ANGRYREBEL

Aliases: Ghost RAT

First seen
2013-09-01 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-07-19 20:32:31
Profile updated
2026-07-07 12:48:40

Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications

Context

ANGRYREBEL, also known as Ghost RAT, is a remote access trojan primarily utilized in cyber espionage campaigns against government, defense, and technology sectors. It enables attackers to gain remote control over infected systems and exfiltrate sensitive information.

Exploited vulnerabilities

  • CVE-2025-55182 (vulnerability)

Reports & references

  • secureworks.com — Bronze Olive (report)
  • cloud.google.com — Threat Actors Exploit React2Shell Cve 2025 55182 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Angryrebel (report)
  • news.sophos.com — Cloudsnooper Report (report)

External references