SugarGh0st RAT Targets U.S. Artificial Intelligence Experts
ID: 7b011470-3314-5858-a4b2-5a2228b7e6b6
STIX ID: report--7b011470-3314-5858-a4b2-5a2228b7e6b6
Feed Name: securityonline.info
Proofpoint discovered UNK_SweetSpecter, a May 2024 campaign delivering a SugarGh0st Remote Access Trojan to U.S. AI researchers via ZIP attachments containing LNK shortcut files that launch JavaScript droppers; the multi-stage chain abuses ActiveX sideloading and shellcode to deploy an XOR/aplib-compressed payload that enables keylogging, C2 communications, and data exfiltration, with active C2 domains and IPs observed and linguistic artifacts pointing to Chinese-speaking operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
