As with all Gh0st RAT variants, the capability of the malware is handled through plugins and an internal module dispatcher.The final stage is Golden Gh0st RAT, which comes with a wide array of capabilities to set up persistence, steal sensitive data, start a SOCKS proxy tunnel, suppress display output, log keystrokes, take screenshots, enumerate processes, execute shell commands, drop additional payloads, and clear Windows Event logs. Some of the applications it specifically targets for data collection include Skype, Google Chrome, Mozilla Firefox, 360 Secure Browser, 360 Speed Browser, and Tencent QQ Browser.
Very despicable behavior and capabilities, this RAT.
The attack starts as submitted screenshots to support personel.
Last edited by a moderator:
