ATT&CKReferencesNccgroup Gh0st April 2018

Nccgroup Gh0st April 2018

Pantazopoulos, N. (2018, April 17). Decoding network data from a Gh0st RAT variant. Retrieved November 2, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1059
Command and Scripting Interpreter
Malwaregh0st RAT

gh0st RAT is able to open a remote shell to execute commands.

T1105
Ingress Tool Transfer
Malwaregh0st RAT

gh0st RAT can download files to the victim’s machine.

T1113
Screen Capture
Malwaregh0st RAT

gh0st RAT can capture the victim’s screen remotely.

T1543.003
Windows Service
Malwaregh0st RAT

gh0st RAT can create a new service to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
Malwaregh0st RAT

gh0st RAT has added a Registry Run key to establish persistence.

T1573.001
Symmetric Cryptography
Malwaregh0st RAT

gh0st RAT uses RC4 and XOR to encrypt C2 traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.