WMI Ghost

Aliases: Syndicasec, Wimmie

First seen
2021-05-14 00:00:00
Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 12:54:22

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:us country_code:ru

Context

WMI Ghost, also known as Syndicasec or Wimmie, is a stealthy remote access tool (RAT) that leverages Windows Management Instrumentation (WMI) for persistence and execution. It primarily targets government entities and technology firms to establish a backdoor for espionage purposes.

Reports & references

  • Broadcom/Symantec — Thrip Hits Satellite Telecoms Defense Targets (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Wmighost (report)
  • secrary.com — Wmighost (report)

External references