Gh0st RAT is a long-running Windows remote access trojan associated with Chinese intrusion activity and historically linked to the GhostNet espionage campaign. Public reporting places its origins around 2008 and ties its development to the C. Rufus Security Team. Over time, multiple threat actors and derivative malware families have reused or borrowed from its source code, making Gh0st RAT both a distinct malware family and a code lineage seen in later China-nexus operations.
Gh0st RAT functions as a backdoor and remote administration implant that enables sustained control of compromised systems. Reported variants support persistence and remote command-and-control, and more recent observed samples have used multi-stage loading, dynamic API resolution, and in some cases domain-generation-based command-and-control to complicate detection and infrastructure tracking. In contemporary intrusions, Gh0st RAT has been deployed after attackers established access through web compromise chains involving exposed administrative applications, log poisoning, web shells, and follow-on tooling such as AntSword and Nezha. In those cases, operators also modified Microsoft Defender settings before installing the RAT to improve execution and persistence.
The malware has appeared in campaigns attributed or tentatively linked to China-nexus actors, including operations targeting Tibetan communities and broader intrusions affecting organizations in East and Southeast Asia. It has also been referenced in activity associated with the cluster tracked as Phantom Taurus, where deployed backdoors were assessed to likely borrow from Gh0st RAT source code. Victimology observed alongside recent Gh0st RAT deployments includes systems in Taiwan, Japan, South Korea, and Hong Kong, consistent with espionage-oriented targeting patterns rather than commodity cybercrime alone.
Gh0st RAT remains notable because of its longevity, adaptability, and continued operational relevance. Even when not deployed in its original form, its codebase and protocol characteristics continue to surface in modern backdoors used by China-aligned operators for persistent remote access and post-compromise control on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“...deploying backdoors that very likely borrowed source code from Ghost RAT, a Trojan developed by Chinese threat actor C. Rufus Security Team. Ghost RAT appears to date to 2008...”
“...deploying backdoors that very likely borrowed source code from Ghost RAT, a Trojan developed by Chinese threat actor C. Rufus Security Team. Ghost RAT appears to date to 2008...”
"SilverFox activity: Antiy says the SilverFox (YouSnake) group infected over 17,000 users with the Ghost RAT..."
"SilverFox activity: Antiy says the SilverFox (YouSnake) group infected over 17,000 users with the Ghost RAT..."
10 distinct techniques documented for this family, organized by ATT&CK tactic.
All WinApi functions are resolved dynamically using GetProcAddress and are stored into a large function table which is trivially reassembled.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ghost RAT6
Ghost RAT6
Huntress Uncovers Log Poisoning Campaign Linking Nezha and Ghost RAT in Widespread Asian Cyber Intrusions
Remote Access Trojan deployed via Nezha to provide persistent remote access and control over compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.