GhostWeaver RAT is a Windows remote access trojan observed on 2026-02-02 as the final payload in a KONGTUKE “ClickFix” intrusion chain that used legitimate but compromised websites to deliver injected JavaScript, redirect victims to a fake CAPTCHA page, and execute a clipboard-injected ClickFix script. In the documented activity, the infection chain led to MintsLoader and then GhostWeaver RAT. The malware was initially misidentified as AsyncRAT but later corrected to GhostWeaver RAT, with NETRESEC credited for the identification correction. High-confidence network behavior attributed to GhostWeaver RAT included repeated TLSv1.0 beaconing to 173.232.146[.]62:25658 and external IP discovery via api.ipify[.]org, checkip.dyndns[.]org, and ipinfo[.]io endpoints for city, region, and country. Related activity in the same intrusion included MintsLoader retrieval from .top domains such as sbwur1[.]top and gecdfcjcbcmmakk[.]top, and the pcap contained multiple failed DNS queries for numerous .top domains. Recovered artifacts from an infected Windows host included C:\Users[username]\AppData\Roaming\script.ps1, C:\Users[username]\AppData\Roaming\Microsoft\321fa94650293031791ed45e9ea6b1d2, C:\Users[username]\AppData\Local\rootCert_lock.pfx, and C:\Users[username]\AppData\Local\WindowsUpdateCertificate.pfx. Persistence-related artifacts included scheduled tasks named Google_Maintenance_Worker and Set-SmbServerConfiguration. The associated samples were distributed as password-protected ZIP files.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Originally, I'd thought the final malware was Async RAT, but it's actually GhostWeaver RAT.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan/backdoor observed as the final payload in this ClickFix infection chain; performs external IP discovery (e.g., api.ipify.org, checkip.dyndns.org, ipinfo.io) and communicates with a C2 over TLS.
Remote access trojan observed as the final payload in this ClickFix chain; performs external IP discovery/geo lookups (ipify, dyndns checkip, ipinfo) and communicates with a C2 over TLS (noted as TLSv1.0) on 173.232.146[.]62:25658.
Remote access trojan observed as the final payload in this ClickFix infection chain; performs external IP discovery (api.ipify.org, checkip.dyndns.org) and geolocation lookups (ipinfo.io) and communicates with a C2 over TLS (noted as TLSv1.0) on 173.232.146.62:25658.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.