GH0ST RAT
GH0ST RAT
C++
RAT
Threat IntelligenceMalwareDecember 7, 202515 min read

Gh0st RAT: Threat Intelligence Profile

Chinese-origin RAT with decades of use

Scroll

Gh0st RAT (also known as Gh0st RAT, Gh0stCringe, Gh0stTimes) is a C++-based remote access trojan active since 2008. Chinese-origin RAT with decades of use. Key capabilities include: remote desktop, keylogger, file manager, microphone, webcam, source code leaked 2008, still widely used by Chinese APTs.

Overview & Background

Chinese-origin RAT with decades of use. First observed in 2008, Gh0st RAT is attributed to Chinese APTs. The malware is written in C++ and provides operators with comprehensive remote access capabilities.

Active Threat

Gh0st RAT continues to be actively distributed and used in campaigns targeting organizations worldwide. Its capabilities include: remote desktop, keylogger, file manager, microphone, webcam, source code leaked 2008, still widely used by Chinese APTs.

Technical Capabilities

Distribution Methods

Gh0st RAT is typically distributed through phishing emails with malicious attachments, cracked software downloads, and malvertising campaigns. Common delivery mechanisms include Office macros, ISO/IMG containers, and script-based downloaders.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1566.001 Phishing AttachmentMalicious email attachments
ExecutionT1204.002 Malicious FileUser executes RAT payload
PersistenceT1547.001 Registry Run KeysAutostart persistence
Defense EvasionT1027 Obfuscated FilesPayload obfuscation
Credential AccessT1056.001 KeyloggingKeystroke capture
CollectionT1113 Screen CaptureScreenshot collection
CollectionT1125 Video CaptureWebcam access
C2T1071.001 Web ProtocolsHTTP/HTTPS C2 communication

Detection & Defense

Protect Against Remote Access Trojans

Mjolnir Security provides comprehensive detection and response capabilities against Gh0st RAT and similar RAT threats.

RAT DetectionEndpoint SecurityThreat HuntingIncident ResponseMDR Services
  • RAT Detection & Removal Identify and remediate Gh0st RAT infections including persistence mechanisms and lateral movement artifacts.
  • Threat Intelligence Continuous monitoring for Gh0st RAT campaigns and infrastructure targeting your organization.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: December 7, 2025