Gh0stCringe, also known as CirenegRAT, is a Windows remote access trojan derived in part from the publicly released Gh0st RAT source code, while also containing substantial unique functionality. It has been observed in multiple intrusion contexts, including phishing campaigns targeting users in Taiwan and compromises of poorly secured Windows-hosted MS-SQL and MySQL database servers. Reported delivery and access methods include phishing emails carrying malicious PDF or ZIP lures, exploitation of SMB vulnerabilities, and attacks against exposed database services using weak credentials or unpatched vulnerabilities. Gh0stCringe has also appeared in broader espionage-oriented operations against government networks and has been associated in reporting with activity linked to Silver Fox and with intrusions attributed with moderate confidence to Alloy Taurus/GALLIUM/Softcell.
The malware provides full remote command-and-control and supports a broad post-compromise feature set. Documented capabilities include host reconnaissance, collection of system and security-product information, keylogging, clipboard theft, payload download and execution, service control, self-update, self-uninstall, event cleaning, process and window scanning, and loading of additional proxy or plugin modules. It can also invoke destructive behavior including master boot record destruction. Gh0stCringe uses a custom command-and-control packet format distinguished from classic Gh0st RAT variants and can receive commands to extend functionality through in-memory modules.
Gh0stCringe includes multiple persistence modes tailored to different execution contexts, including service-based persistence and Run-key registration. It also supports self-copying, file attribute manipulation, optional file-size padding, and anti-analysis checks involving parent-process validation. Additional defense-evasion behavior includes terminating selected processes. Keylogging is implemented through asynchronous keyboard state polling rather than the hook-based approach used by some Gh0st RAT variants.
Operational reporting places Gh0stCringe in campaigns against government entities and users in Asia, especially Taiwan, as well as opportunistic compromises of vulnerable database servers. In some server-side intrusions it has co-occurred with other commodity malware such as cryptomining-related families, suggesting use in mixed criminal ecosystems as well as more targeted operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The discovery of AtlasCross RAT represents an evolution of the threat actor's arsenal from Gh0st RAT derivatives like ValleyRAT (aka Winos 4.0), Gh0stCringe, and HoldingHands RAT (aka Gh0stBins).
The discovery of AtlasCross RAT represents an evolution of the threat actor's arsenal from Gh0st RAT derivatives like ValleyRAT (aka Winos 4.0), Gh0stCringe, and HoldingHands RAT (aka Gh0stBins).
The discovery of AtlasCross RAT represents an evolution of the threat actor's arsenal from Gh0st RAT derivatives like ValleyRAT (aka Winos 4.0), Gh0stCringe, and HoldingHands RAT (aka Gh0stBins).
The discovery of AtlasCross RAT represents an evolution of the threat actor's arsenal from Gh0st RAT derivatives like ValleyRAT (aka Winos 4.0), Gh0stCringe, and HoldingHands RAT (aka Gh0stBins).
The discovery of AtlasCross RAT represents an evolution of the threat actor's arsenal from Gh0st RAT derivatives like ValleyRAT (aka Winos 4.0), Gh0stCringe, and HoldingHands RAT (aka Gh0stBins).
"Another piece of malware that the attackers tried to use is Gh0stCringe, which is based on the source code of Gh0st RAT."
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Registering Run Key : Registers Run Key for the path ‘C:\Program Files\Common Files\scvh0st.exe’.
Unlike Gh0st RAT which uses the Windows Hooking method (use of SetWindowsHookEx() API), Gh0stCringe uses the keylogging technique of Windows Polling method (using GetAsyncKeyState() API).
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Gh0st RAT derivative in the Silver Fox malware arsenal, referenced as part of the tooling lineage preceding AtlasCross RAT.
RAT-family malware used in Taiwan-targeted phishing activity attributed to Silver Fox.
A Gh0st RAT variant delivered through phishing lures (taxes/invoices/pensions) using multi-stage loaders, DLL sideloading, and anti-VM/privilege-escalation techniques to reach a final payload that provides C2, host reconnaissance, and remote administration (file management/remote desktop) via additional modules.
Gh0st RAT-derived malware used to establish a foothold; deployed via a dropper and executed under masqueraded filenames/paths (e.g., conhost.exe under an ESET directory).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.