Actionable Intelligence for Malware Defense.

News & Events » Press Releases » The Many Faces of Gh0st Rat
Press Releases

The Many Faces of Gh0st Rat

Plotting the connections between malware attacks.

Snorre Fagerland, Principal Security Researcher

Norman SharkA

Introduction

Gh0st Rat is a well-known Chinese remote access trojan which was originally made by C.Rufus Security Team several years ago. Just as with other well-featured “off-the-shelf” trojans like Poison Ivy, Hupigon and DarkComet it has been used by all sorts of people – from the script kiddie next door to resourceful targeted attack actors (1)

Cybercriminals use off-the-shelf malware not only because it’s easy and cheap. They also use it because it’s hard to track. Anybody could use this malware, so the criminal could be anybody. However, this changes somewhat when they start modifying the code. The malware now becomes somewhat attributable and can be connected to known cases and criminal groups. This document is the result of examining selected common traits between some 1200+ Gh0st Rat program files (samples) with the help of Maltego, a tool to visualize data connections. The samples were processed by us in a timeframe of approximately six months, from August 2011 to February 2012.

In this study we attempt to map out what logical connections do exist between different Gh0st botnet campaigns. This is important because it gives an indication of the scale of operation and sometimes what the aims of the campaigns are, and this can be valuable for risk analysis. Additional data produced by the study may be used for risk mitigation.

Contact Information

Stein Surlien, CEO Norman Shark

Mob:+ 47 911 16 240 Email: stein.surlien@norman.com

Isabella Alveberg, CMO Norman Shark

Mob:+ 47 957 30 578  Email: isabella.alveberg@norman.com

“In today’s climate of persistent threats, network defense alone is no longer enough. In order to protect networks from the proliferation of targeted attacks and unknown threats, analysts need dynamic malware intelligence capabilities that allow them to respond quickly in the event of an incursion.”