win.ghostengine

First seen
2020-05-15 00:00:00
Malware type
backdoor, rat
Profile updated
2026-07-07 15:02:51

Targeted industries: government-and-public-sector energy-and-utilities

Context

Win.GhostEngine is a Remote Access Trojan used primarily for cyber-espionage purposes, with capabilities to infiltrate and control target systems remotely. It has been observed targeting government and energy sectors, allowing attackers to snoop on and exfiltrate sensitive information.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Ghostengine (report)
  • darkreading.com — Novel Edr Killing Ghostengine Malware Stealth (report)
  • elastic.co — Invisible Miners Unveiling Ghostengine (report)
  • github.com — Windows Trojan Ghostengine.Yar (report)

External references