gh0st RAT

S0032

Malware.View on attack.mitre.org

About this malware

gh0st RAT is a remote access tool (RAT). The source code is public and it has been used by multiple groups.

Techniques used24

Procedure examples24

TechniqueProcedure example
T1012
Query Registry

gh0st RAT has checked for the existence of a Service key to determine if it has already been installed on the system.

T1055
Process Injection

gh0st RAT can inject malicious code into process created by the “Command_Create&Inject” function.

T1056.001
Keylogging

gh0st RAT has a keylogger.

T1057
Process Discovery

gh0st RAT has the capability to list processes.

T1059
Command and Scripting Interpreter

gh0st RAT is able to open a remote shell to execute commands.

T1070.004
File Deletion

gh0st RAT has the capability to to delete files.

T1082
System Information Discovery

gh0st RAT has gathered system architecture, processor, OS configuration, and installed hardware information.

T1095
Non-Application Layer Protocol

gh0st RAT has used an encrypted protocol within TCP segments to communicate with the C2.

T1105
Ingress Tool Transfer

gh0st RAT can download files to the victim’s machine.

T1106
Native API

gh0st RAT has used the `InterlockedExchange`, `SeShutdownPrivilege`, and `ExitWindowsEx` Windows API functions.

T1112
Modify Registry

gh0st RAT has altered the InstallTime subkey.

T1113
Screen Capture

gh0st RAT can capture the victim’s screen remotely.

T1129
Shared Modules

gh0st RAT can load DLLs into memory.

T1132.001
Standard Encoding

gh0st RAT has used Zlib to compress C2 communications data before encrypting it.

T1140
Deobfuscate/Decode Files or Information

gh0st RAT has decrypted and loaded the gh0st RAT DLL into memory, once the initial dropper executable is launched.

View all 24 procedure examples

Groups that use it11

Campaigns1

References3

  1. Arbor Musical Chairs Feb 2018 Open source
    Sabo, S. (2018, February 15). Musical Chairs Playing Tetris. Retrieved February 19, 2018.
  2. FireEye Hacking Team Open source
    FireEye Threat Intelligence. (2015, July 13). Demonstrating Hustle, Chinese APT Groups Quickly Use Zero-Day Vulnerability (CVE-2015-5119) Following Hacking Team Leak. Retrieved January 25, 2016.
  3. Nccgroup Gh0st April 2018 Open source
    Pantazopoulos, N. (2018, April 17). Decoding network data from a Gh0st RAT variant. Retrieved November 2, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.