logo

New PLAYFULGHOST Malware Hacking Devices To Remotely Capture Audio Recordings

ID: 5e0b1494-2c18-50a8-8337-319c8028bd52

STIX ID: report--5e0b1494-2c18-50a8-8337-319c8028bd52

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2025-01-02

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

PLAYFULGHOST is a Gh0st RAT variant observed in phishing and SEO-poisoning campaigns that deliver malicious installers and archives; once executed it uses DLL search order hijacking and vulnerable renamed binaries to load payloads. The campaign uses multiple components (BOOSTWAVE, TERMINATOR, QAssist.sys, CHROMEUSERINFO.dll) to evade detection, maintain persistence via registry keys, scheduled tasks, startup items and services, and exfiltrate data including Chrome credentials, keystrokes, screenshots and audio.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.