GHOSTSPIDER is a modular Windows backdoor used in cyber-espionage intrusions targeting telecommunications organizations, including Southeast Asian providers. It has been associated with activity attributed to the China-linked Earth Estries cluster, which is also tracked in some reporting as Salt Typhoon, although attribution relationships among these labels are not uniformly established. GHOSTSPIDER uses TLS-protected command-and-control communications and employs a staged architecture: a DLL search-order hijacking stager obtains and executes further payloads, including beacon loaders and task-specific modules. Components can be loaded in memory, reducing persistent forensic artifacts. Observed deployment and execution methods include proxy execution through Regsvr32, installation of an initial DLL stager as a service, and scheduled-task execution of a beacon loader and encrypted .NET payload. Its protocol supports file-transfer and operational control functions, including upload, write, close, heartbeat, and update-interval commands.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2022-3236 A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
We have observed them exploiting server-based N-day vulnerabilities, including the following: Ivanti Connect Secure VPN Exploitation (CVE-2023-46805 and CVE-2024-21887) A chain of exploits to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges.
We have observed them exploiting server-based N-day vulnerabilities, including the following: CVE-2023-48788 Fortinet FortiClient EMS SQL Injection Vulnerability
We have observed them exploiting server-based N-day vulnerabilities, including the following: Ivanti Connect Secure VPN Exploitation (CVE-2023-46805 and CVE-2024-21887) A chain of exploits to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges.
ProxyLogon (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) A set of four chained vulnerabilities that perform remote code execution (RCE) in Microsoft Exchange servers.
ProxyLogon (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) A set of four chained vulnerabilities that perform remote code execution (RCE) in Microsoft Exchange servers.
ProxyLogon (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) A set of four chained vulnerabilities that perform remote code execution (RCE) in Microsoft Exchange servers.
ProxyLogon (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) A set of four chained vulnerabilities that perform remote code execution (RCE) in Microsoft Exchange servers.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GHOSTSPIDER is a multi-modular backdoor that uses TLS-secured communication protocol to connect with the C2 server. It begins with a stager deployed using DLL search order hijacking which then receives and executes additional payloads such as beacon loaders and additional modules.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
They execute a multi-stage infection chain involving batch files or PowerShell scripts to deploy encrypted payloads, such as DEMODEX rootkit and GHOSTPSIDER backdoor, and MASOL RAT.
They execute a multi-stage infection chain involving batch files or PowerShell scripts to deploy encrypted payloads.
Encrypted configurations and shellcode are stored in registry keys, while reflective loaders decrypt and execute these components in memory, evading detection.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated multi-modular backdoor used for long-term espionage. It uses staged deployment, DLL/service installation, in-memory module loading, TLS-protected custom C2 communications, and modular beacon functionality for flexible post-compromise operations.
Backdoor or payload executed via regsvr32 proxy execution.
Backdoor reportedly developed for telecom networks and deployed by Salt Typhoon on servers outside network devices.
A backdoor used by the threat actor(s) as part of their C2 infrastructure to maintain covert access to victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.