SecOps Ghost is a Windows-focused Python-based covert host-monitoring and reconnaissance toolset. Variants enumerate running processes, network-adapter configuration, startup entries, local TCP ports, and registry-based startup information. Collected telemetry is serialized and encrypted, commonly with AES-CBC, then either stored locally in an encrypted database or transmitted periodically through HTTP-based or messaging-service channels. The framework includes packers that encode the collector source and execute the decoded payload in memory, with junk-code generation to vary packed output. Reported versions implement concealed console and subprocess execution, exception suppression, debugger and virtual-machine detection, uptime and timing checks, and randomized collection intervals. Persistence mechanisms include Startup-folder copying, current-user Run-key modification, and scheduled tasks configured to run at system startup; some variants also attempt Fodhelper-based UAC bypass for elevation. SecOps Ghost has been presented as an audit or monitoring utility, but its stealth, anti-analysis, persistence, privilege-escalation, encrypted telemetry, and covert reconnaissance features are consistent with spyware-style host-surveillance functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
ghost_packer.py — автоматический обфусциратор... Переводит исходный текст ядра в массив случайных символов Base64... Финальный файл ghost_packed.py содержит только Base64 строку
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python-based, purportedly fileless Windows monitoring implant/toolset. Its core component performs anti-analysis checks for debuggers, virtual-machine artifacts, short system uptime, and sandbox time manipulation; hides its console; executes ipconfig, tasklist, and reg query commands covertly; and repeatedly sends collected host telemetry to an HTTP endpoint. A companion packer applies randomized XOR encoding and junk-code insertion before executing decrypted source in memory. The described behavior is consistent with a stealthy discovery and telemetry-collection backdoor, notwithstanding its claimed SecOps/Green Team purpose.
Windows-focused Python surveillance/backdoor framework that enumerates network configuration, running processes, and startup entries; encrypts and Base64-encodes the collected telemetry; and sends it to operator-controlled Telegram, webhook, or web-server infrastructure. It uses XOR packing with junk-code polymorphism, a fodhelper.exe UAC-bypass technique, hidden-window PowerShell/WMI execution, and SYSTEM-level scheduled-task persistence under names such as WinSecAuditTask.
A Python-based stealth surveillance/backdoor toolkit. It performs host reconnaissance by enumerating local TCP ports and running processes; periodically exfiltrates the results as AES-CBC-encrypted, Base64-encoded Telegram messages; uses XOR packing, junk code, and in-memory execution for obfuscation; attempts Windows Startup-folder persistence; and uses registry hijacking with fodhelper.exe to attempt UAC bypass and elevated execution.
Python-based covert reconnaissance and data-exfiltration implant. It scans localhost ports 1–1024, enumerates running processes, serializes the results to JSON, encrypts them with AES-256-CBC, Base64-encodes the output, and exfiltrates it using Telegram Bot API requests. It includes a CPU-intensive timing check intended to evade sandbox analysis, randomized execution intervals, XOR packing with junk code for obfuscation, and Startup-folder persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.