216.73.217.174

GhostContainer backdoor for Exchange servers

· Published 17/07/2025 14:59 · Modified 17/07/2025 19:51

Export JSON

Essential information

Published
17/07/2025 14:59
Modified
17/07/2025 19:51
Tags
2025-07-17 apt asia backdoor evasion exchange ghostcontainer open-source proxy
Related entities
1 observables, 2 others

Description

A sophisticated targeting servers of high-value organizations in has been discovered. The malware, named , is a multi-functional that can be dynamically extended with additional modules. It leverages several projects and employs various techniques to avoid detection. The grants attackers full control over the server and can function as a or tunnel. The malware is believed to be part of an campaign targeting government and high-tech companies in . It includes components for C2 parsing, virtual page injection, and web functionality. The attackers demonstrated expertise in exploiting systems and assembling sophisticated espionage tools.

External references