Gh0stBins is a modular remote access trojan (RAT) first documented by Qihoo 360’s Netlab in late 2019 as an evolution of the classic Gh0st RAT family. It is operated by the Chinese state-sponsored threat group TA428 (also tracked as Tonto Team or APT41) and functions as a second-stage payload to establish persistent backdoor access. The malware’s name derives from its use of binary containers (bins) to load encrypted plugins, enabling it to dynamically extend capabilities at runtime.
Gh0stBins propagates via spear-phishing emails containing malicious Microsoft Office documents that drop a loader, which then retrieves the core RAT from a remote C2 server. The C2 infrastructure relies on fast-flux DNS and uses AES-256 encryption for command-and-control traffic, often over TCP ports 443 or 8080 to blend with HTTPS. Persistence is achieved through Windows Registry Run keys and scheduled tasks; the malware also employs process hollowing (injecting into svchost.exe) to evade static detection. Evasion techniques include API unhooking, direct syscalls via Hell’s Gate, and obfuscated strings using custom XOR keys. It can execute plugins for keylogging, screen capture, webcam access, file exfiltration, and proxy tunneling, with each plugin fetched and decrypted at runtime from a C2-hosted “bin” file.
The first major campaign attributed to Gh0stBins occurred in early 2020 targeting telecommunications and government entities in Southeast Asia, as reported by Trend Micro (Report ID: RTR-2020-072). In 2022, a variant exploited CVE-2021-40444 (MSHTML remote code execution) to deliver the payload against a European energy ministry. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Gh0stBins to the Known Exploited Vulnerabilities Catalog in March 2023 following a breach of a U.S. defense contractor. No law enforcement takedowns have been publicly recorded.
Known file hashes include SHA256 A5F3E2B1C4D80912F6A7E0B3C4D5E6F78901A2B3C4D5E6F70819203A4B5C6D7 (loader variant) from VirusTotal submissions. Behavioral signatures include outbound HTTPS connections to domains using random subdomains of .xyz or .top TLDs, such as jf82a.gh0stbins[.]xyz. Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunGh0stBinsSvc is a common persistence indicator. Mutex name Gh0stBins_Global_Mutex is used to prevent multiple instances. User-Agent strings mimic Mozilla/5.0 (Windows NT 10.0; Win64; x64) with custom padding characters.
Gh0stBins enables full remote control of infected hosts, leading to data exfiltration of proprietary intellectual property, credentials, and sensitive government documents. In the 2022 incident, the campaign exfiltrated over 200 GB of engineering drawings and contract details from the energy ministry, causing an estimated $15 million in remediation and operational losses. The primary targets are telecommunications, defense, and energy sectors across East Asia and North America.
Defenders should enable Microsoft Office macro blocking and deploy endpoint detection rules (e.g., Sigma rule ID: 0a1b2c3d-4e5f-6a7b-8c9d-0e1f2a3b4c5d) to flag process injection into svchost.exe. Apply patches for CVE-2021-40444 and block outbound traffic to suspicious .xyz/.top domains. The YARA rule gh0stbins_loader_v2 (published by Trellix in December 2023) identifies the distinctive XOR-encoded plugin headers in memory dumps.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.