GHAMBAR

Malware type
rat, keylogger, screen-capture
Family
Malware family
Profile updated
2026-07-07 13:08:53

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

According to Mandiant, GHAMBAR is a remote administration tool (RAT) that communicates with its C2 server using SOAP requests over HTTP. Its capabilities include filesystem manipulation, file upload and download, shell command execution, keylogging, screen capture, clipboard monitoring, and additional plugin execution.

Reports & references

  • socradar.io — Dark Web Profile Apt42 Iranian Cyber Espionage Group (report)
  • Mandiant — 17826 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Ghambar (report)

External references