SugarGh0st RAT is a Windows remote-access trojan used by the suspected China-based threat actor SweetSpecter. It has been delivered through spear-phishing emails containing ZIP archives that use an LNK-file lure displaying a decoy document while decrypting and executing the malware in the background. SugarGh0st RAT enables operators to control compromised systems, execute arbitrary commands, capture screenshots, and exfiltrate data. SweetSpecter used this delivery chain in attempted targeting of OpenAI employees and has been associated with cyber-espionage activity against government and political entities in Asia, Africa, and the Middle East.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SweetSpecter also targeted OpenAI employees with spear-phishing messages carrying SugarGh0st RAT.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan delivered through spear-phishing messages targeting OpenAI employees in the reported SweetSpecter activity.
Remote access trojan (RAT) used for cyber-espionage, providing persistent backdoor access to compromised systems.
Remote access trojan (RAT) used for persistent access and control of compromised systems.
A remote access trojan used in the SweetSpecter spear-phishing campaign. It is delivered via a malicious ZIP/LNK attachment, then decrypted and executed to provide control of the compromised Windows machine, including arbitrary command execution, screenshot capture, and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.