SugarGh0st is a remote-access trojan (RAT) associated with suspected China-based cyber-espionage activity. It has been used by the SweetSpecter threat actor in spear-phishing operations, including attempts targeting OpenAI personnel. In those operations, malicious ZIP attachments disguised as support requests initiated an infection chain that installed SugarGh0st on victim systems. SugarGh0st has also been associated with campaigns attributed to SneakyChef targeting government entities in Asia and the Europe, Middle East, and Africa region. Earlier activity has targeted artificial-intelligence researchers, indicating intelligence collection interest in AI expertise and related policy or technology sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SweetSpecter, a suspected China-based adversary ... has also been observed conducting unsuccessful spear-phishing attempts against OpenAI employees to deliver the SugarGh0st RAT.
“…SneakyChef, targeted government entities in Asia and EMEA with SugarGh0st malware…” | ...SneakyChef, targeted government entities in Asia and EMEA with SugarGh0st malware...
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned solely as background concerning prior attacks on AI researchers; the content provides no behavioral or technical details.
Mentioned only as prior activity targeting AI researchers; the content provides no further behavioral details.
Remote access trojan dropped via spear-phishing ZIP attachments as part of an infection chain attributed to the SweetSpecter cluster.
A remote access trojan used in spear-phishing attempts to gain access to victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.