gh0st RAT

MITRE ATT&CK: S0032 View on attack.mitre.org

Aliases: Mydoor, Moudoor, gh0st RAT

First seen
2009-01-01 00:00:00
Malware type
rat, backdoor
Family
Malware family
Operating systems
windows, macos
Related IoCs
6735 (6693 malicious)
Last IoC activity
2026-09-02 02:37:50
Profile updated
2026-07-07 13:19:40

Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications

Context

gh0st RAT is a remote access tool (RAT). The source code is public and it has been used by multiple groups.

Recent IoC activity

6,711 malicious indicators in Maltiverse are attributed to gh0st RAT (S0032). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname skystackservice.com 2026-09-02 1
file sample 2026-09-02_85a7ec184c0983bd54a7d653dc48d787_elex_gh0st-rat_wannacry 2026-09-02 1
file sample faef256b12f9549223e1abe82e7650875ba13203f948f5682113ad0f783a7645 2026-09-02 1
file sample 24511f4fc74a65ccad4175b26dbca15b6dc25ecb47c5ddac3d36369457c1d1af 2026-09-02 1
file sample 2026-09-02_a8727fea33d12f810198f240a33af286_elex_gh0st-rat_wannacry 2026-09-02 1
file sample f68b55affd59eccfaef1d974566af4000493d1b6eb449acc43d1c948646ddd4e 2026-09-02 1
file sample 2026-09-02_bc8266c973d82ed7579534c5a441f4cf_elex_wannacry 2026-09-02 1
file sample 4d3ae7328a2afd70bd350088a3bae50fb4e6ce33aeb97eb9b625fa93f92a0127 2026-09-02 1
file sample der-btuq.exe 2026-09-02 2
file sample dc12de857b86bb05919c002933400aa379da223fd08d8aa8f18f475bc55088f8 2026-09-02 1
file sample 2026-09-01_8dbd2214b5771e20c6d54fce3a181fb8_elex_glassworm_parite_ramnit_wannacry 2026-09-02 1
file sample 417dee39d4e87bc9cb87332286268296ee42601e6b7f0423cc889ac58d8cbfc1 2026-09-02 1
file sample 3494370d16e7097361760d7ff93f5b324db1445c956d80daca81ecfe4b990712.bin 2026-09-02 2
file sample 5d2af5a710f9caf1471d1b05da512dd7b209644734fd3b90213d4cf17843d9f2.dll 2026-09-02 2
file sample 2026-09-01_be16138c4ee32e79e82641616eb4f92a_elex_glassworm_parite_ramnit_wannacry 2026-09-02 1
file sample 243420d7c7ec04bb0211163a808b97db63302fbd2f7ea6507c61d03a50c68874 2026-09-02 1
file sample 188c11796ae42faff1b1a0570f2a939300ef64fdc8259cb154df8f1608ba1fb3 2026-09-02 1
file sample 9a39c838f3b523a91f03e3ce97689e42f84ae037fe1201ee2bd1ef88426b5ae4 2026-09-02 1
file sample 7ea99608ebade854c3b871df800f0ddce029a9d0fcc89444484b282ee5706538 2026-09-02 1
file sample eefa4453e08902f8676e812796c3797ed477741571c8fb4f808741e3ecbc87bb 2026-09-02 1

Detection coverage

  • 576 Sigma rules

Malware & tools used

  • Shared Modules (attack-pattern)
  • Modify Registry (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Process Injection (attack-pattern)
  • Rundll32 (attack-pattern)
  • Service Execution (attack-pattern)
  • DLL (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Query Registry (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Native API (attack-pattern)
  • Process Discovery (attack-pattern)
  • Windows Service (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • System Information Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Screen Capture (attack-pattern)
  • Fast Flux DNS (attack-pattern)
  • Keylogging (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Encrypted Channel (attack-pattern)

Used by threat actors

Related threat objects

Reports & references

  • web.archive.org — Executive Summary Final 1 (report)
  • research.nccgroup.com — Decoding Network Data From A Gh0St Rat Variant (report)
  • MITRE ATT&CK — S0032 (report)
  • arbornetworks.com — Musical Chairs Playing Tetris (report)
  • Mandiant — Demonstrating Hustle (report)
  • volexity.com — Have You Been Haunted By The Gh0St Rat Today (report)

External references