216.73.216.6

Digital Doppelgangers: Anatomy of Evolving Impersonation Campaigns Distributing Gh0st RAT

· Published 15/11/2025 05:58 · Modified 17/11/2025 09:53

Export JSON

Essential information

Published
15/11/2025 05:58
Modified
17/11/2025 09:53
Tags
2025-11-15 brand impersonation chinese-speaking targets cloud infrastructure dll side-loading domain generation gh0st rat multi-stage infection
Related entities
10 techniques (mitre), 3 malware, 5 others

Description

This report details two interconnected malware campaigns targeting Chinese-speaking users in 2025, using large-scale to deliver variants. The first campaign, active from February to March, mimicked three brands across over 2,000 domains. The second campaign, starting in May, impersonated over 40 applications with more sophisticated infection chains. Both campaigns used for payload delivery and for evasion. The adversary demonstrated an evolving operational playbook, advancing from simple droppers to complex multi-stage infections. The campaigns' infrastructure remained active for months, indicating a persistent and well-resourced threat actor focused on globally.

External references