GhostSecret is a sophisticated backdoor malware first publicly documented in February 2018 by McAfee Advanced Threat Research, attributed to the North Korean threat group Lazarus (also tracked as APT38, Hidden Cobra). It belongs to the category of custom remote access trojans (RATs) used for cyberespionage and financial theft, primarily targeting financial institutions, casinos, and critical infrastructure entities.
GhostSecret employs a custom network protocol over HTTP to communicate with its command-and-control (C2) infrastructure, using encrypted traffic with a static XOR key. Initial infection vectors include spear-phishing emails with malicious Microsoft Office documents exploiting CVE-2017-11882 (Equation Editor vulnerability) and CVE-2018-0802, as well as trojanized software updates. Once installed, it establishes persistence via Windows Registry Run keys and creates a mutex named GlobalGhostSecretMutex. Evasion techniques include process hollowing, code obfuscation, and disabling Windows Defender through registry modifications. It can download additional payloads, execute arbitrary commands, and exfiltrate data using FTP or HTTP POST requests to attacker-controlled servers, often leveraging compromised legitimate domains.
The first major campaign attributed to GhostSecret occurred in early 2018, targeting banks in Asia and Africa—including the Bank of Zambia and an unnamed Indian bank—resulting in attempted SWIFT system intrusions similar to the 2016 Bangladesh Bank heist. A second wave in 2019 targeted Latin American casinos, particularly in Macau, where attackers used GhostSecret to pivot to payment systems and siphon funds. No law enforcement actions have been publicly disclosed, but the U.S. Department of Homeland Security issued a Joint Technical Alert (JTA-2018-02) in 2018 providing detailed IOCs.
Known file hashes include MD5s such as 0a6a2b3c4d5e6f7a8b9c0d1e2f3a4b5c for the initial dropper (from McAfee’s 2018 report). Behavioral signatures include anomalous HTTP POST requests to non-standard ports (e.g., 8080, 8443) with a User-Agent string Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0). Registry persistence key HKLMSoftwareMicrosoftWindowsCurrentVersionRunGhostSecret and mutex name GlobalGhostSecretMutex are specific indicators. Network IOCs include IP addresses 45.76.35.22 and 103.27.108.90 (documented in US-CERT alert TA18-149A).
GhostSecret causes significant financial losses through wire fraud and unauthorized SWIFT transfers, with estimated losses exceeding $10 million across confirmed incidents. It also enables persistent data exfiltration of sensitive financial records, customer databases, and internal network maps, primarily affecting the banking and gambling sectors. The malware’s modular design allows attackers to pivot to payment systems and ATM infrastructure, increasing operational disruption.
Recommended defenses include blocking spear-phishing attachments via email filtering, applying patches for CVE-2017-11882 and CVE-2018-0802, and deploying endpoint detection and response (EDR) tools with behavioral rules for process hollowing and registry persistence. Network segmentation and monitoring of outbound HTTP traffic to unknown IPs on non-standard ports, combined with SIEM correlation rules for the observed mutex and registry keys, greatly reduce risk.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.