Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
RAT

Gh0st RAT

RAT 15 detections found

Also known as: Ghost RAT, Gh0stRAT, Mydoor, Moudoor

Gh0st RAT is a Windows remote access trojan whose source code, originally developed by the C. Rufus Security Team, was leaked publicly around 2008 and has since been adopted and customized by numerous China-linked and other espionage-focused threat actors. It provides remote shell access, keylogging, webcam/microphone capture, and full remote control over an encrypted, compressed C2 channel. Customized derivatives remain active today: Cisco Talos and Proofpoint have both tracked "SugarGh0st RAT," a modified Gh0st variant used since 2023 against government targets in Uzbekistan and South Korea and, in 2024, against U.S. artificial-intelligence researchers.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules