gh0st RAT
MITRE ATT&CK: S0032 View on attack.mitre.org
Aliases: Mydoor, Moudoor, gh0st RAT
- First seen
- 2009-01-01 00:00:00
- Malware type
- rat, backdoor
- Family
- Malware family
- Operating systems
- windows, macos
- Related IoCs
- 6735 (6693 malicious)
- Last IoC activity
- 2026-09-02 02:37:50
- Profile updated
- 2026-07-07 13:19:40
Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications
Context
gh0st RAT is a remote access tool (RAT). The source code is public and it has been used by multiple groups.
Recent IoC activity
6,711 malicious indicators in Maltiverse are attributed to gh0st RAT (S0032). The 20 most recently updated:
Detection coverage
- 576 Sigma rules
Malware & tools used
- Shared Modules (attack-pattern)
- Modify Registry (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Process Injection (attack-pattern)
- Rundll32 (attack-pattern)
- Service Execution (attack-pattern)
- DLL (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Query Registry (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Native API (attack-pattern)
- Process Discovery (attack-pattern)
- Windows Service (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- System Information Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Screen Capture (attack-pattern)
- Fast Flux DNS (attack-pattern)
- Keylogging (attack-pattern)
- Standard Encoding (attack-pattern)
- Encrypted Channel (attack-pattern)
Used by threat actors
- Operation Dust Storm (campaign)
- Threat Group-3390 (threat-actor)
- Axiom (threat-actor)
- PittyTiger (threat-actor)
- APT18 (threat-actor)
- APT41 (threat-actor)
- TA459 (threat-actor)
- Kimsuky (threat-actor)
- Leviathan (threat-actor)
- APT5 (threat-actor)
- Higaisa (threat-actor)
- Andariel (threat-actor)
- APT14 (threat-actor)
Related threat objects
- Ghost RAT (malware)
Reports & references
- web.archive.org — Executive Summary Final 1 (report)
- research.nccgroup.com — Decoding Network Data From A Gh0St Rat Variant (report)
- MITRE ATT&CK — S0032 (report)
- arbornetworks.com — Musical Chairs Playing Tetris (report)
- Mandiant — Demonstrating Hustle (report)
- volexity.com — Have You Been Haunted By The Gh0St Rat Today (report)