Description
Ghost RAT is an alternate detection name for Gh0st RAT, a remote access trojan that has circulated since the late 2000s and remains active in campaigns today. The trojan gives operators remote desktop viewing, file and process management, keystroke capture, and payload downloads on infected Windows systems. Its leaked source code spawned countless variants, and both state sponsored and criminal actors have used the family for espionage and commodity intrusions.
Stats
- First seen
- May 2023
- Last seen
- October 2026
Also known as
GhostRATGhostRatGhostrat
Alert name variants
| Alert Name |
|---|
| Android.Backdoor.GhostRAT |
| ByteCode-MSIL.Backdoor.Ghostrat |
| Script-JS.Backdoor.GhostRAT |
| Win32.Backdoor.GhostRAT |
| Win32.Downloader.GhostRAT |
| Win32.Trojan.GhostRat |
| Win32.Trojan.GhostRAT |
| Win64.Backdoor.GhostRAT |