Ghost is a backdoor used to maintain remote control of compromised systems. UTG-Q-015 has used Ghost alongside Xnote and Vshell to control Linux servers. The group's Linux operations have included targeting AI-related infrastructure, although specific exploitation chains associated with its other backdoors cannot be attributed to Ghost.
Payloads identified as Ghost have also appeared in Windows campaigns distributing malicious installers disguised as KakaoTalk through SEO-poisoned search results. Later variants concealed encrypted shellcode in PNG images and installed the final payload as a Windows service, providing persistence. These delivery chains combined legitimate installer components with malicious code.
The Ghost backdoor designation must be distinguished from similarly named ransomware, GhostLocker, the Ghost npm supply-chain campaign, and GHOST iOS exploitation stages. Their encryption, cryptocurrency-theft, and exploitation capabilities are not established capabilities of this backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Exploiting CVE-2018-13379 gives adversaries direct, unauthenticated access to sensitive system files, including the jackpot sslvpn_websession. This plaintext file often contains usernames and passwords, giving attackers immediate access to credentials. | On February 19, 2025, CISA and the FBI issued an advisory warning about “Ghost” ransomware, which exploits this vulnerability using publicly available code.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UTG-Q-015 generally use Xnote, Ghost, Vshell and other backdoors to control the target linux servers.
APT27 (aka Lucky Mouse, Emissary Panda, Iron Tiger, ZipToken, Group 35, TEMP.Hippo, TG 3390, Bronze Union) ... Examples of associated tools: Ghost, ASPXSpy, ZxShell RAT, HyperBro, PlugX RAT, Windows Credential Editor, FoundCore, China Chopper...
4 distinct techniques documented for this family, organized by ATT&CK tactic.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named exploit stages mentioned in a historical payload-capture indicator. The content provides no further description of their capabilities or deployment.
Native iOS exploitation payloads targeting internal services associated with ARKit face tracking, Safari JavaScript bridging, Safari data records, privilege escalation, and WebKit exception handling. The report distinguishes these exploit stages from the wallet-stealing modules and identifies a previously undocumented Safari data-records signature.
Final malware payload delivered and executed by the fake KakaoTalk installer campaign.
A malicious npm supply-chain campaign first seen in early February 2026 that uses fake npm install logs and sudo prompts to trick developers into installing a remote access trojan that steals cryptocurrency wallets and sensitive personal data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.