GhostContainer is a suspected advanced persistent threat activity cluster associated with intrusions against government entities in Asia through exploitation of Microsoft Exchange Server. The operation is characterized by deployment of the bespoke GhostContainer backdoor, a modular post-exploitation framework designed to provide full control over compromised Exchange servers while minimizing reliance on conventional command-and-control infrastructure. Operators are assessed to connect directly to infected servers through Exchange web requests, an approach that supports stealth and complicates network-based detection. GhostContainer supports execution of shellcode and system commands, file download and file manipulation, and loading of additional .NET bytecode modules. Reported modules include web proxying and tunneling components, indicating an emphasis on covert operator access and flexible post-compromise operations. The malware’s modular architecture and the operators’ ability to adapt public code into an espionage-capable toolset indicate a skilled intrusion set focused on long-term access and operational concealment. The activity has been linked to targeting of high-value organizations, specifically government entities in Asia, and is consistent with espionage-oriented objectives rather than financially motivated crime. No high-confidence country-of-origin attribution is currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.