FinGhost is a Chinese-speaking threat actor associated with opportunistic intrusions in East Asia and linked in prior reporting to use of the Zegost malware family. Activity associated with this actor overlaps with the DragonSpark intrusion cluster, which has been assessed with high confidence as operated by a Chinese-speaking actor but has not been conclusively tied to a single publicly established group. The actor has targeted Internet-exposed web servers and MySQL servers for initial access, followed by deployment of webshells, remote access tooling, and custom malware. Observed tradecraft includes use of China Chopper webshells, SparkRAT for persistent remote access, Meterpreter for post-compromise control, and multiple open-source tools associated with Chinese-speaking developers. The actor has used privilege-escalation utilities such as SharpToken and BadPotato, remote administration tooling such as GotoHTTP, and custom loaders including a Python-based shellcode loader and a Golang-based loader that interprets embedded Golang source code at runtime through Yaegi to complicate static analysis and improve defense evasion. Post-compromise behavior has included privilege escalation, lateral movement, malware deployment, remote command execution, and information theft capabilities exposed through SparkRAT and related tooling. Available reporting supports Chinese-speaking operational characteristics and infrastructure overlap consistent with operators based in or linked to China. The actor’s ultimate objective has not been conclusively established, with available evidence supporting either espionage or cybercrime, so a single dominant motivation cannot be assigned with high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.