Ghost RAT
Aliases: Farfli, Gh0st RAT, PCRat
- First seen
- 2008-06-01 00:00:00
- Malware type
- rat, keylogger, screen-capture, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:22:25
- Profile updated
- 2026-07-07 12:35:12
Targeted industries: defense-and-aerospace government-and-public-sector technology-and-telecommunications
Context
According to Security Ninja, Gh0st RAT (Remote Access Terminal) is a trojan “Remote Access Tool” used on Windows platforms, and has been used to hack into some of the most sensitive computer networks on Earth. Below is a list of Gh0st RAT capabilities. Take full control of the remote screen on the infected bot. Provide real time as well as offline keystroke logging. Provide live feed of webcam, microphone of infected host. Download remote binaries on the infected remote host. Take control of remote shutdown and reboot of host. Disable infected computer remote pointer and keyboard input. Enter into shell of remote infected host with full control. Provide a list of all the active processes. Clear all existing SSDT of all existing hooks.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Pcrat (yara-rule)
Related threat objects
- Gh0st RAT (malware)
Reports & references
- web.archive.org — Inside Back Door Attack (report)
- secureworks.com — Bronze Globe (report)
- MITRE ATT&CK — G0001 (report)
- MITRE ATT&CK — G0026 (report)
- labs.bitdefender.com — Operation Pzchao A Possible Return Of The Iron Tiger Apt (report)
- bitdefender.com — Bitdefender Business 2017 Whitepaper Pzchao Crea2452 En En Genericuse (report)
- nccgroup.trust — Decoding Network Data From A Gh0St Rat Variant (report)
- secureworks.com — Bronze Union (report)
- Palo Alto Unit 42 — Iron Taurus (report)
- MITRE ATT&CK — G0011 (report)
- Trend Micro — Collecting In The Dark Tropic Trooper Targets Transportation And Government Organizations (report)
- secureworks.com — Bronze Fleetwood (report)
- secureworks.com — Bronze Edison (report)
- nartv.org — Ghostnet (report)
- st.drweb.com — Drweb Research Attacks On Russian Research Institutes En (report)
- MITRE ATT&CK — G0096 (report)
- s.tencent.com — 836 (report)
- Microsoft — Gallium Targeting Global Telecom (report)
- Trend Micro — Wp Operation Earth Berberoka (report)
- Trend Micro — New Apt Group Earth Berberoka Targets Gambling Websites With Old (report)
- botconf.eu — Botconf2022 40 Lunghihorejsi (report)
- decoded.avast.io — Apt Group Planted Backdoors Targeting High Profile Networks In Central Asia (report)
- ESET — Operation Nightscout Supply Chain Attack Online Gaming Asia (report)
- Palo Alto Unit 42 — Operation Diplomatic Specter (report)
- ptsecurity.com — Covid 19 And New Year Greetings The Higaisa Group (report)