Malware

Ghost RAT

Also known as: Farfli · Gh0st RAT · PCRat

According to Security Ninja, Gh0st RAT (Remote Access Terminal) is a trojan “Remote Access Tool” used on Windows platforms, and has been used to hack into some of the most sensitive computer networks on Earth. Below is a list of Gh0st RAT capabilities. Take full control of the remote screen on the infected bot. Provide real time as well as offline keystroke logging. Provide live feed of webcam, microphone of infected host. Download remote binaries on the infected remote host. Take control of remote shutdown and reboot of host. Disable infected computer remote pointer and keyboard input. Enter into shell of remote infected host with full control. Provide a list of all the active processes. Clear all existing SSDT of all existing hooks.

Indicators of Compromise 30

MITRE ATT&CK TTPs 33

Source Articles

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
A malware campaign attributed to the Chinese threat cluster Silver Fox (aka Yinhu) is distributing malicious fake software installers through spoofed vendor websites, primarily targeting Chinese-speaking users and multinational organizations in China. The installers deploy Gh0st RAT and ValleyRAT, which disable Windows Update services, weaken Microsoft Defender, and establish command-and-control communication via non-standard ports. The payloads use DLL sideloading and masquerade as legitimate installers to bypass security controls, enabling keystroke logging, clipboard theft, and remote system control.
hacker-news ·3h ago
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
The Chinese cybercrime group SilverFox targeted a Japanese industrial manufacturing organization using a sophisticated attack chain involving a three-driver BYOVD (Bring Your Own Vulnerable Driver) technique for kernel-level access and defense evasion. The attack began with a phishing email containing an invoice-themed lure, leading to DLL side-loading via malicious ZIP archives that deploy ValleyRAT, a Gh0st RAT variant. The malware uses multiple persistence and recovery mechanisms, including NTDLL unhooking, process injection, and a dual watchdog system to maintain remote access and resist removal.
hacker-news ·4w ago
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
A threat actor cluster known as CylindricalCanine, linked to the broader GoldenEyeDog (APT-Q-27) group, was responsible for a breach at DigiCert in April 2026. The attackers compromised support analysts via a malicious .scr file delivered through a customer support chat, gaining access to initialization codes and stealing code-signing certificates. These certificates were then used to sign malware, including Zhong Stealer and Golden Gh0st RAT, enabling evasion of security detection. The group primarily targets finance organizations in the Asia-Pacific region using phishing and DLL side-loading techniques.
hacker-news ·1mo ago
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
The China-linked threat actor Silver Fox has been linked to a new Rust-based remote access trojan (RAT) named MODBEACON. This malware leverages gRPC streaming and reuses transport layers from the open-source Xray/V2Ray framework for encrypted command-and-control (C2) communications. It targets technology, education, and state-owned enterprises in Asia via counterfeit software installers distributed through SEO poisoning, enabling long-term access with capabilities including plugin loading, persistence, and data exfiltration.
hacker-news ·1mo ago