GhostAdmin

Aliases: Ghost iBot

First seen
2017-05-01 00:00:00
Malware type
rat, screen-capture
Family
Malware family
Profile updated
2026-07-07 15:02:53

Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical

Targeted regions: country_code:us country_code:ru country_code:cn

Context

GhostAdmin is a Remote Access Trojan (RAT) known for its capabilities in screen capturing and data exfiltration, often used in cyber-espionage attacks. It targets government, financial, and healthcare sectors, primarily in the United States, Russia, and China.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Ghost Admin (report)
  • bleepingcomputer.com — New Ghostadmin Malware Used For Data Theft And Exfiltration (report)
  • cylance.com — Threat Spotlight Ghostadmin (report)

External references