logo

Digital Doppelgangers: Anatomy of Evolving Impersonation Campaigns Distributing Gh0st RAT

ID: 3cb85d7b-a5bf-5234-821f-1f66451f9351

STIX ID: report--3cb85d7b-a5bf-5234-821f-1f66451f9351

Feed Name: Palo Alto Networks Unit 42

Threat Score
78/100

Date Published: 2025-11-14

Date Updated: 2026-04-28

Author: Keerthiraj Nagaraj, Vishwa Thothathri, Nabeel Mohamed and Reethika Ramesh

...
...

Executive Summary: This report details two interconnected 2025 malware campaigns that used large-scale brand impersonation and thousands of disposable domains to distribute Gh0st RAT to Chinese-speaking users. Campaign Trio (Feb–Mar) relied on mass-registered domains serving trojanized MSI/EXE installers from centralized hosting, while Campaign Chorus (May onward) evolved to multi-stage droppers, VBScript assemblers, cloud-hosted payloads and DLL side‑loading to evade defenses; the report provides TTP mapping to MITRE ATT&CK, infrastructure and IoCs (IPs, domains, file hashes), and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.