216.73.216.6

Introducing Gh0stGambit: A Dropper for Deploying Gh0st RAT

· Published 31/07/2024 10:43 · Modified 31/07/2024 10:59

Export JSON

Essential information

Published
31/07/2024 10:43
Modified
31/07/2024 10:59
Tags
2024-07-31 dropper encryption evasion gh0st rat malware moudoor mydoor rat
Related entities
1 vulnerabilities (cve), 6 observables, 20 techniques (mitre), 3 malware

Description

This analysis examines a recent campaign involving a dubbed Gh0stGambit, which is employed to retrieve and execute encrypted payloads, specifically a variant of the notorious Gh0st Remote Access Trojan (). The report details the multi-stage infection process, including the use of deceptive Chrome installer lures, the 's evasive techniques, and the capabilities of the delivered variant. The exhibits advanced functionality, such as rootkit components, keylogging, process termination, and data exfiltration. The investigation concludes that the campaign primarily targets Chinese-speaking users, based on the use of Chinese web lures and the 's ability to gather information from Chinese applications.

External references