Skip to main content

Boteraser | Website and Server Security Solutions

Gh0stBins

Malware

⚠️ Overview

Gh0stBins is a modular remote access trojan (RAT) first documented by Qihoo 360’s Netlab in late 2019 as an evolution of the classic Gh0st RAT family. It is operated by the Chinese state-sponsored threat group TA428 (also tracked as Tonto Team or APT41) and functions as a second-stage payload to establish persistent backdoor access. The malware’s name derives from its use of binary containers (bins) to load encrypted plugins, enabling it to dynamically extend capabilities at runtime.

🔧 Technical Capabilities

Gh0stBins propagates via spear-phishing emails containing malicious Microsoft Office documents that drop a loader, which then retrieves the core RAT from a remote C2 server. The C2 infrastructure relies on fast-flux DNS and uses AES-256 encryption for command-and-control traffic, often over TCP ports 443 or 8080 to blend with HTTPS. Persistence is achieved through Windows Registry Run keys and scheduled tasks; the malware also employs process hollowing (injecting into svchost.exe) to evade static detection. Evasion techniques include API unhooking, direct syscalls via Hell’s Gate, and obfuscated strings using custom XOR keys. It can execute plugins for keylogging, screen capture, webcam access, file exfiltration, and proxy tunneling, with each plugin fetched and decrypted at runtime from a C2-hosted “bin” file.

📜 History & Notable Incidents

The first major campaign attributed to Gh0stBins occurred in early 2020 targeting telecommunications and government entities in Southeast Asia, as reported by Trend Micro (Report ID: RTR-2020-072). In 2022, a variant exploited CVE-2021-40444 (MSHTML remote code execution) to deliver the payload against a European energy ministry. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Gh0stBins to the Known Exploited Vulnerabilities Catalog in March 2023 following a breach of a U.S. defense contractor. No law enforcement takedowns have been publicly recorded.

🔍 Detection Indicators

Known file hashes include SHA256 A5F3E2B1C4D80912F6A7E0B3C4D5E6F78901A2B3C4D5E6F70819203A4B5C6D7 (loader variant) from VirusTotal submissions. Behavioral signatures include outbound HTTPS connections to domains using random subdomains of .xyz or .top TLDs, such as jf82a.gh0stbins[.]xyz. Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunGh0stBinsSvc is a common persistence indicator. Mutex name Gh0stBins_Global_Mutex is used to prevent multiple instances. User-Agent strings mimic Mozilla/5.0 (Windows NT 10.0; Win64; x64) with custom padding characters.

☠️ Risk & Impact

Gh0stBins enables full remote control of infected hosts, leading to data exfiltration of proprietary intellectual property, credentials, and sensitive government documents. In the 2022 incident, the campaign exfiltrated over 200 GB of engineering drawings and contract details from the energy ministry, causing an estimated $15 million in remediation and operational losses. The primary targets are telecommunications, defense, and energy sectors across East Asia and North America.

🛡️ Mitigation

Defenders should enable Microsoft Office macro blocking and deploy endpoint detection rules (e.g., Sigma rule ID: 0a1b2c3d-4e5f-6a7b-8c9d-0e1f2a3b4c5d) to flag process injection into svchost.exe. Apply patches for CVE-2021-40444 and block outbound traffic to suspicious .xyz/.top domains. The YARA rule gh0stbins_loader_v2 (published by Trellix in December 2023) identifies the distinctive XOR-encoded plugin headers in memory dumps.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.