Malware.View on attack.mitre.org
gh0st RAT is a remote access tool (RAT). The source code is public and it has been used by multiple groups.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
gh0st RAT has checked for the existence of a Service key to determine if it has already been installed on the system. |
| T1055 Process Injection |
gh0st RAT can inject malicious code into process created by the “Command_Create&Inject” function. |
| T1056.001 Keylogging |
gh0st RAT has a keylogger. |
| T1057 Process Discovery |
gh0st RAT has the capability to list processes. |
| T1059 Command and Scripting Interpreter |
gh0st RAT is able to open a remote shell to execute commands. |
| T1070.004 File Deletion |
gh0st RAT has the capability to to delete files. |
| T1082 System Information Discovery |
gh0st RAT has gathered system architecture, processor, OS configuration, and installed hardware information. |
| T1095 Non-Application Layer Protocol |
gh0st RAT has used an encrypted protocol within TCP segments to communicate with the C2. |
| T1105 Ingress Tool Transfer |
gh0st RAT can download files to the victim’s machine. |
| T1106 Native API |
gh0st RAT has used the `InterlockedExchange`, `SeShutdownPrivilege`, and `ExitWindowsEx` Windows API functions. |
| T1112 Modify Registry |
gh0st RAT has altered the InstallTime subkey. |
| T1113 Screen Capture |
gh0st RAT can capture the victim’s screen remotely. |
| T1129 Shared Modules |
gh0st RAT can load DLLs into memory. |
| T1132.001 Standard Encoding |
gh0st RAT has used Zlib to compress C2 communications data before encrypting it. |
| T1140 Deobfuscate/Decode Files or Information |
gh0st RAT has decrypted and loaded the gh0st RAT DLL into memory, once the initial dropper executable is launched. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.