216.73.216.6

AI-Automated Threat Hunting Brings GhostPenguin Out of the Shadows

· Published 08/12/2025 16:35 · Modified 21/12/2025 18:49

Export JSON

Essential information

Published
08/12/2025 16:35
Modified
21/12/2025 18:49
Tags
2025-12-08 ai threat hunting c++ ghostpenguin linux backdoor multi-threaded rc5 encryption remote shell udp communication zero-detection malware
Related entities
2 observables, 17 techniques (mitre), 1 malware

Description

An undocumented called was discovered using AI-driven threat hunting. This C++ malware provides access and file system operations over an encrypted UDP channel. It uses a structured handshake mechanism and synchronizes threads for registration, heartbeat signaling, and command delivery. The discovery involved analyzing zero-detection Linux samples from VirusTotal, extracting artifacts, and using AI for automated profiling. Custom YARA rules and queries helped surface this evasive threat. Analysis revealed is still in development, with debug artifacts present. The malware's comprehensive capabilities include access, file manipulation, and directory operations.

External references