by Chinese threat actor C. Rufus Security Team. Ghost RAT appears to date to 2008...”
“...deploying backdoors that very likely borrowed source code from Ghost RAT, a Trojan developed by Chinese threat actor C. Rufus Security Team. Ghost RAT appears to date to 2008...”
"SilverFox activity: Antiy says the SilverFox (YouSnake) group infected over 17,000 users with the Ghost RAT..."
11 distinct techniques documented for this family, organized by ATT&CK tactic.
All WinApi functions are resolved dynamically using GetProcAddress and are stored into a large function table which is trivially reassembled.
Each of these POST requests represents the attacker’s C2 server sending instructions to the compromised web server via the deployed web shell.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ghost RAT6
Ghost RAT6
Huntress Uncovers Log Poisoning Campaign Linking Nezha and Ghost RAT in Widespread Asian Cyber Intrusions
Remote Access Trojan deployed via Nezha to provide persistent remote access and control over compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.