- Blue Coat Selects Norman Shark As Malware Analysis Technology Partner
- Norman Shark to Announce Malware Analyzer G2 v4.0 and Updated Network Threat Discovery at Black Hat 2013
- Norman Shark Cyber Research Report Uncovers First Large Cyber Espionage Activity Emanating From India
- Norman Shark to Launch Norman Shark Network Protection Solution at RSA, Demos to be Available
- Norman AS splits company to maximize revenue
- Long Shadow Of Stuxnet Inspires Custom Anti-Malware Project
- Defense In Depth Enables Protection Of Critical Pipeline Assets
- Norman Shark to Sponsor Third Annual Securing Our eCity Cybersecurity Symposium 2012
- Study Shows Israel and Palestinian Territories under Cyber Attack from Same Source for More Than One Year
- Systematic cyber attacks against Israeli and Palestinian targets going on for a year
- Protecting Today’s SCADA-Based Mass Transit Systems Should Begin with a Defense-in-Depth
- The Wake Up Call: Hackers are Reported to have Caught the World’s Major Oil and Gas Companies Napping
- Norman Shark Malware Analyzer G2 Is Industry’s Most Flexible and Powerful Platform for Cyber Threat Discovery and Assessments
- Norman Shark Presents New Episode of Video Series to Continue Focus on Cybercrime Prevention among Executives
- Norman Shark Named as a Gartner “Vendor to Watch” in New Market Trends Report, Cites Norman Shark Network Threat Discovery and Malware Analyzer G2 Network Protection Solutions
- Norman Shark is shifting its U.S. headquarters from Washington, D.C., to San Diego
- Web security firm beefs up San Diego operation
- The Many Faces of Gh0st Rat
- Norman Shark Malware Analyzer G2 Is Industry’s Most Flexible and Powerful Platform for Cyber Threat Discovery and Assessments
- Norman Shark Announces SCADA Security OEM Partnership with Kongsberg Maritime to Protect Critical Oil, Gas and Maritime Industrial Environments Globally
- Norman Shark Customers Secured Against Flamer
The Many Faces of Gh0st Rat
Plotting the connections between malware attacks.
Snorre Fagerland, Principal Security Researcher
Norman SharkA
Introduction
Gh0st Rat is a well-known Chinese remote access trojan which was originally made by C.Rufus Security Team several years ago. Just as with other well-featured “off-the-shelf” trojans like Poison Ivy, Hupigon and DarkComet it has been used by all sorts of people – from the script kiddie next door to resourceful targeted attack actors (1)
Cybercriminals use off-the-shelf malware not only because it’s easy and cheap. They also use it because it’s hard to track. Anybody could use this malware, so the criminal could be anybody. However, this changes somewhat when they start modifying the code. The malware now becomes somewhat attributable and can be connected to known cases and criminal groups. This document is the result of examining selected common traits between some 1200+ Gh0st Rat program files (samples) with the help of Maltego, a tool to visualize data connections. The samples were processed by us in a timeframe of approximately six months, from August 2011 to February 2012.
In this study we attempt to map out what logical connections do exist between different Gh0st botnet campaigns. This is important because it gives an indication of the scale of operation and sometimes what the aims of the campaigns are, and this can be valuable for risk analysis. Additional data produced by the study may be used for risk mitigation.
Stein Surlien, CEO Norman Shark Mob:+ 47 911 16 240 Email: stein.surlien@norman.com Isabella Alveberg, CMO Norman Shark Mob:+ 47 957 30 578 Email: isabella.alveberg@norman.comContact Information

