Netskope Threat Labs

Ghost RAT

ATP Sandbox Adv. Heuristics

Ghost RAT is an alternate detection name for Gh0st RAT, a remote access trojan that has circulated since the late 2000s and remains active in campaigns today. The trojan gives operators remote desktop viewing, file and process management, keystroke capture, and payload downloads on infected Windows systems. Its leaked source code spawned countless variants, and both state sponsored and criminal actors have used the family for espionage and commodity intrusions.

First seen
May 2023
Last seen
October 2026
GhostRATGhostRatGhostrat
Alert Name
Android.Backdoor.GhostRAT
ByteCode-MSIL.Backdoor.Ghostrat
Script-JS.Backdoor.GhostRAT
Win32.Backdoor.GhostRAT
Win32.Downloader.GhostRAT
Win32.Trojan.GhostRat
Win32.Trojan.GhostRAT
Win64.Backdoor.GhostRAT