logo

SugarGh0st RAT Targets U.S. Artificial Intelligence Experts

ID: 7b011470-3314-5858-a4b2-5a2228b7e6b6

STIX ID: report--7b011470-3314-5858-a4b2-5a2228b7e6b6

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2024-05-17

Date Updated: 2026-04-22

Author: do son

...
...

Proofpoint discovered UNK_SweetSpecter, a May 2024 campaign delivering a SugarGh0st Remote Access Trojan to U.S. AI researchers via ZIP attachments containing LNK shortcut files that launch JavaScript droppers; the multi-stage chain abuses ActiveX sideloading and shellcode to deploy an XOR/aplib-compressed payload that enables keylogging, C2 communications, and data exfiltration, with active C2 domains and IPs observed and linguistic artifacts pointing to Chinese-speaking operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.