Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In part one of this blog series, we analyzed CylindricalCanine’s malware Golden Gh0st RAT... the Golden Gh0st RAT payload contains hard-coded IP addresses that can be extracted.
In part one of this blog series, we analyzed CylindricalCanine’s malware Golden Gh0st RAT... the Golden Gh0st RAT payload contains hard-coded IP addresses that can be extracted.
Central to the threat actor's operations is a modified version of Gh0st RAT (aka Farfli)... The modular malware, referred to as Golden Gh0st RAT, is delivered by means of Golden Gh0st Loader.
In this blog, we review the behavior and capabilities of a malware we call Golden Gh0st Loader and Golden Gh0st RAT... Golden Gh0st RAT’s main feature is remote access, and is a modified version of the Gh0st RAT.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
By stealing them, the attackers could intercept certificates intended for legitimate customers, then use them to sign malware that looked more credible to security controls.
the initial delivery and lure are different: the malware was distributed through a watering hole website offering a VPN download.
Defenders should also watch for suspicious DLLs loaded by legitimate applications, unexpected scheduled tasks, new local administrator accounts, and outbound WebSocket traffic to the listed domains.
Defenders should also watch for suspicious DLLs loaded by legitimate applications, unexpected scheduled tasks, new local administrator accounts, and outbound WebSocket traffic to the listed domains.
By stealing them, the attackers could intercept certificates intended for legitimate customers, then use them to sign malware that looked more credible to security controls.
Defenders should also watch for suspicious DLLs loaded by legitimate applications, unexpected scheduled tasks, new local administrator accounts, and outbound WebSocket traffic to the listed domains.
By stealing them, the attackers could intercept certificates intended for legitimate customers, then use them to sign malware that looked more credible to security controls.
The library then decrypts and loads the actual RAT from a file that may be disguised as a log file.
Golden Gh0st RAT can give operators remote access, collect browser credentials, capture screenshots, list running processes, execute commands, and erase traces of activity from infected systems.
The final stage is Golden Gh0st RAT, which comes with a wide array of capabilities to ... clear Windows Event logs.
Recursive file/directory delete... Self-destruct—deletes payload files
By stealing them, the attackers could intercept certificates intended for legitimate customers, then use them to sign malware that looked more credible to security controls.
Golden Gh0st RAT can give operators remote access, collect browser credentials, capture screenshots, list running processes, execute commands, and erase traces of activity from infected systems.
the Golden Gh0st RAT payload contains hard-coded IP addresses that can be extracted.
The final stage is Golden Gh0st RAT, which comes with a wide array of capabilities to set up persistence, steal sensitive data, start a SOCKS proxy tunnel...
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom Gh0st RAT variant used by the CylindricalCanine subgroup of GoldenEyeDog, featuring hard-coded command-and-control IP addresses and used in phishing campaigns against corporate victims.
Remote access trojan used by GoldenEyeDog that provides persistent access, steals browser credentials, captures screenshots, enumerates processes, executes commands, removes traces, and can deploy persistence plugins including an RDP-enabling administrator backdoor account.
A modified Gh0st RAT variant used by CylindricalCanine/GoldenEyeDog. It is the final-stage payload in a DLL side-loading chain and supports persistence, sensitive data theft, SOCKS proxying, display suppression, keylogging, screenshots, process enumeration, shell command execution, dropping additional payloads, and clearing Windows Event logs.
A modified Gh0st RAT variant used by GoldenEyeDog/CylindricalCanine, primarily delivered via phishing or support portal submissions. It provides remote access and modular plugin-based capabilities including keylogging, screenshot capture, SOCKS proxying, credential theft, command execution, persistence, anti-forensics, and delivery of an RDP backdoor plugin.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.