logo

'SneakyChef' APT Slices Up Foreign Affairs With SugarGh0st

ID: 16a153a7-6813-5dab-83d0-6d91802d9f75

STIX ID: report--16a153a7-6813-5dab-83d0-6d91802d9f75

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-06-21

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Cisco Talos uncovered a Chinese-language APT operator called "SneakyChef" running espionage campaigns since late August using modified Gh0st RAT (SugarGh0st) and a newer implant (SpiceRAT) to target foreign ministries, agricultural ministries, and an embassy across multiple countries. The actor has moved from LNK-wrapped RARs to self-extracting RAR lures that drop decoy government documents, a DLL loader, encrypted malware, and VB persistence scripts—decoys appear legitimate and may have been obtained via prior espionage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.