WMI Ghost
Aliases: Syndicasec, Wimmie
- First seen
- 2021-05-14 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 12:54:22
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:us country_code:ru
Context
WMI Ghost, also known as Syndicasec or Wimmie, is a stealthy remote access tool (RAT) that leverages Windows Management Instrumentation (WMI) for persistence and execution. It primarily targets government entities and technology firms to establish a backdoor for espionage purposes.
Reports & references
- Broadcom/Symantec — Thrip Hits Satellite Telecoms Defense Targets (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Wmighost (report)
- secrary.com — Wmighost (report)