GhostNet is the name commonly used for a large cyber-espionage operation uncovered in 2009 that compromised systems in more than 100 countries, including computers associated with Tibetan organizations, diplomatic entities, and government-related targets. Public reporting ties the operation to the use of remote-access malware often referred to as Ghost RAT, which enabled covert surveillance and remote control of infected Windows systems. Documented capabilities associated with the operation include theft of sensitive files, remote command execution, and covert activation of webcams and microphones for live monitoring. The campaign is widely characterized as espionage-focused rather than financially motivated or destructive.
The operation is notable for targeting the Office of the Dalai Lama and other Tibetan-related organizations, and for broader victimology spanning embassies, ministries, and international institutions. Reporting has described infrastructure linked to servers in China, but direct state attribution has remained unproven in the public record. GhostNet is historically significant as an early, high-profile example of transnational cyber-espionage using commodity-style remote administration malware in targeted intrusions.
Available information in this record supports treating GhostNet primarily as the campaign name for an espionage network rather than a distinct malware family. The malware associated with the operation functioned as a Windows backdoor or RAT used for surveillance, data theft, and post-compromise control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cyber-espionage network uncovered after sensitive files were exfiltrated from Tibetan government computers; it was largely traced to Chinese servers.
Targeted cyber-espionage malware operation historically used to spy on Tibetan organizations and many government offices globally (as referenced for historical context).
Named espionage malware/network discussed alongside Ghost RAT in GhostNet investigation.
Surveillance malware/program associated with covert activation of webcams and audio inputs for spying.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.