Gh0stRAT malware family
Gh0stRAT is a malware family tracked by MalwareAnalyzer by Cyble across 3 publicly analyzed samples. First seen 2026-08-14, most recently 2026-08-16. Observed ATT&CK techniques include T1071.001, T1056.001, T1057.
Corpus statistics
- Publicly analyzed samples: 3
- First seen: 2026-08-14
- Last seen: 2026-08-16
- Verdicts: malicious 3
- File types: pe 3
ATT&CK techniques used by Gh0stRAT
Recent Gh0stRAT samples
- 0db86074ffe79db8018fce56819b50748ea822defb132377248c51343e2ec903 - malicious (2026-08-16)
- 39dbb39daeee65821ae18be140e9216e0abfd779a3f83d800a44f51944abb810 - malicious (2026-08-14)
- 1de862ad0ecdc1785f4706e3ae7caaa65b781cbf7ac572f2b1b7f5becd1ad3fc - malicious (2026-08-14)
Frequently asked about Gh0stRAT
- What is Gh0stRAT?
- Gh0stRAT is a malware family tracked by MalwareAnalyzer by Cyble across 3 publicly analyzed samples. First seen 2026-08-14, most recently 2026-08-16. Observed ATT&CK techniques include T1071.001, T1056.001, T1057.
- How many Gh0stRAT samples have been analyzed?
- MalwareAnalyzer by Cyble holds 3 publicly analyzed samples attributed to Gh0stRAT, first seen 2026-08-14 and most recently 2026-08-16. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Gh0stRAT use?
- Across our Gh0stRAT samples the most frequently observed techniques are T1071.001 (2), T1056.001 (1), T1057 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Gh0stRAT use?
- Gh0stRAT samples in this corpus are distributed as pe (3).
- Is Gh0stRAT malicious?
- 3 of 3 analyzed Gh0stRAT samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends