logo

GHOSTPULSE haunts victims using defense evasion bag o' tricks

ID: 9af685b3-9d52-598c-aa6b-043166ba88ac

STIX ID: report--9af685b3-9d52-598c-aa6b-043166ba88ac

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2023-10-27

Date Updated: 2026-04-27

...
...

Elastic Security Labs documents the GHOSTPULSE campaign that uses signed MSIX installers and sideloading to deliver a multi-stage, stealthy loader which decrypts and injects final payloads (information-stealers and RATs). The report provides a stage-by-stage technical analysis (PowerShell/GPG dropper, side-loaded DLL extracting encrypted blobs, module stomping, NT syscall invocation, process doppelgänging), associated IOCs (domains, IPs, file hashes, code signers), detection guidance, and a configuration extractor for researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.