win.ghostengine
- First seen
- 2020-05-15 00:00:00
- Malware type
- backdoor, rat
- Profile updated
- 2026-07-07 15:02:51
Targeted industries: government-and-public-sector energy-and-utilities
Context
Win.GhostEngine is a Remote Access Trojan used primarily for cyber-espionage purposes, with capabilities to infiltrate and control target systems remotely. It has been observed targeting government and energy sectors, allowing attackers to snoop on and exfiltrate sensitive information.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Ghostengine (report)
- darkreading.com — Novel Edr Killing Ghostengine Malware Stealth (report)
- elastic.co — Invisible Miners Unveiling Ghostengine (report)
- github.com — Windows Trojan Ghostengine.Yar (report)