GhOstRAT is a Windows-based remote access trojan (RAT). The provided content states that a "GhostRAT Loader" downloads and executes GhOstRAT on Windows, launches multiple background processes, deploys additional components as part of a staged infection chain, alters system configurations for persistence across reboots, and communicates with external servers to enable remote command execution or data exchange. The malware was reported as being deployed via exploitation of CVE-2024-23692, an unauthenticated remote code execution vulnerability in Rejetto HTTP File Server (HFS) 2.4.0 RC7 and 2.3m; ASEC observed attackers exploiting vulnerable HFS servers to install RATs including GhOstRAT for persistence. The content also notes a separate case in which China-linked hackers weaponized the Nezha RMM tool to deploy GhostRAT. A CYFIRMA YARA rule titled "Suspicious_Malware_Indicator_GhostRAT" is associated with a sample hash: b0521ad45fd21cdae26afdc74307870c5859421e049bbff2a545852b0ccf0fe6.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Listed under Discovery for Ndm448 and GhostRAT Loader; also referenced in narrative: “interaction with extensive registry structures…”.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows remote access trojan delivered by GhostRAT Loader; described as enabling stealthy background operation, persistence across reboots, and external communications consistent with remote command execution and/or data exchange (supporting monitoring and information theft).
Remote Access Trojan (RAT) deployed via weaponized Nezha RMM tool by China-linked threat actors.
Remote access trojan reportedly deployed after exploitation of CVE-2024-23692 in Rejetto HFS to establish persistence on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.