Attackers have been distributing the Gh0stCringe remote access trojan, also tracked as CirenegRAT, through vulnerable MS-SQL and MySQL database servers exposed to brute-force attacks, dictionary attacks, or exploitation of unpatched flaws. The malware is linked to the same poorly secured server ecosystem that has also seen infections from KingMiner and Vollgar, indicating continued abuse of internet-facing database infrastructure for malware deployment and persistence.
Gh0stCringe is a feature-rich backdoor derived partly from the leaked Gh0st RAT source code and supports keylogging, host reconnaissance, payload download and execution, clipboard theft, modular proxy or plugin loading, and even MBR destruction. It uses a custom command-and-control protocol identified by the signature string xy , gathers detailed host and security-product information, stores XOR-encoded keystrokes in %SystemDirectory%\Default.key, and has been detected by AhnLab V3 as Backdoor/Win.Gh0stRAT variants.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Gh0stCringe, also known as CirenegRAT, was first discovered in December 2018 according to the AhnLab report.
AhnLab reported observing Gh0stCringe being distributed to vulnerable MS-SQL and MySQL database servers, with logs tied to sqlservr.exe and MySQL server processes on Windows. The activity was assessed as targeting poorly managed database servers with weak credentials or unpatched vulnerabilities.
Before the database-server activity described in the report, Gh0stCringe had been known to spread through an SMB vulnerability using the ZombieBoy SMB exploitation tool.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.