GhostAdmin
Aliases: Ghost iBot
- First seen
- 2017-05-01 00:00:00
- Malware type
- rat, screen-capture
- Family
- Malware family
- Profile updated
- 2026-07-07 15:02:53
Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical
Targeted regions: country_code:us country_code:ru country_code:cn
Context
GhostAdmin is a Remote Access Trojan (RAT) known for its capabilities in screen capturing and data exfiltration, often used in cyber-espionage attacks. It targets government, financial, and healthcare sectors, primarily in the United States, Russia, and China.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Ghost Admin (report)
- bleepingcomputer.com — New Ghostadmin Malware Used For Data Theft And Exfiltration (report)
- cylance.com — Threat Spotlight Ghostadmin (report)