Gh0st RAT is an open-source remote-access trojan and backdoor for Windows. Its publicly available source code has enabled numerous modified implants used by multiple threat actors, including China-linked espionage groups and criminal operators. Moudoor is an alternate name associated with its use by Axiom, also known as Group 72.
Gh0st RAT provides remote shell access, file management, payload downloading and execution, process and window enumeration, and remote shutdown or reboot. Documented variants support online and offline keylogging, webcam and microphone surveillance, clipboard monitoring, and host-information collection. Modified Dragon Breath implants additionally support active-window logging, remotely configured clipboard replacement, event-log clearing, and victim tagging. The malware can inject malicious code into newly created processes and establish persistence through Windows services and startup registry entries. Its command-and-control implementations include encrypted custom protocols over TCP; particular variants use AES or RC4, and some use compressed traffic.
Distribution includes trojanized software installers and counterfeit vendor-download pages. Dragon Breath, also tracked as APT-Q-27, has delivered modified Gh0st RAT through installers impersonating Google Chrome and Microsoft Teams, primarily targeting Chinese-speaking users. Silver Fox has also distributed the malware through spoofed software-download sites. Gh0st RAT has been deployed in campaigns exploiting CVE-2024-4577 in Windows PHP CGI installations and in compromises of vulnerable HTTP File Server installations. Some delivery chains employ DLL side-loading and extensive endpoint-defense tampering. A September 2024 campaign used RealBlindingEDR and a vulnerable Dell driver to disable EDR through bring-your-own-vulnerable-driver exploitation.
Known operators include Axiom and GALLIUM. Gh0st RAT variants have appeared in espionage against government, technology, education, telecommunications, aerospace, defense, manufacturing, and research organizations. Its availability and extensive modification across unrelated operations make the malware alone insufficient for reliable threat-actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2024년 5월 HFS의 원격 코드 실행 취약점인 CVE-2024-23692가 공개되었으며 이를 활용할 경우 공격자는 HFS에 명령이 포함된 패킷을 전송하여 HFS가 악성 명령을 실행하도록 할 수 있다.
The TellYouThePass ransomware gang has been leveraging CVE-2024-4577, a remote code execution vulnerability in PHP to deliver web shells and deploy ransomware on targeted systems. | July 11, 2024: Multiple malware campaigns targets the PHP vulnerability: Gh0st RAT, RedTail crypto miners, and XMRig.
gh0st RAT is able to open a remote shell to execute commands.
A Chinese advanced persistent threat tracked as Deep Panda has been observed exploiting the Log4Shell vulnerability in VMware Horizon servers to deploy a backdoor and a novel rootkit on infected machines with the goal of stealing sensitive data. The latest set of attacks documented by Fortinet shows that the infection procedure involved the exploitation of the Log4j remote code execution flaw (aka Log4Shell) in vulnerable VMware Horizon servers.
另一种是格式攻击文档,利用漏洞CVE-2012-0158来释放并执行可执行文件,同时打开欺骗收件人的“正常”文档文件。... CVE-2012-0158是一个文档格式溢出漏洞... 该组织则使用了MHT格式,这种格式同样可以触发漏洞,而且在当时一段时间内可以躲避多种杀毒软件的查杀。 | 通过我们对于案例4中update.exe的分析,得到该样本所使用的互斥量为“chinaheikee__inderjns”,该互斥量与我们分析过的gh0st样本的互斥量一致,是默认配置,而且上线数据包与gh0st 3.75版本非常一致,因此我们可以判定该update.exe为gh0st后门。
The first flaw affects the Firefox browser and is tracked as CVE-2019-17026... Both vulnerabilities were used as part of a campaign aimed at Chinese government agencies and attributed to the DarkHotel APT. This campaign delivered the Gh0st RAT malware onto compromised devices. | Both vulnerabilities were used as part of a campaign aimed at Chinese government agencies and attributed to the DarkHotel APT. This campaign delivered the Gh0st RAT malware onto compromised devices.
The second, designated CVE-2020-0674, is a remote code execution (RCE) flaw in Internet Explorer. Both bugs were patched in January and February 2020. Both vulnerabilities were used as part of a campaign aimed at Chinese government agencies and attributed to the DarkHotel APT. This campaign delivered the Gh0st RAT malware onto compromised devices. | Both vulnerabilities were used as part of a campaign aimed at Chinese government agencies and attributed to the DarkHotel APT. This campaign delivered the Gh0st RAT malware onto compromised devices.
We first observed this actor in July of 2018 exploiting a WebLogic vulnerability (CVE-2017-10271) to drop a miner that was associated with a campaign called "MassMiner".
These attacks began with exploitation of CVE-2022-3236 which is detailed in Sophos Security Advisory sophos-sa-20220923-sfos-rce.
As in the CVE-2022-1040 attack, the attackers built a malware that inspects all ping packets, waiting for a specially crafted ping packet that would not, otherwise, occur “in nature.”
36 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Red Dev 4 - Background: BlackMould, Poison Ivy, SoftEther VPN, Gh0st RAT, China Chopper
Red Dev 4 - Background: BlackMould, Poison Ivy, SoftEther VPN, Gh0st RAT, China Chopper
We have observed the group to use the following RAT malware: Gh0st RAT (aka Moudoor)
“The last payload downloaded is a slightly modified Gh0st RAT sample designed to act as a backdoor implant. Its behavior is very similar to the versions detected in attacks associated with the Iron Tiger APT group.”
The RONINGLOADER infection chain's final payload is described as a modified gh0st RAT providing keylogging, clipboard hijacking, and encrypted C2.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
513 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An operator-controlled malicious AI agent configured within Hermes Agent through a replacement SOUL.md persona file. It receives tasks through Telegram, generates and executes terminal commands, analyzes their output, and helps maintain access. Its collection priorities include AI-service API keys, SSH credentials, access tokens, and other secrets; results and collected data are returned through Telegram. The report describes an interactive operator–AI workflow rather than fully autonomous attacks.
Malicious persona configuration used with the otherwise unmodified Hermes Agent framework within CARBONATO infections. It instructs the LLM-enabled agent to perform post-exploitation activity, maintain persistence, collect credentials—especially AI API keys—and execute operator tasks relayed through Telegram.
An AI agent deployed by Carbonato within the Hermes Agent framework. It interprets operator tasks received through Telegram, generates and executes terminal commands, collects sensitive credentials and tokens, and returns results to the operator.
The malicious persona imposed on the Hermes Agent instance within CARBONATO. It acts as a Telegram-directed post-exploitation agent that executes commands on compromised hosts, maintains persistence, and prioritizes exfiltration of AI API keys and other credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.