logo

US AI Experts Targeted in SugarGh0st RAT Campaign

ID: 1795fe08-dc00-5a8e-97d4-88f0e53d8c1d

STIX ID: report--1795fe08-dc00-5a8e-97d4-88f0e53d8c1d

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-05-16

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Proofpoint and Cisco Talos observed a highly targeted espionage campaign (UNK_SweetSpecter) leveraging a customized Gh0st RAT variant called SugarGh0st to steal generative-AI-related information from fewer than ten US AI experts; the attack used AI-themed phishing with a zipped shortcut that deployed a JavaScript dropper, ActiveX sideloading, and an encrypted payload that ultimately connected to attacker-controlled C2 infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.