Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the final stage downloaded: ghost.js on Unix machines, or ghost.npl on Windows workstations ... The first thing we notice is the getSystemInfo() function, which sweeps the system for basic information such as the hostname, release name, platform, IP address, and MAC address. It then builds a string with that information and sends it to the C2 server to register the victim host.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
It made its way to us through an old classic excuse: a job offer targeting Alex, one of our developers. He played along with the fake job interview and, in the end, was given a repository as part of a coding challenge, which he then shared with us to investigate.
Oh no! The code is heavily obfuscated... they’re using the same obfuscation technique they’ve been using for the last three years.
One of the strings reveals the C2 server address and endpoint... It then builds a string with that information and sends it to the C2 server to register the victim host.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.