Gh0stnet
Aliases: Remosh
- First seen
- 2009-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-06-14 23:25:04
- Profile updated
- 2026-07-07 12:55:59
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:us country_code:ru
Context
Gh0stnet, also known as Remosh, is a remote access tool (RAT) commonly used in cyber-espionage campaigns. It has been identified in attacks targeting sensitive information from government and telecommunications entities.
Reports & references
- Wikipedia — Ghostnet (report)
- contagiodump.blogspot.com — Jul 25 Mac Olyx Gh0St Backdoor In Rar (report)
- Trend Micro — Wp Detecting Apt Activity With Network Traffic Analysis (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Ghostnet (report)
- nartv.org — 10 Years Since Ghostnet (report)